cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
271
Views
10
Helpful
4
Replies

Can Ids monitors both incomming and outgoing traffic or both simulatneously

Zaheer_Assariya
Level 1
Level 1

Q1 Can IDs monitoring interface monitor both incomming and outgoing traffic simultaneously (i have just one ids monitoring interface on ids)?

Q2) If i have only on monitoring interface on my IDS, can I monitor traffic thats comming via two different routers. The routers are not physically at the same location. If yes then how if no then whats the best solution ?

Thanks

4 Replies 4

sachinraja
Level 9
Level 9

Hi zaheer,

Yes.. both incoming & outgoing traffic can be monitored by the IDS...

Monitoring in IDS is just based on what traffic you are going to SPAN at the switch. It just acts like a syslog server, collecting the details it gets from the switch. So, if you have set SPAN on both directions, IDS will monitor and report that.

2) Again... it all depends on how you can span the traffic to the IDS port.. if both the routers are connected to switches, which are on the same domain and trunked to each other, you can do a RSPAN and remotely monitor the other router's port.. in this case, you will get the IDS reports for both the routers.

Hope this helps !!

All the best..

Dear Sachinraja,

It was a very helpfull reply. I am still not clear in one part , if I have one monitoring interface in IDS, can this monitoring interface be used to monitor both incomming and out going traffic simultaneously at a single physical interface for example S1 or i need two differnt monitoring interface (one for incooming traffic at S1 and the other for outgoing traffic at S1).

Zaheer,

IDS generally has only one sniffing interface (bu default) which can monitor both incoming and outgoing traffic.. you dont need any more interfaces, unless the service is a isolated one..

consider this example..

router --> switch <-- IDS sniffing interface...

consider.. router - Fa0/1 , IDS Fa 0/2

on the switch you will configure..

monitor session 1 source interface fa0/1 both

monitor session 1 destination interface fa0/2

"both" keyword will forward both the incoming & outgoing traffic to the IDS. IDS will just see these packets and act upon..

so.. you just require one monitoring interface on your scenario..

All the best !!

Hey ,

Thanks for the help..it was awsome. Takecare