IDS selection?

Unanswered Question
Feb 27th, 2007

Hello All,

In fact i am a Linux guy, somehow pulled to select cisco hardware for our data centre , that is the reason asking silly question :) but you have to bare it, heh

In fact we are planning to have PIX 515 for our data centre , is it possible to configure PIX as IDS as well ? or we have to buy seperate IDS hardware, if we have to buy seperate, then what is recommended hardware.

thanks

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Richard Burts Tue, 02/27/2007 - 08:27

Nayyar

If you are purchasing equipment for the data centre and get a PIX 515 then you would need additional hardware for IDS. And the PIX is relatively old technology at this point. Cisco has introduced a new product line the ASA5500 which strategically will be the replacement product for PIX. You can get an ASA5510 which has an IDS module as part of the equipment which will perform better than the PIX and probably cost less than the PIX plus an IDS.

My suggestion to you is to look into the ASA5500 products as the equipment for your data centre.

HTH

Rick

dhengste7 Fri, 03/23/2007 - 08:11

To follow up, even though the 515 has a ids function, or is that just part of the Java module for the PDM?

I had read that you can enable IDS with the IP audit command in the cli. In the pdm the options on the policy to interface mappings have none in the drop down menus. TIA

abinjola Fri, 03/23/2007 - 19:50

are you looking for an extensive IDS/IPS functionality ? if not then yes you may certainly go for pix 515 "E"...

there are just 50 signatures supported by Pix fw

in order to be able to add some signatures to the PIX FW you can use the

IP audit command, please follow this URL for more information about this

command:

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref

/gl.htm#wp1101884

note that not all the signatures are supported on the PIXOS code,

below is the list of supported signatures:

http://www.ciscotaccc.com/kaidara-advisor/security/showcase?case=K93520960

the support for all IDS signatures, this is only available for IDS sensors.

regarding the new FW family 'ASA' here is a link where you can find some

useful information about it,

http://www.cisco.com/en/US/customer/products/ps6120/index.html

so now decide if you wanna save the money or save the network..:-)

dhengste7 Sat, 03/24/2007 - 04:17

Looking for at least some IDS functionality since we already have a 515E ur Pix. Is the IDS feature cli only? The pdm doesn't seem to be helpful.

Would Snort be a better option? thanks.

Actions

This Discussion