Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 56 guests and 2 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Hardwarearrow IPS Suggestions
EH-Net
May 25, 2012, 09:19:54 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: IPS Suggestions  (Read 8113 times)
0 Members and 1 Guest are viewing this topic.
scucci
Newbie
*
Offline Offline

Posts: 29


View Profile
« on: July 05, 2009, 05:21:15 PM »

We're currently a small shop and we've been running a large external Intrusion Prevention system by ISS. We're currently a small to medium sized company and we've run into issues with the IPS before. Due to it being external we've had an issue with the way our firewalls are setup running traffic through it. I'm also looking to upgrading my firewall and wanted to know if anyone has had any experience with the Cisco IPS module that comes installed in the ASA. I've taken a few demo's of the management and wanted to know if anyone's used it before or have any suggestions. I think for the size of our organization this is something that would fit perfectly. Any thoughts?
Logged
dalepearson
Sr. Member
****
Offline Offline

Posts: 356


View Profile WWW
« Reply #1 on: July 07, 2009, 09:08:35 AM »

Scucci,

I dont have hands on experiance with the box, as thats not my role anymore. However I have worked with a customer who had a 5540 deployed and it had a pretty decent throughput for the size of the organisation, and as you say the management interface is graphical and concise, and pretty configurable.

Obviously you will know your organisation, but I would ask CISCO for a demo unit and pop it on your network in learning mode for a while, and then trial it. Proof is in the pudding I will say.

My only observation from experiance, is that people forget that you need to make good use of the logs, and monitor them accordingly, and also dont forget you need additional license and support inplace for the IDS / IPS components in addition.

I will also add that I have had a little look at the Astaro Security Gateway, not in a commerical environment, just in a virtual lab. Not sure on the price comparisons, but again this box has some IPS functionality, as well as some other bits and bobs. You could download the free VM and try it out also.

I think these AIO devices bring real benefit in a SME, so I think you have a few options to review. Just incase I sound like a salesman Smiley I dont work or have any relationships with Cisco or Astaro. Hope it helps a little.
Logged

charlottebandit
Newbie
*
Offline Offline

Posts: 49


View Profile
« Reply #2 on: July 15, 2009, 06:35:11 PM »

We're currently a small shop and we've been running a large external Intrusion Prevention system by ISS. We're currently a small to medium sized company and we've run into issues with the IPS before. Due to it being external we've had an issue with the way our firewalls are setup running traffic through it. I'm also looking to upgrading my firewall and wanted to know if anyone has had any experience with the Cisco IPS module that comes installed in the ASA. I've taken a few demo's of the management and wanted to know if anyone's used it before or have any suggestions. I think for the size of our organization this is something that would fit perfectly. Any thoughts?


The Cisco IPS modules for the ASA's are pretty good actually.  The difference between this setup and another solution that offers "everything" in a box is that you have dedicated resources built into the card which helps A LOT on performance.  Automatic updates can be done.  The ability to prevent IP Telephony attacks can be done. 

Having an IPS in front of a perimeter firewall doesn't make much sense as it's analyzing every packet and payload rather than allowing a firewall perform analysis based on access rules, inspection engines, threat detection, and possibly VPN connections. 

An IDS in front is ok though for forensic evidence collection as long as it's not directly inline.  ISS makes good products though.
Logged

MS, CCSP, CCNP, CCDP, CEH, CHFI, CPTS
Bane
Guest
« Reply #3 on: August 20, 2009, 12:09:25 PM »

We're currently a small shop and we've been running a large external Intrusion Prevention system by ISS. We're currently a small to medium sized company and we've run into issues with the IPS before. Due to it being external we've had an issue with the way our firewalls are setup running traffic through it. I'm also looking to upgrading my firewall and wanted to know if anyone has had any experience with the Cisco IPS module that comes installed in the ASA. I've taken a few demo's of the management and wanted to know if anyone's used it before or have any suggestions. I think for the size of our organization this is something that would fit perfectly. Any thoughts?


The Cisco IPS modules for the ASA's are pretty good actually.  The difference between this setup and another solution that offers "everything" in a box is that you have dedicated resources built into the card which helps A LOT on performance.  Automatic updates can be done.  The ability to prevent IP Telephony attacks can be done. 

Having an IPS in front of a perimeter firewall doesn't make much sense as it's analyzing every packet and payload rather than allowing a firewall perform analysis based on access rules, inspection engines, threat detection, and possibly VPN connections. 

An IDS in front is ok though for forensic evidence collection as long as it's not directly inline.  ISS makes good products though.

There are cases where having an IPS in front of the firewall makes sense. The most specific is in a hosting situation where you are trying to protect against DoS and DDoS attacks. Firewalls and UTM devices are not designed to protect against denial of service attacks. Most modern IPS devices such as TippingPoint and TpoLayer are.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.21 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.