JuniperForum.com
September 07, 2010, 07:17:03 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: If you have an interesting idea for an article or knowledgebase entry, please submit it!
 
  Home Help Login Register  
* *
Pages: [1]
  Print  
Author Topic: Best Policy Practice on IDP  (Read 849 times)
Capt_Winters
Sr. Member
****
Posts: 268


View Profile
« on: September 09, 2008, 02:56:16 AM »


Hi Gurus,

  Any recommendation on best practices when it comes to POLICIES?

  Like policy hardening, fine tuning..etc.

  My rule on IDP right now is..


  Is to accept all traffic from any any to my network with all major and severity accepted

 Im going to gather all reports then fine tune the policy with DROP as action..

any suggestions?

thank you..

winters
Logged
bwalker
Newbie
*
Posts: 5


View Profile
« Reply #1 on: September 11, 2008, 08:41:48 AM »


Hello Winters,

That's basically what I did.  I don't use Juniper, I prefer Stonesoft's IDS/IPS solution but I approached the implementation in the same way.

The last thing you want to do (especially if you are introducing inline IPS) is to put the device in and have it blocking legitimate traffic.  As with all IDS/IPS you have to base-line it - let it log and then you can determine what is the "norm" for your environment.  This can take as long as you like (I did it for 4-6 weeks) and then from the information it found I fine tuned my policy.

The nice thing about the StoneGate IPS is that it has a "passive termination" feature which means that it allowed all traffic to pass but logged any traffic that it would have blocked in "active termination" in a different colour which made it loads easier for me to decipher the logs and build my policy.

Good luck with your implementation.

Brian
Logged
Frac
Hero Member
*****
Posts: 784


View Profile WWW
« Reply #2 on: September 22, 2008, 06:16:25 AM »

Hi,

you have a nice tool in juniper idp for this! (profiler)

you can create a violation rule base and then let profiler run for 3 weeks and compare this rulebase with the profiler database.

you will then see all the traffic that isn't included in your violation rulebase.

GreetZ,
Frac
Logged

JNCIS-FWV, JNCIS-ER, JNCIA-EX, JNCIA-IDP http://juniper-frac.blogspot.com
Pages: [1]
  Print  
 
Jump to:  

Navigation

Donate

Please consider donating if we've saved you time or money. It helps pay for the bandwidth, equipment, and hosting charges to keep this site running

Tools

Submit Article/KB - Do not submit questions here.

Recent

Stats

Members
  • Total Members: 22513
  • Latest: eklein
Stats
  • Total Posts: 40575
  • Total Topics: 11249
  • Online Today: 77
  • Online Ever: 393
  • (August 06, 2008, 07:40:57 AM)
Users Online
Users: 4
Guests: 72
Total: 76
TinyPortal v1.0 beta 4 © Bloc
Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!

Sponsored in part by CollarWise

Page created in 0.206 seconds with 37 queries.