Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Question on IDS

Status
Not open for further replies.

SgtB

IS-IT--Management
Oct 3, 2002
447
US
I'd like to place an IDS system outside my firewall. I've seen many "best practices" diagrams stating that I'd be a good idea to put an IDS on the outside, and the inside of your firewall. Now here's the question...
If you put an IDS outside your firewall, then whats protecting the IDS? How could you trust an IDS that's that vulnerable? I'm assuming there's some little trick I don't know that makes the IDS reliable/secure.

So how is it done?
Thanks!
 
I use SNORT for an IDS. I have the ethernet0 set as a passive interface (no IP address). There is a diagram at snort.org on how to make a cable that will only allow the IDS box to sniff the incoming/outgoing network packets but not respond to any queries on the interface. If you want you can then setup an internal interface to access the IDS from the inside. If you do this make sure that the address is hidden from the outside world.
 
I found some info on a passive interface. Just for the record, and some info for people who may read this. Here's a link to a nice little place that shows you how to (easily) create a no-ip interface on RH Linux.


Beats cutting cable! j/k

Thanks for the reply!
 
That is a very good article. I had to fumble my way through it with the FAQs and Howto's (but this was over 1 year ago).
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top