Re: IDS/IPS system with Foundry sFlow
Martin Roesch <[email protected]>
| Newsgroups | gmane.comp.security.ids |
|---|---|
| Message-ID | <[email protected]> |
When you say "with sFlow" do you mean analyze the sFlow records or analyze the packets on the wire and correlate it with the sFlow data? -- Sent from my iPhone On Apr 21, 2008, at 3:42 PM, "Security Group" <[email protected]> wrote: > Hello, > > We have got a network with an embedded support for sFlow technology. > We also want to have a good IDS/IPS system. Does anyone know a good > setup with our foundry? > > We noticed that Foundry got their own application called "IronView > Network Manager", it is able to operate with snort. Does anyone know > of this is a good solution? Or should we use an sFlow converter (e.g. > InMon sFlow toolkit) that can work with snort? > > What are the other possibilities for IDS/IPS besides snort. It has to > operate with the sFlow technology. > > Kind regards, > > Babel Timo > > --- > --------------------------------------------------------------------- > Test Your IDS > > Is your IDS deployed correctly? > Find out quickly and easily by testing it > with real-world attacks from CORE IMPACT. > Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw > to learn more. > --- > --------------------------------------------------------------------- > ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw to learn more. ------------------------------------------------------------------------