IDS mailing list archives

RE: IDS/IPS system with Foundry sFlow


From: "Otis DuPont" <odoggz () rcn com>
Date: Tue, 22 Apr 2008 18:56:28 -0400

You can still use 'snort' or rather the technology by Sourcefire, but get it
included as an embedded/bundled solution. Nokia IP###s (290, 390 etc) are
good for that and more. So I'd check Nokia because they've made some great
moves since 2007 on FW, IPS and IDS.

-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com] On
Behalf Of Security Group
Sent: Monday, April 21, 2008 3:42 PM
To: focus-ids () securityfocus com
Subject: IDS/IPS system with Foundry sFlow

Hello,

We have got a network with an embedded support for sFlow technology.
We also want to have a good IDS/IPS system. Does anyone know a good
setup with our foundry?

We noticed that Foundry got their own application called "IronView
Network Manager", it is able to operate with snort. Does anyone know
of this is a good solution? Or should we use an sFlow converter (e.g.
InMon sFlow toolkit) that can work with snort?

What are the other possibilities for IDS/IPS besides snort. It has to
operate with the sFlow technology.

Kind regards,

Babel Timo

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it 
with real-world attacks from CORE IMPACT.
Go to
http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=in
tro_sfw 
to learn more.
------------------------------------------------------------------------




------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it 
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw 
to learn more.
------------------------------------------------------------------------


Current thread: