Chapter 1 Introducing the Sensor
Appliances
1-6
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Determine which segments of the network you want to monitor to determine the
location for the appliance. Remember, each appliance maintains a security policy
configured for the segment it is monitoring. The security policies can be standard
across the organization or unique for each appliance. You may consider changing
your network topology to force traffic across a given monitored network segment.
There are always operational trade-offs when going through this process. The end
result should be a rough idea of the number of appliances required to protect the
desired network.
Placing an Appliance on Your Network
You can place an appliance in front of or behind a firewall. Each position has
benefits and drawbacks.
Placing an appliance in front of a firewall allows the appliance to monitor all
incoming and outgoing network traffic. However, when deployed in this manner,
the appliance does not detect traffic that is internal to the network. An internal
attacker taking advantage of vulnerabilities in network services would remain
undetected by the external appliance (see
Figure 1-2 on page 1-7
).
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...