(703) 637-3990 Partners Network Monitor Webmail

Intrusion Detection vs. Firewall

What’s the difference - and why you need both.

Intrusion Detection and Prevention Systems are commonly mistaken for a firewall, or as a substitute for one. In practice, they serve different purposes in a network security strategy.

A firewall functions by limiting access between networks to prevent intrusion, but it cannot detect attacks originating from within the network. When opening ports for inbound internet traffic, organizations must create exceptions through the firewall - and those exceptions are exactly what an IDPS is designed to watch.

An IDPS works differently: it evaluates a suspected intrusion once it has taken place, signals an alarm, and makes attempts to stop it. These systems identify attacks designed to bypass standard firewall filtering.

How IDP Systems Work

The technology relies on attack signature databases. Organizations configure the IDP for their specific applications, and when attackers use known signatures, the attack is stopped and logged. Success depends on maintaining large, regularly updated signature databases.

Juniper Products

DHK offers Juniper hardware IDP solutions with thousands of attack signatures. Two deployment models exist: Deep Inspection (a firewall add-on with roughly 250-500 signatures) and dedicated hardware IDP platforms for organizations needing more comprehensive protection.