Hmmm...not sure how I missed this post the first time around. Regardless, if you are having problems with routing assymetry on your internal (backbone) network, you need to work on your routing (outside your backbone is a different story).
How exactly are you looking to implement your NIDS? What software/hardware are you looking to deploy? Most modern NIDS have split up the functionality of Network Intrusion Detection into several components, a monitor (watches network traffic), a reporter (reports to central location), an event collector (records the events sent by the reporter), a central database (where the events are stored), and a console (a frontend that queries the database).
Regardless of what you use, I don't really see how you could be having problems with assymetry if your internal routing is functional (you are keeping your NIDS and the databse internal to your network right?)...
/nebulus




Reply With Quote