<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The IPS Guy &#187; Mcaffe</title>
	<atom:link href="http://theipsguy.com/category/mcaffe/feed/" rel="self" type="application/rss+xml" />
	<link>http://theipsguy.com</link>
	<description>Intrusion Prevention/Detection technologies.</description>
	<lastBuildDate>Thu, 19 Aug 2010 17:25:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Virtual IPS vs. Virtualized IPS</title>
		<link>http://theipsguy.com/virtual-ips-vs-virtualized-ips/</link>
		<comments>http://theipsguy.com/virtual-ips-vs-virtualized-ips/#comments</comments>
		<pubDate>Tue, 27 Apr 2010 17:48:14 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IBM]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[Mcaffe]]></category>
		<category><![CDATA[Sourcefire]]></category>
		<category><![CDATA[Virtual IPS]]></category>
		<category><![CDATA[Virtualization]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=223</guid>
		<description><![CDATA[Virtualization is a top priority for most organizations today. Security of these virtualized environments should also be a top priority and in the Intrusion Prevention market most vendors are developing or have developed virtual or virtualized solutions. The terms virtual IPS and virtualized IPS have different meanings and I want to take some time to [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Virtualization is a top priority for most organizations today. Security of these virtualized environments should also be a top priority and in the Intrusion Prevention market most vendors are developing or have developed virtual or virtualized solutions.</p>
<p>The terms virtual IPS and virtualized IPS have different meanings and I want to take some time to attempt to differentiate these terms. Most vendors have had virtual IPS for many years. Virtual IPS is the ability to apply different polices to certain types of traffic. This could be done using VLAN tags or physical interfaces. IBM does this using the Protection Domains feature which allows a different policy to be deployed to different VLAN&#8217;s. Mcafee does this by allowing different policies to be assigned to physical interfaces and can also support policies to be applied based no VLAN tags.</p>
<p>Virtualized IPS is what most of us think of today when we discuss virtualization. Virtualized IPS is an IPS appliance that runs in a virtual environment such as VmWare, Zen or Microsoft&#8217;s Hyper-V. The IPS is installed as a virtual server and can be configured so that all server to server traffic inside and outside the virtual environment can be monitored by an IPS.</p>
<p>It is important to be clear on these differences in terminology because not all vendors have virtualized IPS and most sales people will not know enough to properly answer the question, Do you support virtualization? Most will say yes, because they have heard their support teams talk about virtual IPS not virtualized IPS. Virtualized IPS will continue to grow in importance and eventually all the major Intrusion Prevention vendors will have these offerings. Until then do your homework and hold the vendors accountable.</p>
]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/virtual-ips-vs-virtualized-ips/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Errors with Mcafee Endpoint Encryption</title>
		<link>http://theipsguy.com/errors-with-mcafee-endpoint-encryption/</link>
		<comments>http://theipsguy.com/errors-with-mcafee-endpoint-encryption/#comments</comments>
		<pubDate>Thu, 15 Apr 2010 23:00:10 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[Mcaffe]]></category>
		<category><![CDATA[EEPC]]></category>
		<category><![CDATA[Endpoint Encryption]]></category>
		<category><![CDATA[Mcafee]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=217</guid>
		<description><![CDATA[I have a client that is deploying Mcafee Endpoint Encryption, formerly known as Safeboot. The product integrates with Active Directory and the newest version can be managed through the ePO management console. Overall the product has experienced a number of problems. Most of these problems are documented and can be mitigated by defragmenting the disk [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>I have a client that is deploying Mcafee Endpoint Encryption, formerly known as Safeboot. The product integrates with Active Directory and the newest version can be managed through the ePO management console. Overall the product has experienced a number of problems. Most of these problems are documented and can be mitigated by defragmenting the disk or removing software that replaces the MSGINA, such as the HP Protect Tools.</p>
