Dealing with Switches
17
Figure 1 6 A typical connection scheme with one firewall and switched network.
If the switch you are using has a spanning port, you can connect the IDS machine
to the spanning port as shown in Figure 1 7. All network traffic, including internal data
flowing among company servers and the Internet data, will be visible to the IDS.
Figure 1 7 IDS connected a spanning port.
You can also connect the IDS to a small HUB or a Network TAP right behind the
firewall, i.e., between firewall and the switch. In this case all incoming and outgoing
traffic is visible to the IDS. The scheme is shown in Figure 1 8.
footer
Our partners:
PHP: Hypertext Preprocessor Cheap Web Hosting
JSP Web Hosting
Ontario Web Hosting
Jsp Web Hosting
Cheapest Web Hosting
Java Hosting
Cheapest Hosting
Visionwebhosting.net Business web hosting division of Vision Web Hosting Inc.. All rights reserved