cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
370
Views
4
Helpful
1
Replies

Getting started with IDS

dpatkins
Level 1
Level 1

Is there a generic step by step way for one to start his network off using IPS/IDS? We have 2 4235 1 FWSM and some PIXs and VPN concentrator soon to be monitored by CMS. Do I set the IDS device to report all information and then tweak from there? And at that point, we should be down to an actually workable amount of events by what? A 2 month timeframe? Thank you

1 Reply 1

lisa.hall
Level 2
Level 2

Cisco IOS Software Intrusion Prevention System (Cisco IOS IPS), with inline intrusion capabilities, is the first system in the industry to provide an inline, deep-packet-inspection-based IPS solution that helps enable Cisco. routers to effectively mitigate a wide range of network attacks. Armed with the intelligence to accurately identify, classify, and stop malicious or damaging traffic in real time, Cisco IOS IPS is a core component of the Cisco Self-Defending Network, which helps the network protect itself. This technology uses Cisco IPS Sensor Software and signatures. Because Cisco IOS IPS is inline, it can drop traffic, send an alarm, or reset a connection-facilitating immediate router response to security threats.

http://www.cisco.com/en/US/products/ps6634/products_white_paper0900aecd80327257.shtml

http://www.cisco.com/en/US/products/ps6634/products_ios_protocol_group_home.html

Review Cisco Networking for a $25 gift card