Network Security Archives

An easy way to network enable video surveillance.

For years video surveillance technologies have required a dedicated network and dedicated hardware to provide an organization the ability to monitor their facilities. Often times this required dedicated digital video recorders per location which were often not backed up or updated so that when the information was actually needed it was not available. Like other technologies such as voice, IP video surveillance is now a reality but many customer still have legacy analog cameras that … Read the rest

Ironport DLP

I find that the Ironport DLP policies are a bit confusing, maybe even misleading.  Many of them in their description say that it will classify emails with Social Security numbers, or account numbers, but in fact they require more than just those specific matches to be considered

(function(d, s, id) {
var js, fjs = d.getElementsByTagName(s)[0];
if (d.getElementById(id)) {return;}
js = d.createElement(s); js.id = id;
js.src = “//connect.facebook.net/en_US/all.js#xfbml=1″;
fjs.parentNode.insertBefore(js, fjs);
}(document, “script”, “facebook-jssdk”));

Read the rest

Security – More than just ACLs

In an age where people think network security, they see access-lists, firewalls, IPS and other appliances to assist, the resiliency of the network seems to have faded into the darkness.

(function(d, s, id) {
var js, fjs = d.getElementsByTagName(s)[0];
if (d.getElementById(id)) {return;}
js = d.createElement(s); js.id = id;
js.src = “//connect.facebook.net/en_US/all.js#xfbml=1″;
fjs.parentNode.insertBefore(js, fjs);
}(document, “script”, “facebook-jssdk”));

Read the rest

Utilizing Object Groups on the ASA

Object groups on the ASA allow you to group similar types of components within a single heading.  You can use this heading for access-lists, which in turn can be used for access control, NAT,

(function(d, s, id) {
var js, fjs = d.getElementsByTagName(s)[0];
if (d.getElementById(id)) {return;}
js = d.createElement(s); js.id = id;
js.src = “//connect.facebook.net/en_US/all.js#xfbml=1″;
fjs.parentNode.insertBefore(js, fjs);
}(document, “script”, “facebook-jssdk”));

Read the rest

Intrusion Prevention for the Core

Many customers are taking advantage of Intrusion Prevention Systems at the edge of their network to protect their organizations from Internet based threats. These solutions are often integrated with the organizations firewall, mail and web security appliances. Many of these systems today have expanded beyond signature based solutions to include the concept of reputation based filtering.
While edge network IPS solutions have proved to be an effect means of mitigating threats, the increase in threat … Read the rest

Dropping Traffic in IOS

Everyone is familiar with access-lists as a way to drop traffic in IOS.  This has become a standard easy way to stop unwanted traffic from traversing networks at key points.  There are other solutions as well as ways to optimize your access-lists that sometimes are a better for your router’s processor when it comes to processing traffic. 

(function(d, s, id) {
var js, fjs = d.getElementsByTagName(s)[0];
if (d.getElementById(id)) {return;}
js = d.createElement(s); js.id =

Read the rest

Mebroot and Torpig

Botnets are becoming more prevalent as malware technology becomes more sophisticated.  One of the more diabolical pieces of Malware that hit the scene back in 2008 is called Mebroot.  Mebroot is a rootkit that replaces a machines master boot record allowing it to install even before the operating system of the machine installs effectively protecting it from desktop protection software.  Mebroot alone is rather benign in that it does not contain any specific applications but … Read the rest

Anyconnect Essentials Licensing

Anyconnect Essentials licensing allows for you to max out the number of Anyconnect VPN clients on your ASA version 8.21 or higher.  So on an ASA 5520 you can have 750.  Cisco is making this an incredibly inexpensive option.  Just remember, if you have a failover pair, you must purchase 2 licenses.

Author: Alex Jerrold

Posted at Geeknick

(function(d, s, id) {
var js, fjs = d.getElementsByTagName(s)[0];
if (d.getElementById(id)) {return;}
js = d.createElement(s); js.id

Read the rest

When Cisco introduced its ASA5500 series of security appliances, many people viewed this simply as a PIX replacement. The reality is the ASA series of products offer customers much more than just a firewall. The ASA is now truly a multipurpose edge security device allowing customers to integrate multiple functions into a single security appliance. Let’s take a look at a few of the more popular capabilities.

VPN termination

The ASA offers multiple methods of … Read the rest

 Page 2 of 2 « 1  2