<p>The one problem that they have not been able to correct though is the Sector Chain is Invalid error. This error generally happens right after installation but can happen at any time.  According to the support engineers I have spoken to the machine is generally unable to be recovered! This is a serious problem that Mcafee seems to not be addressing. They have said they are unable to replicate the problem but this issue has been brought up multiple times in different forums going back to 2008.</p>
<p>Come on Mcafee you need to fix this problem. You supposedly have hundreds of thousands of customers and you make the encryption used by the HP Protect Tools. You can fix this and need to ASAP.</p>
<p>HP Forums</p>
<p><a title="http://bit.ly/dalIDD" href="http://bit.ly/dalIDD">http://bit.ly/dalIDD</a></p>
<p>Mcafee Knowledgebase Article</p>
<p><a title="http://bit.ly/dCeL2q" href="http://bit.ly/dCeL2q">http://bit.ly/dCeL2q</a></p>
]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/errors-with-mcafee-endpoint-encryption/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Intrusion Prevention Cabling</title>
		<link>http://theipsguy.com/intrusion-prevention-cabling/</link>
		<comments>http://theipsguy.com/intrusion-prevention-cabling/#comments</comments>
		<pubDate>Fri, 19 Mar 2010 16:57:46 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>
		<category><![CDATA[Mcaffe]]></category>
		<category><![CDATA[intrusion prevention]]></category>
		<category><![CDATA[Mcafee IPS]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=212</guid>
		<description><![CDATA[As a follow up on my previous post on cabling an IPS I have attached an example that I have seen successful.This example is specific to a Mcafee M2750 device and assumes interfaces that are hard set. Note that the actual firewall and LAN switch are using Straight cables and not cross-over. The only cross-over [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>As a follow up on my previous post on cabling an IPS I have attached an example that I have seen successful.This example is specific to a Mcafee M2750 device and assumes interfaces that are hard set. Note that the actual firewall and LAN switch are using Straight cables and not cross-over. The only cross-over is placed between the Fail-open kit and the IPS.</p>
<p><a href="http://theipsguy.com/wp-content/uploads/2010/03/Cabling.png"><img class="aligncenter size-medium wp-image-213" title="Cabling" src="http://theipsguy.com/wp-content/uploads/2010/03/Cabling-300x280.png" alt="" width="300" height="280" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/intrusion-prevention-cabling/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Visio Stencils for Mcafee and IBM/ISS IPS devices now available for download.</title>
		<link>http://theipsguy.com/visio-stencils-for-mcafee-and-ibmiss-ips-devices-now-available-for-download/</link>
		<comments>http://theipsguy.com/visio-stencils-for-mcafee-and-ibmiss-ips-devices-now-available-for-download/#comments</comments>
		<pubDate>Fri, 20 Nov 2009 02:00:53 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IBM]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[Mcaffe]]></category>
		<category><![CDATA[Mcafee]]></category>
		<category><![CDATA[Visio stencils]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=155</guid>
		<description><![CDATA[I now have available for download the Mcaffe and IBM/ISS Visio Stencils. You can find them on my download page. I hope to post more over the next few weeks. If you have some please send them to me.]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>I now have available for download the Mcaffe and IBM/ISS Visio Stencils. You can find them on my <a href="http://theipsguy.com/downloads/" target="_blank">download</a> page. I hope to post more over the next few weeks. If you have some please send them to me.</p>
]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/visio-stencils-for-mcafee-and-ibmiss-ips-devices-now-available-for-download/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mcaffe and IBM Comparison</title>
