When you say "with sFlow" do you mean analyze the sFlow records or
analyze the packets on the wire and correlate it with the sFlow data?
--
Sent from my iPhone
On Apr 21, 2008, at 3:42 PM, "Security Group" <secgro (at) gmail (dot) com [email concealed]> wrote:
> Hello,
>
> We have got a network with an embedded support for sFlow technology.
> We also want to have a good IDS/IPS system. Does anyone know a good
> setup with our foundry?
>
> We noticed that Foundry got their own application called "IronView
> Network Manager", it is able to operate with snort. Does anyone know
> of this is a good solution? Or should we use an sFlow converter (e.g.
> InMon sFlow toolkit) that can work with snort?
>
> What are the other possibilities for IDS/IPS besides snort. It has to
> operate with the sFlow technology.
>
> Kind regards,
>
> Babel Timo
>
> ---
> ---------------------------------------------------------------------
> Test Your IDS
>
> Is your IDS deployed correctly?
> Find out quickly and easily by testing it
> with real-world attacks from CORE IMPACT.
> Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaig
n=intro_sfw
> to learn more.
> ---
> ---------------------------------------------------------------------
>
Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaig
n=intro_sfw
to learn more.
------------------------------------------------------------------------
analyze the packets on the wire and correlate it with the sFlow data?
--
Sent from my iPhone
On Apr 21, 2008, at 3:42 PM, "Security Group" <secgro (at) gmail (dot) com [email concealed]> wrote:
> Hello,
>
> We have got a network with an embedded support for sFlow technology.
> We also want to have a good IDS/IPS system. Does anyone know a good
> setup with our foundry?
>
> We noticed that Foundry got their own application called "IronView
> Network Manager", it is able to operate with snort. Does anyone know
> of this is a good solution? Or should we use an sFlow converter (e.g.
> InMon sFlow toolkit) that can work with snort?
>
> What are the other possibilities for IDS/IPS besides snort. It has to
> operate with the sFlow technology.
>
> Kind regards,
>
> Babel Timo
>
> ---
> ---------------------------------------------------------------------
> Test Your IDS
>
> Is your IDS deployed correctly?
> Find out quickly and easily by testing it
> with real-world attacks from CORE IMPACT.
> Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaig
n=intro_sfw
> to learn more.
> ---
> ---------------------------------------------------------------------
>
------------------------------------------------------------------------
Test Your IDS
Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaig
n=intro_sfw
to learn more.
------------------------------------------------------------------------
[ reply ]