Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: IDS in a loadbalanced Network |
|---|---|
| Date: | Fri, 08 Sep 2006 12:51:29 -0400 |
Paul, I'm confused about your comments regarding packets "tunneled within HSRP". HSRP is Cisco's Hot Standby Routing Protocol. It's a multicast virtual routing interface technology for making L3 gateways on a local subnet highly available, not a tunneling or packet encapsulation protocol as you suggest. I'm guessing you meant 802.1q or ISL vs. HSRP, no? Or is there some new covert channel involving HSRP ISS has discovered that the rest of us are unaware of? Anyway, usually* the best bet is to SPAN the various VLANs that you're wanting to monitor into a single destination port on the switch/router. Don't bother trying to monitor the physical aggregated ports themselves. Logical VLAN monitoring is almost always easier. Most vendors offer the option to either mirror Ethernet frames transiting the trunk with or without tagging. You'll usually want to enable tagged frames as modern sensor technologies will make use of the VLAN ID contained within the tag. If you have two or more switch/routers that are HSRP enabled just plug the SPAN/mirror output from these devices into multiple ports offered on a single sensor (pretty much *all* vendors support port aggregation at this point). It's important that you avoid asymmetric routing. Given the fact that packets can come into a subnet on the secondary HSRP router and leave on the primary, you MUST monitor both HSRP devices using a single sensor. * The only exception to this is 1) the switch/router vendor doesn't support monitoring of logical VLANs or 2) duplicate Ethernet frames are a major concern. SPANing multiple logical VLANs in a single switch *can* cause multiple packets to be mirrored to a single egress mirror port. - Adam P. On 9/7/06 7:26 PM, "Palmer, Paul (ISSAtlanta)" <PPalmer@iss.net> wrote:
Jan, *** I work for ISS *** This is likely a vendor specific question. Some vendors can monitor the HSRP traffic directly, while others will not be able to reliably recognize attacks tunneled within HSRP. If your vendor cannot identify attacks within HSRP, you would either need to chose a different location for the IDS where HSRP is not present or chose another vendor. Some vendors aggregate the packets from their various adapters, while others do not. In some cases, they do so only partially. Ask your vendor whether they support PortChannel, EtherChannel, etc. and how they support it. If the adapters are aggregated, the best thing would be to place a tap on each link in the channel/bundle and feed the packets from all of the links to the same IDS. That is, you would place a tap on each link and feed the output from each tap to a different input adapter on the same IDS. If the IDS cannot aggregate adapters, you will need to use a SPAN port capable of handling the full bandwidth of the channel, look at placing the IDS elsewhere on the network where PortChannel is not used, or chose another vendor. I hope this helps. Paul P.S. Since I work for ISS I would be remiss if I did not mention that ISS products do recognize attacks tunneled within HSRP and do aggregate the packets from their adapters. -----Original Message----- From: Scholten, Jan [mailto:jan.scholten@siemens.com] Sent: Thursday, September 07, 2006 6:27 AM To: focus-ids@securityfocus.com Subject: IDS in a loadbalanced Network Hi! While searching for a matching IDS I encountered some problems. Having a network structure with lots of seperate Vlans and/or DMZs networks, i am wondering what is the best way to place an IDS in a redundant L3Switch/router (C6506/7300) with HSRP and PortChannel Loadbalancing for Vlans. Is there a bestpractice how to place an ids in a vlan, using a span port on each of the devices (running in active/active), or is there a better solution? Regards from Germany Jan Scholten ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. ------------------------------------------------------------------------ ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. ------------------------------------------------------------------------
------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. ------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | AW: IDS in a loadbalanced Network, Barthel, Frank |
|---|---|
| Next by Date: | RE: Scan for "outsider" Pcs on network, Lim Ming Wei |
| Previous by Thread: | RE: IDS in a loadbalanced Network, Palmer, Paul (ISSAtlanta) |
| Next by Thread: | RE: IDS in a loadbalanced Network, Scholten, Jan |
| Indexes: | [Date] [Thread] [Top] [All Lists] |