cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
450
Views
0
Helpful
2
Replies

IDS Info

brymiller
Level 1
Level 1

Let’s be real -- the IDS documentation is miserable. It goes on endlessly without stated objectives and many of the screenshots are messed up. Ideally there should be a bunch of field notices that explain specific tasks. For instance, how to connect the IDS – showing how to make sure the monitor port is monitoring, along with an example of RMON and so on. Does anyone know of a place to find good explanations? Please don’t reply if you are one of those a-holes who is just going to point me back to the doc. Yes, I read the doc!

2 Replies 2

smalkeric
Level 6
Level 6

The Cisco IDS 4200 Series sensors are used in the Cisco Intrusion Protection System. These intrusion detection system sensors work in concert with the other components to efficiently protect your data and information infrastructure. With the increased complexity of security threats, achieving efficient network intrusion security solutions is critical to maintaining a high level of protection. Vigilant protection ensures business continuity and minimizes the effect of costly intrusions.

http://www.cisco.com/warp/public/cc/pd/sqsw/sqidsz/

Not too sure how this is going to help the original poster, since it links to the marketing information for the sensor appliances...

I too agree that the documentation lacks recommended best practices, particularly in regards to testing and validation of the system once deployed.

Unfortunately, I have yet to see any resource that specifically addresses such practices for Cisco IDS/IPS. There's plenty of IDS/IPS whitepapers that talk about the concepts of placement, configuration, testing, validation, etc. but they are vendor agnostic.

I can post some suggested links to this type of info if anyone would like, but I need to know if it is at all desired...

Alex Arndt

Review Cisco Networking products for a $25 gift card