Skip to main content

How do you implement IDS in havily based switched network?

More
19 years 4 months ago #9226 by ping

The greatest pleasure in life is doing what people say you can not do..!!
More
19 years 4 months ago #9236 by Chris
I always try to carry with me a hub for these situations - its amazing how handy it be at times :)

Chris Partsenidis.
Founder & Editor-in-Chief
www.Firewall.cx
More
19 years 4 months ago #9263 by ping
I thought i understand most of article but latere i thought that i have not clear idea of tape so can anyone of you explain me what is tape and basic functions it performs ?

The greatest pleasure in life is doing what people say you can not do..!!
More
19 years 4 months ago #9265 by cybersorcerer
I'm assuming you mean a tap so I'll explain what that is. A tap is a device that is inserted on one ethernet cable to provide a means of sniffing the data going to and from the tap without sacrificing bandwidth(like a hub would). The tap device usually has 4 ports. The first two take the terminated ends of the ethernet cable you want to tap. The other two are the ports in which the data tapped from the first two are sent out. One is egress(outgoing traffic) and the other is ingress(incoming traffic). So you run an ethernet cable from those ports to the IDS and you can start passively sniffing.

Taps are usually expensive devices but they are probably the best method to implement a sniffable infrastructure for an IDS on the front lines since the tap does not sacrifice bandwidth. Let me know if that clarified everything for you.

"He who breaks something to find out what it is, has left the path of wisdom."

Gandalf the Grey
Time to create page: 0.128 seconds