IDS - sensing interfaces

From: Tim (ccie2be@nyc.rr.com)
Date: Thu Dec 01 2005 - 20:48:20 GMT-3


Hi guys,

 

Can the types of intrusions being monitored for be different on different
sensing interfaces on the same IDS device?

 

For example, let's say an IDS has 3 sensing interfaces each monitoring
different subnets.

 

On one subnet - the outside untrusted subnet, I want to monitor for DOS
attacks and some other things but on my inside, trusted subnets I don't want
to monitor for DOS attacks.

 

Is this possible? And, if so, how would I configure this?

 

Thanks, Tim



This archive was generated by hypermail 2.1.4 : Mon Jan 09 2006 - 07:07:50 GMT-3