IDS mailing list archives

RE: IDS in a loadbalanced Network


From: "Palmer, Paul (ISSAtlanta)" <PPalmer () iss net>
Date: Thu, 7 Sep 2006 19:26:13 -0400

Jan,

*** I work for ISS ***

This is likely a vendor specific question.

Some vendors can monitor the HSRP traffic directly, while others will
not be able to reliably recognize attacks tunneled within HSRP. If your
vendor cannot identify attacks within HSRP, you would either need to
chose a different location for the IDS where HSRP is not present or
chose another vendor.

Some vendors aggregate the packets from their various adapters, while
others do not. In some cases, they do so only partially. Ask your vendor
whether they support PortChannel, EtherChannel, etc. and how they
support it. If the adapters are aggregated, the best thing would be to
place a tap on each link in the channel/bundle and feed the packets from
all of the links to the same IDS. That is, you would place a tap on each
link and feed the output from each tap to a different input adapter on
the same IDS. If the IDS cannot aggregate adapters, you will need to use
a SPAN port capable of handling the full bandwidth of the channel, look
at placing the IDS elsewhere on the network where PortChannel is not
used, or chose another vendor.

I hope this helps.

Paul

P.S. Since I work for ISS I would be remiss if I did not mention that
ISS products do recognize attacks tunneled within HSRP and do aggregate
the packets from their adapters.

-----Original Message-----
From: Scholten, Jan [mailto:jan.scholten () siemens com] 
Sent: Thursday, September 07, 2006 6:27 AM
To: focus-ids () securityfocus com
Subject: IDS in a loadbalanced Network

Hi!

While searching for a matching IDS I encountered some problems.

Having a network structure with lots of seperate Vlans and/or DMZs
networks, i am wondering what is the best way to place an IDS in a
redundant L3Switch/router (C6506/7300) with HSRP and PortChannel
Loadbalancing for Vlans. 
Is there a bestpractice how to place an ids in a vlan, using a span port
on each of the devices (running in active/active), or is there a better
solution?

Regards from Germany
Jan Scholten 


------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it 
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708

to learn more.
------------------------------------------------------------------------


------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
------------------------------------------------------------------------


Current thread: