Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


November 2004

Policing the Airwaves

3 wireless IDSs tell you who's on your network
RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints
Or get the Monthly Online Pass—only $5.95 a month!

Red-Detect 3.6
The Red-M product line is a set of components that you can purchase individually to fit your needs. For example, Red-M's Red-Alert PRO sensors can operate independently of Red-M's Red-Detect management server. You can manage the sensors with a Web browser, or they can use SNMP to report to any network management software, including the Red-Detect management server.

The Red-Detect management server is based on Red Hat Linux and comes preloaded on a minitower computer. The Red-Detect management console runs on Windows and can connect to one Red-Detect management server to manage that server's associated sensors. If your environment requires more than one Red-Detect server and you want to be able to manage more than one server at a time, or if you want in-depth reporting capabilities, you'll need Red-M's Red-Vision management add-on package. Red-Vision is probably a must-have for larger enterprise installations. Red-M didn't provide Red-Vision for my review.

To set up the Red-Detect server with the typical IP address and password parameters, you must use a crossover Ethernet cable. You also need to install on a workstation the Red-Detect console application, which then lets you contact the Red-Detect server to manage the server, the sensors, and the wireless network monitoring parameters. The Red-Alert PRO sensors have no serial interface, so I had to configure a workstation to have an IP address on the same default network as the sensors would use, then reconfigure the sensors with an address on the network and tell them the address of the Red-Detect management server. Alternatively, the sensors can use DNS queries to find the management server.

Once the server and sensors were online and communicating, I could use the Red-Detect console application on my workstation for monitoring and management. As Figure 3 shows, the Red-Detect console uses a typical treeview layout like AirDefense and AirMagnet, but the information that Red-Detect's interface displays isn't nearly as extensive or detailed. The interface's simple design and capabilities made it easy to navigate and use for configuration and monitoring; however, the online Help lacks context sensitivity and detail.

Red-Detect sends alerts only via SNMP, so you need a third-party SNMP solution if you don't want to sit in front of the console watching for problems. Unlike AirDefense and AirMagnet, Red-Detect doesn't provide any means of establishing policies for use in monitoring. Instead, the product relies on a variety of predefined event types that trigger logging and SNMP traps. For example, the product can track rogue devices, intrusion attempts, probing, wireless attacks, and an assortment of other activities. But the console and sensors couldn't tell me when an AP and client station weren't using encryption.

As you can see in Figure 3, Red-M provides some basic graphical reporting features, which can be useful. You can change the layout from bar graph to line graph and save the graphs to disk, but Red-M has no other built-in reporting facilities, so, for example, you can't generate printed reports unless you purchase Red-Vision.

One particularly interesting Red-Alert PRO feature is that in addition to monitoring 802.11a, 802.11b, and 802.11g networks, the Red-Alert PRO probes can monitor Bluetooth devices. Another attractive feature is the way the solution handles countermeasures against potential intruders. Like AirDefense and AirMagnet, Red-Detect can launch DoS attacks against intruders. An administrator must manually initiate the countermeasure, and after a configurable period of time (as many as 10 minutes) has elapsed, the DoS countermeasure stops automatically. This approach prevents a situation in which an administrator might forget to stop countermeasure activity.

Red-Detect 3.6
Contact: Red-M * 703-744-1445
Web: http://www.red-m.com
Price: $8995 for Red-Detect SOHO Server, which can monitor four sensors and includes management server and four probes; $9995 for Red-Detect Server, which can monitor unlimited sensors and includes management server and four probes; countermeasures cost $3000 extra per server
Summary
Pros: Hardened server platform; monitors 802.11a, 802.11b, 802.11g, and Bluetooth; easy to install and configure; easy-to-use management interface
Cons: No way to establish policies; limited alerting capabilities; Red-Detect Server has only basic management and reporting capabilities—
Rating: 3 out of 5
Red-Vision management and reporting cost extra; countermeasures cost extra; sparse online Help
Recommendation:
Red-M is a far more expensive solution for midsized and large businesses, but small businesses can benefit from the pricing model. Without its pricey Red-Vision and countermeasure add-ons, Red-M is inferior to its competitors.


