[null] IPS hardening guide or checklist

172 views
Skip to first unread message

Shah Dhruv

unread,
Dec 1, 2014, 12:28:12 AM12/1/14
to null-...@googlegroups.com
Hey null members ,
I've been searching on google and on a few benchmarked websites but unable to get an IPS checklist or a hardening guide .
Can anyone help me with one ?
The IPS is IBM Proventia.




______________________

Dhruv Shah aka Snypter
about.me/snypter
Dhruv Shah on about.me
 
Blogger | Researcher | Consultant | Writer

TAS

unread,
Dec 1, 2014, 2:01:03 AM12/1/14
to null-...@googlegroups.com
Below are some generic pointers that should help. 

1. Firmware and license.
2. Signature/Vaccine updates schedule
3. How will set up default action of the signature
4. Forwarding the logs to SYSLOG or SIEM
5. Configuring the alert email and report recipient
6. Configuring alerts of when sensors going down
7. Authentication on the device (LDAP, 2FA etc.)
8. Remote administration of the device
9. Configuration mode: Inline (blocking) Promiscuous Mode
10. SSL offloading is important - If the SSL is offloaded on the server then your IPS can hardly flag something. But these are sometimes regulatory requirements. 

HTH




--
_______________________________________________________________________________
null - Spreading the right Information
null Mailing list charter: http://null.co.in/section/about/null_list_charter/
---
You received this message because you are subscribed to the Google Groups "null" group.
To unsubscribe from this group and stop receiving emails from it, send an email to null-co-in+...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Shah Dhruv

unread,
Dec 3, 2014, 3:20:41 AM12/3/14
to null-...@googlegroups.com

Something is better than nothing .. Thanks ..

vinay kadagave

unread,
Dec 3, 2014, 10:41:01 AM12/3/14
to null-...@googlegroups.com
I would like to add some points to TAS's list.

11. Change the default password of the IPS/IDS.
12. auto Configuration/policy  backup.
13. If the box is inline then check if built in Bypass kit is available or need external bypass kit.




Thanks & Regards,

Vinay

Reply all
Reply to author
Forward
0 new messages