Educause Security Discussion mailing list archives

Re: Network config monitoring and auditing software


From: Brad Judy <win-hied () BRADJUDY COM>
Date: Mon, 14 Sep 2009 15:33:23 -0400

Tripwire Enterprise can do this, but it might be overkill for your purposes.
I have mainly used it on systems rather than network equipment, but the
network equipment portion is simpler to implement.  It has a lot of features
for tracking/approving/reverting changes as well as reporting.

It would be worthwhile to look into it if you might use it for other
purposes.

Brad Judy



-----Original Message-----
From: The EDUCAUSE Security Constituent Group Listserv
[mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Kevin Halgren
Sent: Monday, September 14, 2009 2:50 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Network config monitoring and auditing software

We're looking at software to help with monitoring and auditing changes
to firewall and switch configurations.  I'd be interested to hear what
others out there are using, how happy you are with the product, and any
additional functionality your product has that you have found useful.
I'd also be interested in products that have a broad range of
interoperability with different vendor products.

Our environment is largely Cisco.  The firewalls are Cisco ASAs with a
couple of older Cisco PIX firewalls still in service.  Core switches are
Cisco with some Foundry/Brocade devices at the edge.

Thanks,

Kevin

--
Kevin Halgren
Assistant Director - Systems and Network Services
Washburn University
(785) 670-2341
kevin.halgren () washburn edu

Current thread: