Snort Installation Manual
It always good to know if someone is attempting to break into your network. This is why we put an Intrusion Detection System (IDS) before the first firewall (external side). You can compare this to having a camera monitoring your front door, without this camera you would never know who even attempted to pick your lock unsuccessfully.
Knowing that an attempt was successful in passing through your firewall can let you focus on real threats and help you cut down on false positives. The other benefit is in environments that use Network Address Translation (NAT). This will allow to you get the real source address by correlating the events between the IDS systems before and after the firewall.
This topology will allow you to verify that your firewall baselines are being followed, or that someone didn’t make a mistake when changing a firewall rule. If you know that your firewall baselines outlaw the use of ftp and your post-firewall IDS system is showing ftp alerts, then you know that the firewall is not blocking FTP traffic. This is just a side effect and should not be the only way you verify compliance with your baselines.
Download Snort Installation Manual
Related PDF Manuals:
- iPhone Microsoft Exchange Server
- Toyota Yaris Instruction Manual
- Guide to Connecting the Xbox 360 to Windows Vista Media Center PC
- Apple iMac G5 Remote Director Monitor Proofing System
- Facebook for BlackBerry Smartphones User Guide
- The Insides of Panda Cloud Antivirus
- NetQin Mobile Anti-Virus for Pocket PC 2.2 Users Guide
- BlackBerry Pearl 8220 Smartphone Getting Started Guide
October 2nd, 2008 | by pdf manuals |
By powerrich on Mar 21, 2009
thanks very much for ebook..
good website
By khalifah on Mar 21, 2009
make me more info in IDS
THANKS A LOT