IDS mailing list archives
Re: IDS in a loadbalanced Network
From: Adam Powers <apowers () lancope com>
Date: Fri, 08 Sep 2006 12:51:29 -0400
Paul, I'm confused about your comments regarding packets "tunneled within HSRP". HSRP is Cisco's Hot Standby Routing Protocol. It's a multicast virtual routing interface technology for making L3 gateways on a local subnet highly available, not a tunneling or packet encapsulation protocol as you suggest. I'm guessing you meant 802.1q or ISL vs. HSRP, no? Or is there some new covert channel involving HSRP ISS has discovered that the rest of us are unaware of? Anyway, usually* the best bet is to SPAN the various VLANs that you're wanting to monitor into a single destination port on the switch/router. Don't bother trying to monitor the physical aggregated ports themselves. Logical VLAN monitoring is almost always easier. Most vendors offer the option to either mirror Ethernet frames transiting the trunk with or without tagging. You'll usually want to enable tagged frames as modern sensor technologies will make use of the VLAN ID contained within the tag. If you have two or more switch/routers that are HSRP enabled just plug the SPAN/mirror output from these devices into multiple ports offered on a single sensor (pretty much *all* vendors support port aggregation at this point). It's important that you avoid asymmetric routing. Given the fact that packets can come into a subnet on the secondary HSRP router and leave on the primary, you MUST monitor both HSRP devices using a single sensor. * The only exception to this is 1) the switch/router vendor doesn't support monitoring of logical VLANs or 2) duplicate Ethernet frames are a major concern. SPANing multiple logical VLANs in a single switch *can* cause multiple packets to be mirrored to a single egress mirror port. - Adam P. On 9/7/06 7:26 PM, "Palmer, Paul (ISSAtlanta)" <PPalmer () iss net> wrote:
Jan, *** I work for ISS *** This is likely a vendor specific question. Some vendors can monitor the HSRP traffic directly, while others will not be able to reliably recognize attacks tunneled within HSRP. If your vendor cannot identify attacks within HSRP, you would either need to chose a different location for the IDS where HSRP is not present or chose another vendor. Some vendors aggregate the packets from their various adapters, while others do not. In some cases, they do so only partially. Ask your vendor whether they support PortChannel, EtherChannel, etc. and how they support it. If the adapters are aggregated, the best thing would be to place a tap on each link in the channel/bundle and feed the packets from all of the links to the same IDS. That is, you would place a tap on each link and feed the output from each tap to a different input adapter on the same IDS. If the IDS cannot aggregate adapters, you will need to use a SPAN port capable of handling the full bandwidth of the channel, look at placing the IDS elsewhere on the network where PortChannel is not used, or chose another vendor. I hope this helps. Paul P.S. Since I work for ISS I would be remiss if I did not mention that ISS products do recognize attacks tunneled within HSRP and do aggregate the packets from their adapters. -----Original Message----- From: Scholten, Jan [mailto:jan.scholten () siemens com] Sent: Thursday, September 07, 2006 6:27 AM To: focus-ids () securityfocus com Subject: IDS in a loadbalanced Network Hi! While searching for a matching IDS I encountered some problems. Having a network structure with lots of seperate Vlans and/or DMZs networks, i am wondering what is the best way to place an IDS in a redundant L3Switch/router (C6506/7300) with HSRP and PortChannel Loadbalancing for Vlans. Is there a bestpractice how to place an ids in a vlan, using a span port on each of the devices (running in active/active), or is there a better solution? Regards from Germany Jan Scholten ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. ------------------------------------------------------------------------ ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. ------------------------------------------------------------------------
------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. ------------------------------------------------------------------------
Current thread:
- IDS in a loadbalanced Network Scholten, Jan (Sep 07)
- <Possible follow-ups>
- RE: IDS in a loadbalanced Network Palmer, Paul (ISSAtlanta) (Sep 08)
- Re: IDS in a loadbalanced Network Adam Powers (Sep 08)
- RE: IDS in a loadbalanced Network Scholten, Jan (Sep 08)