> For the complete documentation index, see [llms.txt](https://davidjosearaujo.gitbook.io/notes-miect/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://davidjosearaujo.gitbook.io/notes-miect/seguranca-em-redes-de-comunicacoes/intrusion-detection-and-prevention/network-deployment.md).

# Network Deployment

## IDS

<figure><img src="https://1919807373-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKwrEaJP2cLc3Ipsnkpus%2Fuploads%2Ft435G5viVf2ub3GElmyA%2Fa.png?alt=media&amp;token=b9bed0d3-cbfb-45d4-a71b-69e74ff652cb" alt=""><figcaption></figcaption></figure>

* Network tap.
* Reports to the network management system.

## IPS

<figure><img src="https://1919807373-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKwrEaJP2cLc3Ipsnkpus%2Fuploads%2FZL9SxLcxICccqqa9NJrh%2Fa.png?alt=media&amp;token=9daad54e-09d2-4ded-a2c1-d4ebc5170b8e" alt=""><figcaption><p>Network tap with firewall integration</p></figcaption></figure>

<figure><img src="https://1919807373-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKwrEaJP2cLc3Ipsnkpus%2Fuploads%2FW0wZBDTZCAKuPwvp7peJ%2Fa.png?alt=media&amp;token=8cd14618-7904-45df-996f-33ceb154a326" alt=""><figcaption><p>Inline with firewall integration</p></figcaption></figure>

<figure><img src="https://1919807373-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKwrEaJP2cLc3Ipsnkpus%2Fuploads%2F9lxKXOzQFQvEfL2Cl54s%2Fa.png?alt=media&amp;token=af8bc9c4-4a3c-4c5c-bbcb-5d60ce6b51f4" alt=""><figcaption><p>Inline with embedded firewall</p></figcaption></figure>

## IDS/IPS Actions

### Suricata

* **alert** - generate an alert.&#x20;
* **pass** - stop further inspection of the packet.&#x20;
* **drop** - drop the packet and the generated alert.
* **reject** - send RST/ICMP unreachable error to the sender of the matching packet.
* **rejectsrc** - same as just reject.&#x20;
* **rejectdst** - send RST/ICMP error packet to the receiver of the matching packet.&#x20;
* **rejectboth** - send RST/ICMP error packets to both sides of the conversation.

### Snort

* **alert** - generate an alert using the selected alert method, and then log the packet.&#x20;
* **log** - log the packet.&#x20;
* **pass** - ignore the packet.&#x20;
* **drop** - block and log the packet.&#x20;
* **reject** - block the packet, log it, and then send a TCP reset if the protocol is TCP or an ICMP port unreachable message if the protocol is UDP.&#x20;
* **sdrop** - block the packet but do not log it.
