logo       

RE: How much "out of band" is enough ?: msg#00008

security.ids

Subject: RE: How much "out of band" is enough ?

Rainer,

It depends on your level of paranoia. VLAN's cannot provide security if,
for instance, VTP or 802.1q is tampered with, or if the switches themselves
become compromised.

Jared

-----Original Message-----
From: Rainer Duffner [mailto:rainer@xxxxxxxxxxxxxxx]
Sent: Friday, February 04, 2005 10:47 AM
To: focus-ids@xxxxxxxxxxxxxxxxx
Subject: How much "out of band" is enough ?

Hello,

I'd like to know, how the "out of band" management of IDS and related
SW/HW is done in various environments.

E.g.: for LAN, is it necessary to use separate switches or are VLANs
enough ?
(May depend on the policy).
And for WAN, do you rent separate leased-lines or is it just another
VPN-tunnel in the line ?




Thanks in advance,
Rainer

--
===================================================
~ Rainer Duffner - rainer@xxxxxxxxxxxxxxx ~
~ Freising - Munich - Germany ~
~ Unix - Linux - BSD - OpenSource - Security ~
~ http://www.ultra-secure.de/~rainer/pubkey.pgp ~
===================================================


--------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from
CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
--------------------------------------------------------------------------

--------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from
CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
--------------------------------------------------------------------------




<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise