Jump to content

Recommended Posts

Posted

Before I log a call with smoothwall, does anyone know if you can disable IPS/IDS for certain external IP addresses?

 

We have some Pen Testing booked in and they would like IPS/IDS disabled on their IP Addresses.

 

I cannot seem to find a way to exclude these and I am not keep on turning them off altogether for the duration of the testing window.

 

Cheers.

Posted

From a purely logical sense, you should leave it on as the true test of your edge security and as such the pen test is almost zero value at that point?

 

I have no idea on the setup sorry, but just removing security to test security makes as much sense as asking a burglar to get in but leaving the catch off to make it easier. Forgive me for being nosy!

Posted
From a purely logical sense, you should leave it on as the true test of your edge security and as such the pen test is almost zero value at that point?

 

I have no idea on the setup sorry, but just removing security to test security makes as much sense as asking a burglar to get in but leaving the catch off to make it easier. Forgive me for being nosy!

 

I had this thought when I saw the post earlier. What's the point of a Pen test if you're making it easy for them to break in?

 

I'd have thought the real point to it is to leave the defences in place and then it's up to the testers to find a way around them.

Posted

I think this for them to remote in on a VM to test different parts of the internal infrastructure , although they are also doing and external test as well.

 

All good points tho - I’ll go back and double check I’ve not misread their requirements and then contact them.

Posted (edited)

Could be they are checking internal attacks , PingCastle is often used for that

Edit: saw your post above, wonder what VLAN they want to be on, would make sense to be a Wifi/BYOD user

Edited by ittech2342323
Posted
All the pen tests I have had done have had a box shipped out or dropped off and plugged in. The tester can remote on to that and act as if they are on site. Only time I have had to turn off things for a pen test was a user Phishing test and had to allow their mail host to be not caught.
Posted

I’ve checks using pingcastle, so thought it prudent to have some pen testing done, especially if at some point I’m thinking for going for cyber essentials.

 

I’m having a full battery of tests

 

External

Internal

Azure/365 config checks

Wi-Fi

 

They have sent me over details to create a VM with Kali on it plus some other software.

 

All will be done remotely except for the Wifi which will be done on site.

 

Smoothwall have replied to say IDS only provide alerts and IPS only works on addresses which have port forwarding enabled.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...