		<link>http://theipsguy.com/mcaffe-and-ibm-comparison/</link>
		<comments>http://theipsguy.com/mcaffe-and-ibm-comparison/#comments</comments>
		<pubDate>Tue, 06 Oct 2009 18:07:15 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IBM]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[Mcaffe]]></category>
		<category><![CDATA[intrusion prevention]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=42</guid>
		<description><![CDATA[IBM Device GX4004 GX5008 GX5108 GX5208 # of 10/100/1000 Mbps Network Segments Protected Inline 2 4 4 4 Throughput 200Mbps 400Mbps 1.2Gbps 2Gbps # of 10Gbps Networks Protected 0 0 0 0 # of Virtual IPS Systems 0 0 0 0 Anomaly Detection Coming Coming Coming Coming Integration with McAfee ePO for Combined Protection with [...]]]></description>
			<content:encoded><![CDATA[<table style="height: 295px;" border="1" cellspacing="0" cellpadding="2" width="661">
<tbody>
<tr style="text-align: left;">
<td style="text-align: left;" width="237" valign="top">
<h6><strong>IBM</strong></h6>
</td>
<td width="51" valign="top"></td>
<td width="83" valign="top"></td>
<td width="80" valign="top"></td>
<td width="100" valign="top"></td>
</tr>
<tr>
<td width="237" valign="top">
<h6>Device</h6>
</td>
<td width="51" valign="top">
<h6>GX4004</h6>
</td>
<td width="83" valign="top">
<h6>GX5008</h6>
</td>
<td width="80" valign="top">
<h6>GX5108</h6>
</td>
<td width="100" valign="top">
<h6>GX5208<span id="more-42"></span></h6>
</td>
</tr>
<tr>
<td width="237" valign="top">
<h6># of 10/100/1000 Mbps Network Segments Protected Inline</h6>
</td>
<td width="51" valign="top">
<h6>2</h6>
</td>
<td width="83" valign="top">
<h6>4</h6>
</td>
<td width="80" valign="top">
<h6>4</h6>
</td>
<td width="100" valign="top">
<h6>4</h6>
</td>
</tr>
<tr>
<td width="237" valign="top">
<h6>Throughput</h6>
</td>
<td width="51" valign="top">
<h6>200Mbps</h6>
</td>
<td width="83" valign="top">
<h6>400Mbps</h6>
</td>
<td width="80" valign="top">
<h6>1.2Gbps</h6>
</td>
<td width="100" valign="top">
<h6>2Gbps</h6>
</td>
</tr>
<tr>
<td width="237" valign="top">
<h6># of 10Gbps Networks Protected</h6>
</td>
<td width="51" valign="top">
<h6>0</h6>
</td>
<td width="83" valign="top">
<h6>0</h6>
</td>
<td width="80" valign="top">
<h6>0</h6>
</td>
<td width="100" valign="top">
<h6>0</h6>
</td>
</tr>
<tr>
<td width="237" valign="top">
<h6># of Virtual IPS Systems</h6>
</td>
<td width="51" valign="top">
<h6>0</h6>
</td>
<td width="83" valign="top">
<h6>0</h6>
</td>
<td width="80" valign="top">
<h6>0</h6>
</td>
<td width="100" valign="top">
<h6>0</h6>
</td>
</tr>
<tr>
<td width="237" valign="top">
<h6>Anomaly Detection</h6>
</td>
<td width="51" valign="top">
<h6>Coming</h6>
</td>
<td width="83" valign="top">
<h6>Coming</h6>
</td>
<td width="80" valign="top">
<h6>Coming</h6>
</td>
<td width="100" valign="top">
<h6>Coming</h6>
</td>
</tr>
<tr>
<td width="237" valign="top">
<h6>Integration with McAfee ePO for Combined Protection with McAfee Virus Scan and Spyware Protection</h6>
</td>
<td width="51" valign="top">
<h6>No</h6>
</td>
<td width="83" valign="top">
<h6>No</h6>
</td>
<td width="80" valign="top">
<h6>No</h6>
</td>
<td width="100" valign="top">
<h6>No</h6>
</td>
</tr>
<tr>
<td width="237" valign="top">
<h6>NAC</h6>
</td>
<td width="51" valign="top">
<h6>No</h6>
</td>
<td width="83" valign="top">
<h6>No</h6>
</td>
<td width="80" valign="top">
<h6>No</h6>
</td>
<td width="100" valign="top">
<h6>No</h6>
</td>
</tr>
</tbody>
</table>
<table style="height: 246px;" border="1" cellspacing="0" cellpadding="2" width="661">
<tbody>
<tr>
<td width="237" valign="top">
<h6><strong>Mcafee</strong></h6>
</td>
<td width="51" valign="top"></td>
<td width="83" valign="top"></td>
<td width="80" valign="top"></td>
<td width="100" valign="top"></td>
</tr>
<tr>
<td width="237" valign="top">
<h6>Device</h6>
</td>
<td width="51" valign="top">
<h6>M1450</h6>
</td>
<td width="83" valign="top">
<h6>M2750</h6>
</td>
<td width="80" valign="top">
<h6>M3050</h6>
</td>
<td width="100" valign="top">
<h6>M6050</h6>
</td>
</tr>
<tr>
<td width="237" valign="top">
<h6># of 10/100/1000 Mbps Network Segments Protected Inline</h6>
</td>
<td width="51" valign="top">
<h6>4</h6>
</td>
<td width="83" valign="top">
<h6>10</h6>
</td>
<td width="80" valign="top">
<h6>4</h6>
</td>
<td width="100" valign="top">
