Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: IDS in a loadbalanced Network |
|---|---|
| Date: | Thu, 7 Sep 2006 19:26:13 -0400 |
Jan, *** I work for ISS *** This is likely a vendor specific question. Some vendors can monitor the HSRP traffic directly, while others will not be able to reliably recognize attacks tunneled within HSRP. If your vendor cannot identify attacks within HSRP, you would either need to chose a different location for the IDS where HSRP is not present or chose another vendor. Some vendors aggregate the packets from their various adapters, while others do not. In some cases, they do so only partially. Ask your vendor whether they support PortChannel, EtherChannel, etc. and how they support it. If the adapters are aggregated, the best thing would be to place a tap on each link in the channel/bundle and feed the packets from all of the links to the same IDS. That is, you would place a tap on each link and feed the output from each tap to a different input adapter on the same IDS. If the IDS cannot aggregate adapters, you will need to use a SPAN port capable of handling the full bandwidth of the channel, look at placing the IDS elsewhere on the network where PortChannel is not used, or chose another vendor. I hope this helps. Paul P.S. Since I work for ISS I would be remiss if I did not mention that ISS products do recognize attacks tunneled within HSRP and do aggregate the packets from their adapters. -----Original Message----- From: Scholten, Jan [mailto:jan.scholten@siemens.com] Sent: Thursday, September 07, 2006 6:27 AM To: focus-ids@securityfocus.com Subject: IDS in a loadbalanced Network Hi! While searching for a matching IDS I encountered some problems. Having a network structure with lots of seperate Vlans and/or DMZs networks, i am wondering what is the best way to place an IDS in a redundant L3Switch/router (C6506/7300) with HSRP and PortChannel Loadbalancing for Vlans. Is there a bestpractice how to place an ids in a vlan, using a span port on each of the devices (running in active/active), or is there a better solution? Regards from Germany Jan Scholten ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. ------------------------------------------------------------------------ ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. ------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Snort Tuning, wilson . amajohn |
|---|---|
| Next by Date: | RE: IDS in a loadbalanced Network, Scholten, Jan |
| Previous by Thread: | IDS in a loadbalanced Network, Scholten, Jan |
| Next by Thread: | Re: IDS in a loadbalanced Network, Adam Powers |
| Indexes: | [Date] [Thread] [Top] [All Lists] |