Security Basics mailing list archives
IDS question [was: Re: Firewall and DMZ topology]
From: "Steve Bremer" <steveb () nebcoinc com>
Date: Thu, 12 Jun 2003 06:56:18 -0500
tri-homed firewall, more so if you have IDS sensors at exterior, dmz, and interior, and the time to monitor them.
Changing subjects a little bit here. I agree with our IDS comment,
but I'm curious about how your external IDS is used.
I've ran into differing opinions on this (as I do with most things
security related ;-), but I I don't think that I would want the external
IDS monitoring incoming traffic. Why? Because it would be going
off all the time. As many times as we're probed during the day, the
IDS sensor would be in a constant state of sending alerts. Yes, you
could adjust the rules to reduce this, but then what is the point of
having the IDS sensor there? However, I believe the external IDS
sensor should be there to monitor traffic leaving your external
firewall so you can see if one of your internal or DMZ hosts have
been compromised.
What do you think?
Steve Bremer
NEBCO, Inc.
System & Security Administrator
---------------------------------------------------------------------------
Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts!
The Gartner Group just put Neoteris in the top of its Magic Quadrant,
while InStat has confirmed Neoteris as the leader in marketshare.
Find out why, and see how you can get plug-n-play secure remote access in
about an hour, with no client, server changes, or ongoing maintenance.
Visit us at: http://www.neoteris.com/promos/sf-6-9.htm
----------------------------------------------------------------------------
Current thread:
- Re: nmap for windows, (continued)
- Re: nmap for windows Dan Tesch (Jun 12)
- Re: nmap for windows Scott Bowlus (Jun 12)
- Re: nmap for windows ~Kevin Davis³ (Jun 12)
- Re: nmap for windows Vic Parat (NSS) (Jun 12)
- RE: nmap for windows Zekeriya Eskiocak (Jun 12)
- Re: nmap for windows Chris Gioran (Jun 12)
- Re: nmap for windows 59cobalt (Jun 12)
- IDS question [was: Re: Firewall and DMZ topology] Steve Bremer (Jun 12)
