IDS mailing list archives
Re: Re: RE: RE: IDS vs. IPS deployment feedback
From: trashcanmn () gmail com
Date: 30 Mar 2006 16:51:50 -0000
<snip> Firewalls and IPS has the same characteristics in that if either one stops working, traffic goes down as well. So by installing an IPS you have two devices that can stop your connection. By using an IDS you only have one device (the firewall) that can shut down your network. </snip> The above statement isn't entirely correct. Most modern IPS have a 'fail-over' feature that allows traffic to pass even if the IPS is overloaded or powered off. If deployed correctly an IPS should not completely shut down a network. One of the misconceptions some people have is to believe that deploying and maintaining an IPS requires less work than an IDS. Both systems require knowledgable personnel to tune and customize the rule sets for their environment. If you don't have the right people for an IDS you won't be able to separate legitimate threats from false-postivies. If you don't have the right people for an IPS you will end up blocking legitimate traffic. To me neither scenario is acceptable. As to the post topic, I've used both IDS and IPS systems and found that a combination of both works well for my environment. IPSes can work well in front of or behind your perimeter firewall. They also work well to separate your DMZ from Corp networks. IDS can work well inside your DMZ or Corp networks. ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. ------------------------------------------------------------------------
Current thread:
- Re: IDS vs. IPS deployment feedback, (continued)
- Re: IDS vs. IPS deployment feedback nightelfhunter (Mar 21)
- RE: IDS vs. IPS deployment feedback Andrew Plato (Mar 23)
- Re: IDS vs. IPS deployment feedback Stefano Zanero (Mar 27)
- RE: IDS vs. IPS deployment feedback Cojocea, Mike (IST) (Mar 27)
- Re: RE: IDS vs. IPS deployment feedback xris375 (Mar 27)
- RE: RE: IDS vs. IPS deployment feedback Andrew Plato (Mar 28)
- Re: RE: IDS vs. IPS deployment feedback Devdas Bhagat (Mar 29)
- Re: RE: IDS vs. IPS deployment feedback Jean-Philippe Luiggi (Mar 31)
- Re: RE: IDS vs. IPS deployment feedback Devdas Bhagat (Mar 29)
- Re: RE: RE: IDS vs. IPS deployment feedback xris375 (Mar 30)
- Re: RE: RE: IDS vs. IPS deployment feedback Sanjay Rawat (Mar 31)
- Re: Re: RE: RE: IDS vs. IPS deployment feedback trashcanmn (Mar 31)
- RE: RE: IDS vs. IPS deployment feedback Andrew Plato (Mar 31)