 




<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Want to Implement IDS &amp; IPS In Linux Firewall</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/wanht-to-implement-ids-ips-in-firewall/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers/wanht-to-implement-ids-ips-in-firewall/</link>
	<description></description>
	<lastBuildDate>Sun, 19 May 2013 03:14:28 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: rechil</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/wanht-to-implement-ids-ips-in-firewall/#comment-83856</link>
		<dc:creator>rechil</dc:creator>
		<pubDate>Tue, 16 Nov 2010 05:10:16 +0000</pubDate>
		<guid isPermaLink="false">#comment-83856</guid>
		<description><![CDATA[iPolicy Networks has a dedicated SWAT team of technical experts whose job is to track new security threats and develop IDS/IPS signatures. The signatures can be automatically downloaded to iPolicy Intrusion Prevention Firewalls deployed for immediate protection of networks.
An Intrusion Detection System (IDS) and IPS are security signatures that can be deployed at different levels in a network. IDS &amp; IPS can use different methods of detecting problems, but the most basic method is using signatures. Like an antivirus program checks files for virus signatures, and IDS will check network traffic for patterns associated with malicious network activity. As far as my knowledge the most popular and powerful of the free IDS solutions is &quot;Snort&quot;. To install SNORT and configure as ur necessity&#039;s.
U have to select an interface for Snort to listen on. It can also be run on the internal interface to inspect outgoing traffic. U have to set the IP address range of ur network. Snort has several configuration files, in which the most important are:

1. /etc/snort/snort.conf: This is the primary configuration file
2. /etc/snort/snort.&lt;linuxOS&gt;.conf: This file is created by the Apt installer. 
3. /etc/snort/threshold.conf: This file alerts if u&#039;re seeing lots of same warning. 
4. /etc/snort/rules/: This directory contains the snort rules (firewall signatures). These can be manually updated.
Remember u may also add custom IPS signatures. but this is another issue....]]></description>
		<content:encoded><![CDATA[<p>iPolicy Networks has a dedicated SWAT team of technical experts whose job is to track new security threats and develop IDS/IPS signatures. The signatures can be automatically downloaded to iPolicy Intrusion Prevention Firewalls deployed for immediate protection of networks.<br />
An Intrusion Detection System (IDS) and IPS are security signatures that can be deployed at different levels in a network. IDS &amp; IPS can use different methods of detecting problems, but the most basic method is using signatures. Like an antivirus program checks files for virus signatures, and IDS will check network traffic for patterns associated with malicious network activity. As far as my knowledge the most popular and powerful of the free IDS solutions is &#8220;Snort&#8221;. To install SNORT and configure as ur necessity&#8217;s.<br />
U have to select an interface for Snort to listen on. It can also be run on the internal interface to inspect outgoing traffic. U have to set the IP address range of ur network. Snort has several configuration files, in which the most important are:</p>
<p>1. /etc/snort/snort.conf: This is the primary configuration file<br />
2. /etc/snort/snort.&lt;linuxOS&gt;.conf: This file is created by the Apt installer.<br />
3. /etc/snort/threshold.conf: This file alerts if u&#8217;re seeing lots of same warning.<br />
4. /etc/snort/rules/: This directory contains the snort rules (firewall signatures). These can be manually updated.<br />
Remember u may also add custom IPS signatures. but this is another issue&#8230;.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 6/9 queries in 0.015 seconds using memcached
Object Caching 268/271 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-05-19 20:06:20 -->