TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------

Refer to the ISS RealSecure Getting Started Guide and ISS RealSecure 
User's Guide for specific Windows NT Workstation 4.0 hardening settings 
that is highly recommended by ISS.  I would attempt not to deviate from 
some of their recommendations since some of the common NT hardening may 
possibly disable ISS RealSecure features.

/mark




[EMAIL PROTECTED]
Sent by: [EMAIL PROTECTED]
04/03/00 02:20 PM

 
        To:     [EMAIL PROTECTED]
        cc: 
        Subject:        RE: Installing RealSecure Questions


Someone had mentioned that I should harden my OS before I install the 
actual RealSecure software.  Does anyone have any sites that I could go to 
for a reference or some general tips I should consider?

Mark

Return-Path: <[EMAIL PROTECTED]>
Received: from  rly-zc05.mx.aol.com (rly-zc05.mail.aol.com [172.31.33.5]) 
by      air-zc03.mail.aol.com (v70.20) with ESMTP; Mon, 03 Apr 2000 
16:51:03        -0500
Received: from  n3cdoimmail200m.hood.army.mil 
(n3cdoimmail200m.hood.army.mil  [150.114.100.200]) by rly-zc05.mx.aol.com 
(v70.21) with ESMTP; Mon,       03 Apr 2000 16:50:47 1900
Received: by hood.army.mil with Internet Mail Service (5.5.2650.10)     id 
<2GZ27QFV>; Mon, 3 Apr 2000 15:47:21 -0500
Message-ID: <82486B3C76CAD21185320090272A7C41038E9188@N3CDOIMMAIL120M>
From: "Lincoln, Harvey SFC--G6" <[EMAIL PROTECTED]>
To: "'[EMAIL PROTECTED]'" <[EMAIL PROTECTED]>
Subject: RE: Installing RealSecure Questions
Date: Mon, 3 Apr 2000 15:47:02 -0500
X-Mailer: Internet Mail Service (5.5.2650.10)

The IDS should be placed behind the Firewall so it can detect anything 
that
might get through the firewall

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, March 28, 2000 12:02 PM
To: [EMAIL PROTECTED]
Subject: Installing RealSecure Questions


I'm going to install RealSecure in our dmz network, and I was 
contemplating
on whether or not the IDS should be sitting outside or behind our 
firewall.
My objective is to monitor traffic targeting our web servers.  Does anyone
have any insights on the pros and cons as to where the IDS should be 
placed
on the network?

I'm getting ready to install the RealSecure console and engine.  Does it
matter if I do that first, then set up the machines in promiscous mode or
should I set up the machine so that it is dual-homed and then install the
console and engine software?

Also, does anyone know of any known vulnerabilities that should be fixed
before I place the IDS in a production environment?  If I place the 
machine
outside our firewall should certain ports be disabled? Do certain ports 
also
need to be diabled if the RealSecure box is sitting behind our firewall?

Sorry for the long list of questions, but any help would be appreciated.

Thanks,
Mark









Reply via email to