SD-WAN

 View Only
last person joined: 6 days ago 

Ask questions and share experiences with SD-WAN and Session Smart Router (formerly 128T).

Bro/Zeek IDS with Service Chaining 

03-27-2019 12:20

Quite a few customers have expressed positive experience with the Bro IDS (recently renamed "Zeek").  This tool operates differently than Surricata and Snort and provides some great tools for searching for that network "needle in a haystack".  There is a decent library of plugins and notification tools that make Bro and excellent addition to any IDS solution.

Getting started with the Bro/Zeek IDS is quite easy using 128T's service chaining capability.  The IDS tools may be embedded directly into a 128T router to reduce the complexity of a physical deployment.

It should be noted that Bro is single threaded by design, with the expectation that load balancing is used to scale up to large deployments.  The solution presented in the attached document is intended for smaller branch offices that do not require multi-gigabit throughput.  Scaling up to central site speeds would almost surely require 128T load balancing, CPU affinity or even a separate platform for dedicated processing, so be sure to carefully design your traffic flows to avoid a bottleneck at the IDS.

Feel free to send a note with any corrections/errors.  This process has been lightly tested as a 3rd party integrated solution.

Happy hunting!

#IDS #Zeek #Bro #LoadBalancing #ServiceChaining​​​

Statistics
0 Favorited
2 Views
1 Files
0 Shares
2 Downloads
Attachment(s)
pdf file
128T Bro IDS Deployment v1.2.pdf   689 KB   1 version
Uploaded - 09-13-2021

Related Entries and Links

No Related Resource entered.