A Buying Decision
All three products are designed for enterprise-size networks. However, if your small business needs only a few sensors and you want a standalone hardware-based solution to monitor your environment, Red-M's products are the best solution of the three for you because the Red-Alert PRO sensors, priced at $300 each, can operate without a management server.

If you have a midsized or large enterprise and you need to monitor a variety of sites and hardware platforms, consider the functionality offered by each of the three products to determine your needs and total cost of ownership (TCO). If you prefer a software-based solution that can run on your own hardware, AirMagnet is the clear choice because you can install its sensor software on any system that has a supported wireless network card. If you prefer a turnkey solution that includes a preconfigured server platform, then consider AirDefense. You can use AirDefense's Java-based management console on any Java-enabled platform, whereas the AirMagnet and Red-M management consoles operate only on Windows.

If your decision depends heavily on price, be aware that for midsized and large enterprises that need countermeasures and good reporting capabilities, Red-M's solution is the most expensive of the three. AirDefense's and AirMagnet's base packages are superior to Red-M's. Countermeasures are built into AirDefense and AirMagnet but are a $3000 add-on to a Red-M solution. You also pay extra to get in-depth reporting capabilities from Red-M.

End of Article

   Previous  1  2  [3]  Next  


Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Windows Chief Leaving Microsoft

Kevin Johnson, the man most directly responsible for current and future versions of Windows, as well as Windows Live and Microsoft's online services, is leaving the company for a position at Juniper Networks. Johnson has been co-president or president ...

How can I limit Exchange mailbox size?

...

Microsoft Exchange Online: An ASP's Reaction

Does Microsoft Exchange Online and the company's other new online offerings spell the end of ASPs? Apptix, an Exchange service provider, sees much room for ASPs to offer features that Microsoft won't and to target different business segments. ...


Security Whitepapers Anti-Virus Is Dead: The Advent of the Graylist Approach to Computer Protection

Getting the Job Done: Comparing Approaches for Desktop Software Lockdown

Instant Messaging, VoIP, P2P, and games in the workplace: How to take back control

Related Events Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

Shortcut Guide to SQL Server Infrastructure Optimization
With right tools and techniques, you can have a top-performing SQL Server infrastructure without having to cram your data centers so that they're overflowing. Download this eBook to learn how.

WinConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

Become a fan of Windows IT Pro on Facebook!
Join us on Facebook and be a fan of Windows IT Pro!

Continuous Data Protection and Recovery for Exchange
Read this white paper to learn about Continuous Data Protection (CDP), Exchange 2007's local continuous replication and cluster continuous replication features.

Rev Up Your IT Know-How with Our Recharged Magazine!
The improved Windows IT Pro provides trusted IT content with an enhanced new look and functionality! Get comprehensive coverage of industry topics, expert advice, and real-world solutions—PLUS access to over 10,000 articles online. Order today!

Tips to Managing Messaging
Discover three fundamental mail and messaging management services - security, availability and control services - and how you can implement them in a Microsoft-centric mail and messaging environment.

Get It All with Windows IT Pro VIP
Stock your IT toolbox with every solution ever printed in Windows IT Pro and SQL Server Magazine plus bonus Web-exclusive content on hot topics. Subscribe to receive the VIP CD and a subscription to your choice of Windows IT Pro or SQL Server Magazine!



Solving PST Management Problems
In this white paper, read about the top PST issues and how to administer local/network PST files.

Bandwidth Monitoring Tool from SolarWinds
Identify largest bandwidth users in seconds. Get the free download now.

Transform Your Data Center at Brocade Conference 2008
Storage networking industry’s premier event at the MGM Grand, Las Vegas, September 22 - 24, 2008

Are You Litigation Ready?
Collecting and processing electronic data for e-discovery can be time-consuming and expose a business to significant legal risks. Get prepared with this free white paper

Order Your Fundamentals CD Today!
Gain an introduction to Exchange, learn server security requirements, and understand how unified communications can play a role in your messaging strategies with this free Exchange CD.

KVM over IP Solutions
Learn about a KVM over IP solution that is specifically designed to meet the needs of the distributed IT environment.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound
IT Library Technical Resources Directory Connected Home Windows Excavator SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing