Intrusion Detection Systems mailing list archives

RE: Gigabit IDS


From: blaing () iss net (Brian Laing)
Date: Fri, 14 Jul 2000 10:49:00 +0100


Archive: http://msgs.securepoint.com/ids
FAQ: http://www.ticm.com/kb/faq/idsfaq.html
IDS: http://www-rnks.informatik.tu-cottbus.de/~sobirey/ids.html
UNSUBSCRIBE: email "unsubscribe ids" to majordomo () uow edu au
Jeffrey,

        I have written whitepaper on placing IDS into a switched environment, this
is still an semi early draft (no Glossary or TOC).  I did not mention Gigbit
in the document because TopLayer has not released a Gigbyte switch.  They
have released the switch so I will be adding a section on Gigbit monitoring,
once I have a chance to play with the switch.
        The toplayer solution can load balance traffic across multiple RealSecure
Network Sensors.  This allows you to consolodate a bunch of slower
connections to one more more RealSecure Engines.  I typically consolodate
800Mbps into 2-4 RealSecures.
        With the gigabyte switch you can spread a gigabytes worth of  traffic
across RealSecure Sensors placed on the standard ethernet ports.
        Other than the Gig solution this is all outlined in the attached doc, if
you have any quesitons please feel free to drop me a line.

you can get the doc from www.laing.org/switched.pdf

Cheers,
Brian


Current thread: