© SANS Institute 200
8
,
Author retains full rights.
© SANS Institute 200
8
, Author retains full rights.
Key fingerprint = AF19 FA27 2F94 998D FDB5 DE3D F8B5 06E4 A169 4E46
Network IDS & IPS Deployment Strategies
As mentioned previously, the risk introduced with placing either an IDS or IPS
inline is related to the likelihood of the system failing resulting in the link being
brought down. Some commercial systems will go into failsafe mode where they
default to being open and minimize risk of a device failure causing network outage.
Security and network analysts should know outage caused by system failure must be
avoided if at all possible. The mission of deploying security controls is defeated
when the controls themselves are excessively prone to failure. Especially when their
failure unintentionally brings down large scale network connectivity.