FirewallWizards
[Top] [All Lists]

Re: [fw-wiz] HIPS experience

To: "Firewall Wizards Security Mailing List" <firewall-wizards@listserv.icsalabs.com>
Subject: Re: [fw-wiz] HIPS experience
From: stursa@695online.com
Date: Wed, 23 May 2007 12:57:00 -0400 (EDT)
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.icsalabs.com
Importance: Normal
In-reply-to: <40ecb01f0705210430g45f3a7abk7fee2b26f12e7f82@mail.gmail.com>
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
References: <fe37588d0705151905q54309650m2bef9494d85eb1fd@mail.gmail.com><30525.69.1.110.133.1179506437.webmail@mail.695online.com> <40ecb01f0705210430g45f3a7abk7fee2b26f12e7f82@mail.gmail.com>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
User-agent: MailAdvantagePro/1.4.2
Paul Melson said:
> On 5/18/07, stursa@695online.com <stursa@695online.com> wrote:
>> Checkpoint has a very similar (i.e. behavioral, not signature-based
>> HIPS)
>> known as "Integrity Secure Client". The management center is
>> stand-alone,
>> costs about $3k IIRC. The client licenses cost less as well. For an
>> additional fee you get point-and-click access to a big database of
>> events
>> and software, so it's much easier to determine whether a particular .exe
>> is safe.
>
> This was originally ZoneLabs' Integrity, and at one point in time was
> the only way to enforce host security policy w/ the Cisco VPN3K.  It
> never worked with Check Point until after the acquisition.  To be
> honest, I'm a little surprised that after several releases the Cisco
> ASA/VPN3K support is still there.

Not sure if you mean releases of Integrity or releases of Cisco SW. WRT
Cisco, I just checked our 3020 and it's still in there. It's running 4.7,
rel 10 March 2005.

In the next week we're taking delivery of a new 3020, presumably with
latest software. I'll look and see if the support is still there.

I also checked our ASA, which is running 7.2(1), 31 May 2006. It likewise
appears to still support Integrity.

-- 
Scott L. Stursa
CCNA, MCSA, Security+
_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

<Prev in Thread] Current Thread [Next in Thread>