For years video surveillance technologies have required a dedicated network and dedicated hardware to provide an organization the ability to monitor their facilities. Often times this required dedicated digital video recorders per location which were often not backed up or updated so that when the information was actually needed it was not available. Like other technologies such as voice, IP video surveillance is now a reality but many customer still have legacy analog cameras that … Read the rest
Network Security Archives
An easy way to network enable video surveillance.
Ironport DLP
I find that the Ironport DLP policies are a bit confusing, maybe even misleading. Many of them in their description say that it will classify emails with Social Security numbers, or account numbers, but in fact they require more than just those specific matches to be considered
Security – More than just ACLs
In an age where people think network security, they see access-lists, firewalls, IPS and other appliances to assist, the resiliency of the network seems to have faded into the darkness.
Utilizing Object Groups on the ASA
Object groups on the ASA allow you to group similar types of components within a single heading. You can use this heading for access-lists, which in turn can be used for access control, NAT,
Intrusion Prevention for the Core
Many customers are taking advantage of Intrusion Prevention Systems at the edge of their network to protect their organizations from Internet based threats. These solutions are often integrated with the organizations firewall, mail and web security appliances. Many of these systems today have expanded beyond signature based solutions to include the concept of reputation based filtering.
While edge network IPS solutions have proved to be an effect means of mitigating threats, the increase in threat … Read the rest
Dropping Traffic in IOS
Everyone is familiar with access-lists as a way to drop traffic in IOS. This has become a standard easy way to stop unwanted traffic from traversing networks at key points. There are other solutions as well as ways to optimize your access-lists that sometimes are a better for your router’s processor when it comes to processing traffic.
Mebroot and Torpig
Botnets are becoming more prevalent as malware technology becomes more sophisticated. One of the more diabolical pieces of Malware that hit the scene back in 2008 is called Mebroot. Mebroot is a rootkit that replaces a machines master boot record allowing it to install even before the operating system of the machine installs effectively protecting it from desktop protection software. Mebroot alone is rather benign in that it does not contain any specific applications but … Read the rest
Anyconnect Essentials Licensing
Anyconnect Essentials licensing allows for you to max out the number of Anyconnect VPN clients on your ASA version 8.21 or higher. So on an ASA 5520 you can have 750. Cisco is making this an incredibly inexpensive option. Just remember, if you have a failover pair, you must purchase 2 licenses.
Author: Alex Jerrold
Posted at Geeknick
Cisco’s Adaptive Security Appliance – More Than Just a Firewall
When Cisco introduced its ASA5500 series of security appliances, many people viewed this simply as a PIX replacement. The reality is the ASA series of products offer customers much more than just a firewall. The ASA is now truly a multipurpose edge security device allowing customers to integrate multiple functions into a single security appliance. Let’s take a look at a few of the more popular capabilities.
VPN termination
The ASA offers multiple methods of … Read the rest