7. Intrusion Detection

Note

Advanced Intrusion Detection is only available on SG575 models. Other models offer Basic Instrusion Detection and Blocking only.

The CyberGuard SG appliance provides two intrusion detection systems (IDS). The lightweight and simple to configure Basic Intrusion Detection and Blocking, and the industrial strength Advanced Intrusion Detection.

Basic and Advanced Intrusion Detection take quite different approaches. Basic Intrusion Detection offers a number of dummy services to the outside world, which are monitored for connection attempts. Clients attempting to connect to these dummy services can be blocked. Advanced Intrusion Detection uses complex rulesets to detect known methods used by intruders to circumvent network security measures, which it logs to a remote database for analysis.

To guard against intrusion attempts, use Basic Intrusion Detection and Blocking. For highly detailed diagnostic reports of intrusion attempts, use Advanced Intrusion Detection. You can choose to use Basic and Advanced simultaneously.

Read on to find out how using an IDS can benefit your network’s security, or skip ahead to the Basic or Advanced Intrusion Detection section for an explanation of configuration options.

89

Intrusion Detection

Page 93
Image 93
SnapGear 2.0.1 user manual Intrusion Detection