Intrusion Detection
Feb 08,2010 00:00 by alperen

Intrusion Detection

The Cisco Secure PIX Firewall, like the Cisco Secure IOS Firewall covered in Chapter 7, added intrusion-detection technology to extend the Cisco Secure IDS technology. IDS sensor incorporation into the firewall is ideal for locations requiring additional security between network segments. It can also provide enhanced visibility at intranet, extranet, and branch-office Internet perimeters.

PIX Firewall IDS v6.2 audits (monitors) 53 attack signatures, representing a broad cross section of severe security breaches and the most common information-gathering scans. The PIX Firewall IDS technology auditing is performed by looking at the IP packets as they arrive at an input interface. If a packet matches an active signature, the IDS can perform any or all of the following actions based on the predefined router configuration:

  • Alarm Sends an alarm to a Syslog server and/or a Cisco Secure IDS Director

  • Drop Discards the packet

  • Reset Resets the questionable TCP connection

Any packet that triggers a signature for which the configured action doesn’t drop the packet, can then trigger additional signatures.

PIX Firewall IDS supports both inbound and outbound auditing, as well as interface specific auditing.