OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: IDS on switch with multiple VLANs
From: Eckert, Brian (brian.eckertATTWS.COM)
Date: Thu Nov 02 2000 - 08:57:51 CST


You might want to look into Ethernet Taps. eTaps cost from $400 to $600
each.

thx...b

Brian W. Eckert
AT&T Wireless Services
NDCO Security Project Manager
(o)214.547.2191
(c)214.213.8981
(f)214.547.2290
brian.eckertattws.com

-----Original Message-----
From: Michael Young [mailto:mikeutopia2.com]
Sent: Wednesday, November 01, 2000 6:14 PM
To: FOCUS-IDSSECURITYFOCUS.COM
Subject: IDS on switch with multiple VLANs

I'm currently faced with the problem of implementing an IDS in an
environment where multiple VLANs from different subnets exist on a single
switch. Spanning port technology won't help, as you can only have 1
spanning port per switch, so only one VLAN gets the IDS. I've considered
agent-based network IDS, but wonder if the cost per host becomes
prohibitive at around 17,000 machines.

Is there a simple solution I'm missing?