router help, ips & siem

cubby1223

Lifer
May 24, 2004
13,518
42
86
I began working with a franchise business earlier this year and they just asked me for help with the requirements the corporation is giving them for the network.

Obtaining a router with IPS seems easy enough, just purchase one with anti-virus built-in with a subscription. This is a small business, very little internet usage, they actually are getting by with just a 3mbps dsl line! I'm searching the web and Cisco's ISA550w seems like a nice cheap router that can do that.

But the second requirement is SIEM tools, having the router send logs to a 24x7x365 staffed network operations center, I'm not familiar with! The manuals on Cisco's ISA routers say you can log the IPS events to a remote device, I'm assuming this will be sufficient? But then that still leaves me without a place to send them, do I find a company that provides these monitoring services for me? I will keep searching google for more information, most companies I'm finding their websites basically say "we provide solutions" without much detail into exactly what they provide.

I get the feeling these services are geared towards the large corporations who have lots of money to spend on IT, not necessarily the small business with very little spending money.

Thanks, any help is greatly appreciated.
 

Enigma102083

Member
Dec 25, 2009
147
0
0
Who's NOC are you supposed to be sending them too? Do they specify that you're supposed to send it too Corporate NOC? I would recommend a Sonicwall TZ205 with a Comprehensive Gateway Security bundle, this will get your IPS, IDS, deep-packet, etc and the TZ205 can be configured to connect to an SMTP server and email the logs to wherever you specify. There are solutions providers out there for this, you've probably seen many of them. You're not going to find any detail when cruising their websites. This is because something like that isn't a pre-packaged service, you call them and talk about your needs, requirements, and expectations and they create a solution for you and build a price around what is actually happening. Key point being, you need to call them and talk to them about what you need.
 

cubby1223

Lifer
May 24, 2004
13,518
42
86
The instructions for the franchise are to use any vendor's NOC they want to. I'll get in contact with their rep in the corporate IT services, find out what the exact deal is. Thanks.