Can an IPS collect information of all layers like like which protocol and port numbers are being used or it can only sniff till layer 3 detail?

Tags:
Intrusion detection
Intrusion prevention systems
IPS
Hi. I have a scenario where an IPS is connected to the switch and is monitoring all the ports of it. I would like to know that whether this device can capture information till layer 3 (network layer) or it can capture full details of all seven layers, like which application, protocol and port is being used? Thanks. Your responses awaited. Cheers.

Answer Wiki

Thanks. We'll let you know when a new response is added.

The IPS should be able to see above layer 3. Layer 4 is where the session information resides – so it could tell the difference between UDP & TCP for example. It should be state-aware like a firewall. See the article on Intrusion Prevention Systems

IPS systems analysis all packets which are not encrypted. If you would would like to capture those packets you can do with the IPS or an ASA. Wireshark is free to download for the file analysis.

Discuss This Question:  

 
There was an error processing your information. Please try again later.
Thanks. We'll let you know when a new response is added.
Send me notifications when members answer or reply to this question.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to:

To follow this tag...

There was an error processing your information. Please try again later.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Thanks! We'll email you when relevant content is added and updated.

Following