<h6>4</h6>
</td>
</tr>
<tr>
<td width="237" valign="top">
<h6># of 10Gbps Networks Protected</h6>
</td>
<td width="51" valign="top">
<h6>0</h6>
</td>
<td width="83" valign="top">
<h6>0</h6>
</td>
<td width="80" valign="top">
<h6>2</h6>
</td>
<td width="100" valign="top">
<h6>8</h6>
</td>
</tr>
<tr>
<td width="237" valign="top">
<h6># of Virtual IPS Systems</h6>
</td>
<td width="51" valign="top">
<h6>32</h6>
</td>
<td width="83" valign="top">
<h6>100</h6>
</td>
<td width="80" valign="top">
<h6>1000</h6>
</td>
<td width="100" valign="top">
<h6>1000</h6>
</td>
</tr>
<tr>
<td width="237" valign="top">
<h6>Anomaly Detection</h6>
</td>
<td width="51" valign="top">
<h6>Coming</h6>
</td>
<td width="83" valign="top">
<h6>Coming</h6>
</td>
<td width="80" valign="top">
<h6>Coming</h6>
</td>
<td width="100" valign="top">
<h6>Coming</h6>
</td>
</tr>
<tr>
<td width="237" valign="top">
<h6>Integration with McAfee ePO for Combined Protection with McAfee Virus Scan and Spyware Protection</h6>
</td>
<td width="51" valign="top">
<h6>Yes</h6>
</td>
<td width="83" valign="top">
<h6>Yes</h6>
</td>
<td width="80" valign="top">
<h6>Yes</h6>
</td>
<td width="100" valign="top">
<h6>Yes</h6>
</td>
</tr>
<tr>
<td width="237" valign="top">
<h6>NAC</h6>
</td>
<td width="51" valign="top">
<h6>Yes</h6>
</td>
<td width="83" valign="top">
<h6>Yes</h6>
</td>
<td width="80" valign="top">
<h6>Yes</h6>
</td>
<td width="100" valign="top">
<h6>Yes</h6>
</td>
</tr>
</tbody>
</table>
<h6>The Mcafee devices offer a greater number of monitoring ports as well as faster throughput. They are also adding more capabilities to their devices such as their NAC solution. As we have begun evaluating the Mcafee offering we feel there is going to be more integration that will result in a more integrated security system.</h6>
]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/mcaffe-and-ibm-comparison/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Thinking about 10 gig IPS</title>
		<link>http://theipsguy.com/thinking-about-10-gig-ips/</link>
		<comments>http://theipsguy.com/thinking-about-10-gig-ips/#comments</comments>
		<pubDate>Tue, 14 Jul 2009 12:28:00 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IBM]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[Mcaffe]]></category>
		<category><![CDATA[Sourcefire]]></category>
		<category><![CDATA[tippingpoint]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=6</guid>
		<description><![CDATA[I have been looking at 10 gig solutions for IPS and I have to say there is a wide difference in the way the different vendors are doing this. IBM Network Security Controller allows for two 10 giga-bit networks to be connected in an active/passive configuration. You would then connect the copper IPS devices to [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>I have been looking at 10 gig solutions for IPS and I have to say there is a wide difference in the way the different vendors are doing this.</p>
<p>IBM<br />
Network Security Controller allows for two 10 giga-bit networks to be connected in an active/passive configuration. You would then connect the copper IPS devices to the controller and the controller spreads the load among the connected IPS devices. This would provide IPS with the ability to inspect up to 10 gigabit of traffic assuming the IPS devices connected to it can inspect up to 10 gig. The GX6116 has an inspected throughput of 6 Gbps. IBM has no native 10 giga-bit interfaces on their IPS devices.</p>
<p>Mcafee<br />
Mcafee offers two devices with 10 giga-bit interfaces. The M8000 has 12 10 giga-bit Ethernet ports and a maximum throughput of 10 Gbps, the M6050 has 8 10 giga-bit Ethernet ports with a maximum throughout of 5 Gbps.</p>
<p>Sourcefire<br />
Sourcefire has the 3D9800 with four Fiber 10 Gbps interfaces with up to 10 Gbps line speed and the 3D9900 with 4 10 Gbps SR interfaces. The line speed is up to 10 Gbps.</p>
<p>TippingPoint<br />
The TippingPoint Core Controller has six 10 Gbps Ethernet interfaces(3 segments). This is similar in design to the IBM solution. The controller distributes the load across the connected backend IPS devices. The total inspected bandwidth is dependant on the backend IPS devices.</p>
]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/thinking-about-10-gig-ips/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
