Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: IDS/IPS system with Foundry sFlow |
|---|---|
| Date: | Tue, 22 Apr 2008 15:48:40 -0400 |
I believe sFlow will only forward sampled data, not all packets. -----Original Message----- From: listbounce@securityfocus.com [mailto:listbounce@securityfocus.com] On Behalf Of Martin Roesch Sent: April 22, 2008 2:19 PM To: Security Group Cc: focus-ids@securityfocus.com Subject: Re: IDS/IPS system with Foundry sFlow When you say "with sFlow" do you mean analyze the sFlow records or analyze the packets on the wire and correlate it with the sFlow data? -- Sent from my iPhone On Apr 21, 2008, at 3:42 PM, "Security Group" <secgro@gmail.com> wrote:
Hello, We have got a network with an embedded support for sFlow technology. We also want to have a good IDS/IPS system. Does anyone know a good setup with our foundry? We noticed that Foundry got their own application called "IronView Network Manager", it is able to operate with snort. Does anyone know of this is a good solution? Or should we use an sFlow converter (e.g. InMon sFlow toolkit) that can work with snort? What are the other possibilities for IDS/IPS besides snort. It has to operate with the sFlow technology. Kind regards, Babel Timo --- --------------------------------------------------------------------- Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to
http://www.coresecurity.com/index.php5?module=Form&action=impact&campaig n=intro_sfw
to learn more. --- ---------------------------------------------------------------------
------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaig n=intro_sfw to learn more. ------------------------------------------------------------------------ ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw to learn more. ------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: IDS/IPS system with Foundry sFlow, Martin Roesch |
|---|---|
| Next by Date: | Re: IDS/IPS system with Foundry sFlow, Adam Powers |
| Previous by Thread: | Re: IDS/IPS system with Foundry sFlow, Martin Roesch |
| Next by Thread: | Re: IDS/IPS system with Foundry sFlow, Adam Powers |
| Indexes: | [Date] [Thread] [Top] [All Lists] |