NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW-1] Intrusion detection system!



Title: RE: [FW-1] Intrusion detection system!

I haven't implemented this, but it definitely looks interesting: http://www.snortsam.net/

It uses snort as the IDS, and interacts directly with Checkpoint. Anyone have any experiences with this?

Also available are a few snort based commercial products that are very nice:
www.demarc.com
www.silicondefense.com
www.sourcefire.com

I like the demarc solution because it is capable of being used as a host based system, and has tripwire-like functionality.

M. Dante Mercurio, CCNA, MCSE+I, CCSA
[email protected]
Consulting Group Manager
Continental Consulting Group, LLC
www.ccgsecurity.com

-----Original Message-----
From: Mehta, Phoram [mailto:[email protected]]
Sent: Friday, June 07, 2002 3:50 PM
To: [email protected]
Subject: [FW-1] Intrusion detection system!


A little off topic but people on this list would be the one to offer best
suggestions:


requirements:  An Intrusion detection System ??? (probably distributed)

Details:
Firewall used: FW-1 4.1 on nokia IP440
Routers used: Cisco
Bandwidth: 3MBps
Location on future IDS: cost dependent
Preference: internal but should be able to intercept traffic to all segments (internal workstations(150-200), DMZ's(10-15 servers), Remote access) basically should catch each and every packet passing the firewall. we can place it outside if the above config is too difficult or expensive.

Can anyone advise on which IDS would be good based on their experiences in terms of compatibility with other products, performance, ease and cost.

Thanks,
PKM

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail =================================================
To unsubscribe from this mailing list,
please see the instructions at http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected] =================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.