Because the IOS Firewall IDS supports intrusion detection
features for a wide range of Cisco router platforms, it can make a powerful
addition to any network perimeter. The features can be especially useful in
locations where a router is being deployed to provide additional security
between network segments, such as between the organization and a partner
site.
The Firewall IDS features can provide increased protection between
intranet connections, such as branch-office connections to the corporate office
or even providing additional security for an internal department like an R&D
program. Three examples of IOS Firewall IDS supporting the security goals of all
sizes of organizations include:
-
Small and medium-sized businesses looking for a
cost-effective way to add IDS features to their security policies for their
network router(s).
-
Enterprise customers looking for a cost-effective way to
extend their IDS security protection and policies across all network boundaries,
including branch-office, intranet, and extranet perimeters.
-
Service providers that want to provide router-based managed
firewall and intrusion detection services for their customers.
The IOS IDS support of the Cisco Secure IDS Director
security-management system allows many routers and the Catalyst 6500 family of
switches to provide additional security and visibility into the network in
support of the organization’s Cisco Secure IDS appliance implementation. The
Cisco Secure IDS appliance features and implementation are covered in detail in
the last four chapters of this book. cp7 cis