IDS mailing list archives
RE: IDS in a loadbalanced Network
From: "Palmer, Paul (ISSAtlanta)" <PPalmer () iss net>
Date: Thu, 7 Sep 2006 19:26:13 -0400
Jan, *** I work for ISS *** This is likely a vendor specific question. Some vendors can monitor the HSRP traffic directly, while others will not be able to reliably recognize attacks tunneled within HSRP. If your vendor cannot identify attacks within HSRP, you would either need to chose a different location for the IDS where HSRP is not present or chose another vendor. Some vendors aggregate the packets from their various adapters, while others do not. In some cases, they do so only partially. Ask your vendor whether they support PortChannel, EtherChannel, etc. and how they support it. If the adapters are aggregated, the best thing would be to place a tap on each link in the channel/bundle and feed the packets from all of the links to the same IDS. That is, you would place a tap on each link and feed the output from each tap to a different input adapter on the same IDS. If the IDS cannot aggregate adapters, you will need to use a SPAN port capable of handling the full bandwidth of the channel, look at placing the IDS elsewhere on the network where PortChannel is not used, or chose another vendor. I hope this helps. Paul P.S. Since I work for ISS I would be remiss if I did not mention that ISS products do recognize attacks tunneled within HSRP and do aggregate the packets from their adapters. -----Original Message----- From: Scholten, Jan [mailto:jan.scholten () siemens com] Sent: Thursday, September 07, 2006 6:27 AM To: focus-ids () securityfocus com Subject: IDS in a loadbalanced Network Hi! While searching for a matching IDS I encountered some problems. Having a network structure with lots of seperate Vlans and/or DMZs networks, i am wondering what is the best way to place an IDS in a redundant L3Switch/router (C6506/7300) with HSRP and PortChannel Loadbalancing for Vlans. Is there a bestpractice how to place an ids in a vlan, using a span port on each of the devices (running in active/active), or is there a better solution? Regards from Germany Jan Scholten ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. ------------------------------------------------------------------------ ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. ------------------------------------------------------------------------
Current thread:
- IDS in a loadbalanced Network Scholten, Jan (Sep 07)
- <Possible follow-ups>
- RE: IDS in a loadbalanced Network Palmer, Paul (ISSAtlanta) (Sep 08)
- Re: IDS in a loadbalanced Network Adam Powers (Sep 08)
- RE: IDS in a loadbalanced Network Scholten, Jan (Sep 08)