Doubts about DoS and where to apply IPS sensor.
Hi ¡¡¡ I have 2 doubts:
1) I have published WEB servers, which are in my DMZ. I have adjusted thresholds and protected them against TCP attacks since they only allow HTTPS traffic. I suppose there is no point in protecting them from other types of attacks DoS (UDP, ICMP etc). On the other hand, my firewall connects to an ISP and receives the public IP on one of its interfaces directly (witouth NAT). Is not the public IP (VIP) to connect to the web servers but is the same internet connection. This interface doesn't have any administrative acces enable (ICMP, HTTP etc are disable). I was wondering if I should protect the interface itself from DoS attacks, but I understand that it is not necessary since I do not have any services enabled. If there is no service enabled, they cannot do a DoS. However, I have monitored the IP of the interface with very low thresholds and if found anomaly alerts come out and I don't understand why it detects them when ports or services that are not open are attacked. Should I protect my firewall interfaces, which do not have any services up, from DoS attacks? Why do attack attempts appear if I monitor them, when they don't have any services up?
2)I have another doubt about IPS sensors. I have 2 firewalls between my DMZ. One connects to the internet and the other to my network. All the services that I have published in my dmz are protected with IPS sensors and deep inspection, they are usually Web servers.
On the other hand, all the traffic that enters from the DMZ to the intranet is also protected with IPS in the internal firewall but I wonder if it is necessary. I understand that if there was a worm (for example) on a server in my DMZ it could spread to my intranet if users connect to the infected server and there are no IPS, for example. I also have IPS sensors between my datacenter and user networks. Could you tell me if the use of IPS is correct or should I not use it on my intranet?
Thanks ¡¡¡¡
