mdrabble Posted August 10, 2023 Posted August 10, 2023 Before I log a call with smoothwall, does anyone know if you can disable IPS/IDS for certain external IP addresses? We have some Pen Testing booked in and they would like IPS/IDS disabled on their IP Addresses. I cannot seem to find a way to exclude these and I am not keep on turning them off altogether for the duration of the testing window. Cheers.
PaddyNewman Posted August 10, 2023 Posted August 10, 2023 From a purely logical sense, you should leave it on as the true test of your edge security and as such the pen test is almost zero value at that point? I have no idea on the setup sorry, but just removing security to test security makes as much sense as asking a burglar to get in but leaving the catch off to make it easier. Forgive me for being nosy!
MrEprise Posted August 10, 2023 Posted August 10, 2023 From a purely logical sense, you should leave it on as the true test of your edge security and as such the pen test is almost zero value at that point? I have no idea on the setup sorry, but just removing security to test security makes as much sense as asking a burglar to get in but leaving the catch off to make it easier. Forgive me for being nosy! I had this thought when I saw the post earlier. What's the point of a Pen test if you're making it easy for them to break in? I'd have thought the real point to it is to leave the defences in place and then it's up to the testers to find a way around them.
mdrabble Posted August 11, 2023 Author Posted August 11, 2023 I think this for them to remote in on a VM to test different parts of the internal infrastructure , although they are also doing and external test as well. All good points tho - I’ll go back and double check I’ve not misread their requirements and then contact them.
robintech Posted August 11, 2023 Posted August 11, 2023 (edited) Could be they are checking internal attacks , PingCastle is often used for that Edit: saw your post above, wonder what VLAN they want to be on, would make sense to be a Wifi/BYOD user Edited August 11, 2023 by ittech2342323
TechMonkey Posted August 11, 2023 Posted August 11, 2023 All the pen tests I have had done have had a box shipped out or dropped off and plugged in. The tester can remote on to that and act as if they are on site. Only time I have had to turn off things for a pen test was a user Phishing test and had to allow their mail host to be not caught.
mdrabble Posted August 11, 2023 Author Posted August 11, 2023 I’ve checks using pingcastle, so thought it prudent to have some pen testing done, especially if at some point I’m thinking for going for cyber essentials. I’m having a full battery of tests External Internal Azure/365 config checks Wi-Fi They have sent me over details to create a VM with Kali on it plus some other software. All will be done remotely except for the Wifi which will be done on site. Smoothwall have replied to say IDS only provide alerts and IPS only works on addresses which have port forwarding enabled.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now