With the rapid development of the Internet, the expansion of the network scale and the complexity of the methods of network attacks, security requirements are constantly increasing. Based on the analysis of the intrusion detection system and the firewall, an intrusion detection system and a firewall linkage mode are designed. Considering the overall network security and dynamic requirements, the active defense against burst network attacks is realized.