IDS mailing list archives

Re: Any Intrusion Detection Appliances handle wired and wireless networks?


From: "Kurt Seifried" <bt () seifried org>
Date: Wed, 3 Mar 2004 17:51:58 -0700

Regarding OpenBSD I'm not sure if he meant use OpenBSD as the IDS platform
(i.e. run snort on it) or if he meant using dup-to (for example) to send all
the wireless data to your IDS sensor/network so that it could see it
(essentially using OpenBSD as an intelligent wireless bridge). Plus this way
you could easily filter out traffic you're not much interested in (reducing
load on the IDS) and also allow you to examine the wireless client somewhat
more then an IDS might allow (channel, MAC, etc.).


Kurt Seifried, kurt () seifried org
A15B BEE5 B391 B9AD B0EF
AEB0 AD63 0B4E AD56 E574
http://seifried.org/security/



---------------------------------------------------------------------------
Free 30-day trial: firewall with virus/spam protection, URL filtering, VPN,
wireless security

Protect your network against hackers, viruses, spam and other risks with Astaro
Security Linux, the comprehensive security solution that combines six
applications in one software solution for ease of use and lower total cost of
ownership.

Download your free trial at 
http://www.securityfocus.com/sponsor/Astaro_focus-ids_040301
---------------------------------------------------------------------------


Current thread: