Recommendations for IPS in Medium-Sized LAN?

I have two ASA-5520's in active/standby mode servicing a 500-node LAN w/ 1 outside interface, 1 inside interface, and 1 DMZ. How best to implement IPS, preferably using integrated modules, and without introducing a single point of failure? Also, what software would I need to install & manage IPS? Can it be managed thru ASDM or is something like Cisco Security Manager (CSM) necessary? TIA!

You don;t mention if you want to do in-line IPS or promiscious mode IDS.
We'll assume you want in-line IPS. You'll need an AIP-SSM module in each ASA5520 chassis. they will operate independantly (unlike the firewalls that maintain state between them), and you'll suffer a little when traffic fails over between active and standby ASAs. The size of the AIP-SSM modules will depend on how much traffic you're pushing thru your firewall interfaces that require inspection, including your DMZs. Don't believe the Cisco performance numbers. Since you only have two IPS sensors I wouldn't reccomend CSM. use the CLI, build in GUI or the free up-to-5-sensor management application.

Similar Messages

  • Recommendations for a simple, fast GUI LAN chat application? [Solved]

    We now have 4 ArchLinux machines scattered throughout the house. (My wife is an Archer now!). I am looking for a simple fast GUI LAN chat application. I looked at "qchat" but it is a bit cumbersome and doesn't have the option of a small applet to the panel. Any recommendations appreciated...
    Larry
    Last edited by lagagnon (2010-02-13 21:27:00)

    jwwolf wrote:Found this in AUR
    griv
    I just tried it with a few machines and it works fine.
    Excellent choice! Nice, light and unobtrusive. Works well, thanks for the recommendation.

  • Implementation methodology for medium sized clients

    Hi Friends
    I know there is ASAP methodology for Implementations(BW) which takes lot of time to go thru each and every step for which the medium sized clients cant afford(money).
    Can anyone comeout with a new customized implemetation methodology for medium sized clients which will be of great helpful....
    Points will surely be awarded

    Hi Hari,
    Here is the start. If you're asking for a customized implementation, specifically BW, you could probably draw some conclusions from the implementations that you have been through. For something that is not a "cookie-cutter" implementation from company to company, one thing to think about is:
    <u>Use people close to the business that can help you clarify their needs.</u>
    Instead of only using a system development lifecycle (SDLC) approach to getting the requirements, meet with the business users once a month and demo what you have built. In the beginning it might just be demo of standard content, but after a while you can solicit feedback on layout and design that will assure a system that is more aligned with the users needs. It also provides the users with a great way to interact with your team. BW projects should not be “dark horses” where requirements goes in one end and a solution emerges a few months later they may, or may not, meet the requirements. We do not build data warehouses; we are doing data warehousing (an active and interactive process).
    Best of Luck

  • Hardware sizing recommendations for B2B Server

    My customer Welch Foods Inc. is on 11i Oracle eBusiness Suite and is planning to uptake the latest 1Sync integration features in the PIM product. For out-of-box AS2 connectivity with 1Sync - they are planning to use Oracle B2B Integration Server 10.1.2.3.
    They have an average transaction volume of 30 transactions per month. One time - initial load of 20,000 transactions.
    Based on the above estimates, they are looking for hardware sizing recommendations for the B2B server.
    Your assistance is much appreciated.
    Asmi Maharishi
    SDM for Welch Foods.

    Thanks for your reply!
    Here are the responses to your queries:
    1. Is B2B instance going to run alone in a box
    Yes, B2B instance will run alone on a box.2. what will be the size of message
    Messages can be anywhere from 5-20 KB3. how many messages will be part of a transaction.
    It should be 2 - Registration and publication. But sometimes it depends on how successful the first “registration” goes. Typically we get one or two errors that the users go into PLM, correct and re-send.However, Looking at your current requirement, 30 transaction per month, we can easily address in a 4 GB machine itself.
    Additionally, Oracle B2B supports 10+ messages per second in 32GB, 4 processor machine.
    Memory suggested above is 4GB, does that take into account memory used by the 10G App server foot print or this is only to take care of messages? Also, how many Processors (Risk IBM) will be needed?

  • Log Sizing recommendation for DB6 / SAP CRM

    HI
    Can anyone have Tran Log sizing recommendation for DB2 for Unix ( DB6 ) to be used in SAP CRM 7.0 ?
    Thanks
    Kirubakaran

    Hi Kirubakaran,
    please have a look here
    1086130      DB6: DB2 9.5 Standard Parameter Settings
    or
    1329179      DB6: DB2 9.7 Standard Parameter Settings
    BR,
    Andreas

  • I need a recommendation for a 24" monitor for my late 2013 MacBook Pro

    I need a recommendation for a 24" professional photography monitor for my late 2013 MacBook Pro.  I am looking for a monitor that plays well with my 13" late 2013 Macbook pro.  I tryed the Dell U2413 and found after the fact that it did not work well with my Macbook pro.  Read up on the Asus PA 249Q, It also seems to have problems with my Macbook Pro.  Apple display is larger than i want.  Looking for recommendations for compatable IPS monitor for use with Aperture. buget is $300 to $800.
    Anybody happy with thiers?
    MacBook Pro with Retina display, OS X Mavericks (10.9), Aperture 3.5.1

    Any monitor will work. Decide what specs work best for your needs and get that monitor.

  • Timeout in waiting for IPS service to start. Component: IPS

    Hello
    I have an sa 520 and in logs i see the message
    <Timeout in waiting for IPS service to start.
    Component: IPS>
    i am sure that ips failed to start because although i have enabled ips in lan with
    Signature File SBIPS000019  i do not see any logs for ips events
    firmware version = 2.2.0.7
    the above happened after a facory reset and configuration from scratch

    Well the problem is now resolved. It was either faulty tapes (about 12 of) or two tape drives with faulty heads. We had the heads replaced in one of the drives and tested it with a new tape, it works perfectly again.
    MC

  • Recommendations for laptop coolers?

    Any recommendations for laptop coolers? I'm thinking aluminum, largest fans possible and I want it as large as the footprint of the MBP 15" (no little postage stamp sized units). I was considering the Startech NBCOOLERPRO. Opinions?

    While I haven't had a need for one these things seem to really work from the reviews I've read, lowing temps up to 10 degrees.
    http://www.amazon.com/s/ref=blsrelectronics?ie=UTF8&search-alias=electronics&field-brandtextbin=ThermaPAK
    Do a Google search of Thermapak reviews and you will see quite a few positive ones.
    Regards,
    Roger

  • Recommendations for Bluetooth GPS for N95

    Has anyone got any recommendations for a Bluetooth GPS receiver (to improve the dire performance of the inbuilt one) available in UK?

    I bought the Nokia N95 8GB for its 'all in one device 'convenience.
    I bought an external Bluetooth GPS, not because the inernal was no good, or not accurate enough but because I did not want to destroy it with vibration and rain, strapped to the handlebars of my Yamaha XT225
    I want to create tracks (kml?)that map out the roads, lanes and footpaths of Cebu, Philippines using my Motorbike, in places the car could not go.
    I decided on the Wintec G-Rays2 (WBT-201). This is more than just a Bluetooth GPS, as it has a 'logger' function also (collecting up to 131,072 waypoints). It is also much quicker at acquisition than the internal GPS (34 seconds or if data is still in memory 4-33 sec).
    Even in a car, the WBT-201 G-Rays2 unit, can be positioned on the dash, whilst from anywhere in the car, the N95 receives the NMEA0183 format data stream giving position, speed, altitude and time, together with estimated error and satellite status.
    'Sports Tracker' works very well with this for receiving the data stream 'live'. Once 'captured' it has many 'export' formats of the captured information. Test 'Tracks' of the same 'Route' using the internal GPS and another time the WBT-201, show the external unit to be more accurate. Having said that, the internal GPS is actually pretty good at capturing the same track.
    The only real 'negative' of the WBT-201, is the 'TMXTool' software (for configuring the settings, on the go, rather than connected to a PC), is for PPC, and not S60. However the 'TimeMachineX' software is OK for 'Windows' use.
    David

  • Medium Sized Business Backup Strategy

    Needing to improve a backup plan for a medium-sized business (about 30 employees), they are currently using Microsoft Azure Backup and Windows Backup to backup 4 Windows 2012 Servers (averaging
    300GB) plus one w/ a 1.2TB shared network drive.  The issue with the current solution is that we are now well over the Azure backup 825GB drive limit.
    They currently have a NAS Device w/ 8TB RAID Volume, I'd like to use in the solution.  I'm looking for a low cost solution to backup to the NAS device which will complete in a 4 hour
    nightly window.  I've tried using NovaBackup, to backup to the NAS device, but it's really slow.
    Any ideas?

    Hi,
    Thanks for your posting.
    As NAS is called Network Attached Storage device, so i think it may be under the influence of network speed.
    Did you try to backup to local device to check the result.
    Meanwhile, for the full backup firstly, it may cost much time.
    Regards.
    Vivian Wang

  • Hardware recommendations for Planning & HFM

    We currently have Hyperion Planning 11.1.1.3 running on three servers (one dedicated for RDBMS, one dedicate for Essbase, and another that is running everything else (EPMA, Planning, Financial Reporting, Shared Services, Workspace, Calc Manager, etc).
    We are going to implementing HFM and upgrading to 11.1.2 for our current components and I have reviewed the server sizing for 500 users (175 active) for Planning and HFM. I was wondering if anyone had any experience running both Planning and HFM together and if I need to bump up the server specs for anything to run both smoothly?
    The EPMA Installation Start Here recommends the following for Planning for Windows Servers:
    Web Server: 4 x 3 GHZ+ 16 GB RAM
    Essbase Server: 4 x 3 GHZ+ 8 GB RAM
    Other Services Server: 4 x 3 GHZ+ 16 GB RAM
    RDBMS Server: 4 x 3 GHZ+ 16 GB RAM
    And recommends for HFM:
    Web Server: 4 x 3 GHZ+ 16 GB RAM
    Financial Management Server: 8 x 3 GHZ + 16 GB RAM
    Other Services Server: 2 x 3 GHZ + 8 GB RAM
    RDBMS: 4 x 3 GHZ+ 16 GB RAM
    The Essbase server for Planning will be dedicated, and the Financial Management Server for HFM will be dedicated, but if we wanted to share the Web Server and Other Services Server for both Planning and HFM, do you think we need to size these servers a bit more robustly to handle both HFM and Planning?
    We are looking at 8 x 2.66 GHZ with 32 GB of memory for our Web Server, Other Services Server and Financial Management Server (essbase and RDBMS are sized fine for now), so I just wanted to get some input from the community before we make the recommendation to go ahead with that hardware.
    Thanks!

    Depending upon your Essbase/Planning Application you might need to increase the Ram. Remember you plan the architecture for 3 - 5 years in mind. Its a good practice to have variable like number of users increase per year, new applications, evolving data-set etc into consideration.
    In one of the post, one of the expert suggested to have 2Gb per essbase application.
    HTH
    MN

  • Satellite 1000-Z2: I need a driver for the display and the LAN

    Hi
    I have reformatted my laptop S1000-Z2, and I am having real trouble trying to find any information on this model !
    Basically I need a driver for the display, and the LAN ?
    Best Regards,
    Austin.

    What OS do you use???
    If you use the XP you will not find the LAN driver on the recommended driver site!
    I can not give you any advices where to find such driver because I dont know what LAN card is installed in your oldie.
    But why you dont check this yourself? Try to find out what LAN card you use and googel a little bit for compatible applications ;)

  • Recommendations for Bluetooth headphones?

    Does anyone have a recommendation for a good set of Bluetooth stereo headphones?  I am looking mainly to listen to music and watch videos but would make an occasional call with them. I purchased the Plantronics backbeat and while the sound quality is fine they just don't get loud enough. I have read similar complaints about the Jaybird freedom.  Any suggestions?
    Thanks

    yup.. this was added to Leopard 10.5... 10.5 is REALLY flaky though (all around, not bluetoothwise)... 10.5.2 is what you need.
    but with 10.5.2 installed i use the Motorola MOTOROKR™ S9 with a Belkin USB bluetooth adapter (class 1 so get 300 ft range)... works really well... good for exercise 'cause they are light and they stay in your ears securely and can take sweat etc and they are sound isolating and have two sizes of in ear thingies for different sized ears.
    plus have Advanced Audio Distribution Profile (A2DP) and Audio Video Remote Control Profile (AVRCP). AVRCP lets you control iTunes and volume from the head phones... back, forward, play, pause, volume up and down.. they are really cool and work perfectly.
    http://direct.motorola.com/ens/s9/Headset_Home.asp

  • Recommendations for a new monitor?

    Greetings,
    I'm looking for a new monitor for my Powermac G4 450 MHz AGP (sawtooth).
    I'm currently using a Formac Gallery 1740 after 6 years it's starting to faded out on me.
    I'd really appreciate any suggestion or Recommendations for a new one.
    Aisha K.

    I'm using a 17" LCD, Acer model AL1706 on my G4 400MHz AGP. Was plug 'n play and has been flawless over the years. I'm sure the current model numbers are different.
     Cheers, Tom
    Here's some Acer model LCD monitors.
    http://www.amazon.com/Acer-19-inch-Flat-Panel-Monitor/dp/B0002X8TVW
    Message was edited by: Texas Mac Man

  • Need a printer recommendation for a small office

    hey folks, hoping someone might be able to suggest a recommendation for our business. We’ve had an OkiData color laser printer that’s lasted over 6 years but it’s been giving us some trouble over the last year and yesterday it stopped printing with an error we can’t resolve. Would have to bring a tech in to fix and we’d basically already decided that once this thing bit the dust we’d move on to something else. It’s time.
    We are looking for something in the $200-$400 range, would consider going a little higher if it was clearly worth it. We want something that connects wireless, prints quickly and reliably in Snow Leopard over an Airport Extreme network, decent color print quality is important but doesn’t have to be photo quality (we have an HP Photosmart for that kind of stuff), and it needs to have reasonable printing cost per page. We don’t print a tremendous amount of stuff, but we probably go through 100-200 pages a day and it adds up.
    Was looking at the HP OfficeJet Pro 8500 wireless and that looks like a nice unit except half the people who buy one hate it. Looks like HP quality control is lacking and if you get a good unit, great, but the odds are good you’ll get a lousy one.
    Also looking at the Brother HL-3070CW, but reviews say it has a high consumable cost.
    Basically, the more I look into this the more I head spins and now I've got myself wrapped around the axle and don’t know what to do.
    Any suggestions would be GREATLY appreciated.

    I would steer clear of the 500 express. Since you seem to be new to cisco products, I would use the opportunity and buy what most of your potential customers already have. Get yourself a pix/asa and a 2900 series switch as first poster suggested. If you are interested in certifications, you will need to learn the command line interface. The 500 express will do you no good as it is all gui. This is only my opinion of course. Oh, and did I see not expensive and cisco in the same sentence. :)

Maybe you are looking for

  • How do I fix aperture 3 after upgrade from Aperture 2 to 3?

    Hello. I have had a good search but can't find the answer. 1. 2 days ago I made a full time machine of my mac 2. local mac shop did a clean install from 10.5 to 10.6.8 3. local mac shop then installed aperture 3 4. I then tried to update my new 10.6

  • Error in Send email notification in Incident Management

    Dear Experts , Could you please help me where I am going wrong. Here is my problem. Step-1: Trying to send an email. Step  2: Once clicked on Send E-mail. Below screen appears Step 3: I followed http://scn.sap.com/docs/DOC-35291 . Now I have made som

  • J2ME And JSP...

    Hi there Experts... i am new to J2ME and i need to connect my MIDP forms to jsp.. i dont have any idea about that. Is it possible to pass values those been selected by an user from mobile device to the jsp and again answer from jsp to he mobile devic

  • Exception in two places of insert statment

    Hi All, I want to insert exception in two places in pl sql. I am getting the error.Is there a way to implement exception in two places in insert statement. Thanks, uday Begin Declare V_Code Number; V_Errm Varchar2(64); V_Code1 Number; V_Errm1 Varchar

  • E51 wlan settings

    I have got a problem. I can set up wlan in my school. Free wland wokr without problems but, in my school everyone have they own name and password. It is good for notebook, but I want to try it by mobile. They said to me it was possible. Certificate i