Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Testing Security Devices, Firewall And Intrusion Detection

Status
Not open for further replies.

Sundog2004

Technical User
Jun 14, 2004
4
0
0
GB
We are just in the process of deploying new firewalls and an intrusion detection system. I am looking for tools that will help me test the configuration is correct etc. I have found the Informer products from and they seem to look good, has anyone tried them or can suggest anything else?

I have tried using our vulnerability scanner but not had much joy.
 
You can download an Internet Monitoring and Reporting tool at that will show all the sites your users are going to. Depending on the logging of your new firewall you can get statistics on Blocked and Failed hits and see what your intrusion detection has not let past the firewall, Once again dependent on the logging of the firewall. It's worth a look, WebSpy software is free to evaluate for 30 days(full versions) Check it out.
 
Thanks Pat for the feedback I have used ShieldsUP before to perform some basic port testing etc. What I am really after is a way to be able to replay traffic controlling both the source and the destination so that I can have stateful traffic. I have not been able to find anything other than Blades Informer products to do this yet and I just wanted to check to see if anyone knew of anything else before I proceeded with them. What I like about the products is that you only need a laptop with two nics load the software up and then you can replay traffic between the two nics without needing a target host to respond. You just test the device in the middle by running real attacks or network traffic, all safe and controlled.

Cheers
 
You might want to take a look at Sandstorm. They've got an appliance that stores raw tcpdump data and lets you recreate entire sessions. They have an interface for searching through the data to look for specific traffic.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top