Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-IDS
[Top] [All Lists]

Re: IPS Reliability/Availability

Subject: Re: IPS Reliability/Availability
Date: Tue, 07 Feb 2006 08:41:10 -0500
You should also check for controllable latency. A box could be technically "up", but having problems and introducing latency. You should ask each vendor why they might add latency (fragmentation and session reassembly are potential ones I can think of), what happens when CPU's get taxed too high, if latency is controllable. The classic example is the vendor "pulling the plug" on the box and showing you the bypass capability. But, there are worse scenarios than pulling the plug. Controllable/configurable latency should be something you might want to look at in a vendor.

thanks,

dave

David W. Goodrum, CEH
(nfr)(security)
http://www.nfr.com
(M)703.731.3765
(O)240.747.3425
(F)240.632.0200


Wes Young wrote:
http://www.netoptics.com/products/product_family_details.asp?Section=products&pid=99&cid=5

On Thu, 2006-02-02 at 15:51 -0600, Chris Serafin wrote:

I know from the short time I worked for a Juniper reseller, the Juniper IPS
has a separate box [very small] that does like a HA link to the IPS, so if
the IPS fails, the traffic routed straight throught the network with no IPS

Chris Serafin
IT Security / VoIP Engineer
chris@chrisserafin.com

-----Original Message-----
From: geek_brigades@yahoo.com [mailto:geek_brigades@yahoo.com] Sent: Thursday, February 02, 2006 10:27 AM
To: focus-ids@securityfocus.com
Subject: IPS Reliability/Availability


I am working on a big IPS project and I am very concerned about installing
an inline device in a core enterprise network, where these devices have the
potential to create big time network outages.


Can you, please, share your possible bad experiences about the reliability
of the following inline IPS products:

ISS
TippingPoint
Juniper IPS
Sourcefire
McAfee IntruShield

Have you had any issues with the availability of these devices, such as fail
close crashes or do you have any experience with bypass switches that would
mitigate the availability issue?

Thanks,
Mike

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.
------------------------------------------------------------------------





------------------------------------------------------------------------ Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.
------------------------------------------------------------------------



-- David W. Goodrum, CEH (nfr)(security) http://www.nfr.com (M)703.731.3765 (O)240.747.3425 (F)240.632.0200

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>