cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
292
Views
0
Helpful
2
Replies

IDS place

wdong
Level 1
Level 1

Where is the best place of IDS? outside firewall or inside firewall?

1 Accepted Solution

Accepted Solutions

travis-dennis_2
Level 7
Level 7

It depends on what you want to accomplish. If you want to see most every attack that is coming at you then you would put the IDS in front of the firewall. You will also be getting alot more information to manage but you can see who is trying what and how often. If you only want to try and catch anyone who gets past the firewall then put it behind the firewall. You get much less information to manage this way and you still can issues shuns to the firewall but unless you are monitoring your firewall very closely you will not see every attack or recon since the firewall shuold be catching and dropping most of that traffic.

View solution in original post

2 Replies 2

travis-dennis_2
Level 7
Level 7

It depends on what you want to accomplish. If you want to see most every attack that is coming at you then you would put the IDS in front of the firewall. You will also be getting alot more information to manage but you can see who is trying what and how often. If you only want to try and catch anyone who gets past the firewall then put it behind the firewall. You get much less information to manage this way and you still can issues shuns to the firewall but unless you are monitoring your firewall very closely you will not see every attack or recon since the firewall shuold be catching and dropping most of that traffic.

Thanks!