Intrusion Detection System Server Load Balancing - Nortel Web OS Switch Software Application Manual

Switch software
Table of Contents

Advertisement

Intrusion Detection System Server Load Balancing

Intrusion Detection System (IDS) is a type of security management system for computers and
networks. An Intrusion Detection System gathers and analyzes information from various areas
within a computer or a network to identify possible security breaches, which include both
intrusions (attacks from outside the organization) and misuse (attacks from within the organi-
zation).
Intrusion detection functions include:
n
Monitoring and analyzing both user and system activities
n
Analyzing system configurations and vulnerabilities
n
Assessing system and file integrity
n
Recognizing patterns typical of attacks
n
Analyzing abnormal activity patterns
n
Tracking user policy violations
Intrusion detection devices inspect every packet before it enters a network, looking for any
signs of an attack. The attacks are recorded and logged in an attempt to guard against future
attacks and to record the information about the intruders.
IDS Server Load Balancing helps scale intrusion detection systems since it is not possible for
an individual server to scale information being processed at gigabit speeds.
How Intrusion Detection Server Load Balancing Works
Web OS allows the switch to forward the IP packets to an Intrusion Detection server at the end
of the filtering process or at the end of client processing (when filtering is not enabled). The
user must enable IDS SLB on the port and allocate a real server group for IDS Server Load
Balancing. The IDS SLB-enabled switch copies all incoming packets to this group of intrusion
detection servers. For each session entry created on the switch, an IDS server is selected based
on the IDS server load-balancing metric.
The IDS server receives copies of all the processed frames that are forwarded to the destination
devices. Session entries are maintained so that all the frames of a given session are forwarded
to the same IDS server.
Each IDS server must be connected directly to a different switch port or VLAN because no
field in the packet header can be substituted. Substituting a field would corrupt the packet that
must also be forwarded to its real destination.
212777-A, February 2002
Web OS 10.0 Application Guide
Chapter 6: Server Load Balancing
n
163

Advertisement

Table of Contents
loading

This manual is also suitable for:

Web os 10.0

Table of Contents