An Engineer by Heart !!! A Dreamer, A Pioneer, A Blogger. A Network Engineer Trying to overtake the world with his network engineering skills :) Opinions expressed here are solely my own and do not express the views or opinions of my Present or Past employer.
Thursday, May 28, 2009
Thursday, May 21, 2009
Wednesday, May 20, 2009
Narbik's Bootcamp In India This Year
CCIE#12410 (R&S, SP, Security) CCSI# 30832
Narbik has over 30 years of experience in the industry. Narbik has designed, implemented and supported numerous enterprise networks. Some of the companies that Narbik has worked for are IBM, Carlton United Breweries, Australian cable and wireless, BP, and in US, 20th Century Ins., Home Saving of America, Verizon, TTI, Trinet Inc, and many more. Narbik has been a dedicated CCIE instructor for over 10 years.
http://www.micronicstraining.com/ccie-routing-switching-lab.html
IPSEC Basics
protection between multiple crypto peers engaging in secure data transfer.
IPsec includes the Internet Security Association and Key Management Protocol
(ISAKMP)/Oakley and two IPsec IP protocols: Encapsulating Security Protocol
(ESP) and Authentication Header (AH).
IPsec uses symmetrical encryption algorithms for data protection. Symmetrical
encryption algorithms are more efficient and easier to implement in hardware.
These algorithms need a secure method of key exchange to ensure data protection.
Internet Key Exchange (IKE) ISAKMP/Oakley protocols provide this capability.
This solution requires a standards-based way to secure data from eavesdropping
and modification. IPsec provides such a method. IPsec provides a choice of
transform sets so that a user can choose the strength of their data protection.
IPsec also has several Hashed Message Authentication Codes (HMAC) from
which to choose, each giving different levels of protection for attacks such as
man-in-the-middle, packet replay (anti-replay), and data integrity attacks.
Best Regards,
Deepak Arora
Tuesday, May 19, 2009
Zone-Based Policy Firewall (ZFW)
Cisco IOS® Software Release 12.4(6)T introduced Zone-Based Policy Firewall (ZFW), a new configuration model for the Cisco IOS Firewall feature set. This new configuration model offers intuitive policies for multiple-interface routers, increased granularity of firewall policy application, and a default deny-all policy that prohibits traffic between firewall security zones until an explicit policy is applied to allow desirable traffic.
Nearly all classic Cisco IOS Firewall features implemented before Cisco IOS Software Release 12.4(6)T are supported in the new zone-based policy inspection interface:
-
Stateful packet inspection
-
VRF-aware Cisco IOS Firewall
-
URL filtering
-
Denial-of-Service (DoS) mitigation
Cisco IOS Software Release 12.4(9)T added ZFW support for per-class session/connection and throughput limits, as well as application inspection and control:
-
HTTP
-
Post Office Protocol (POP3), Internet Mail Access Protocol (IMAP), Simple Mail Transfer Protocol/Enhanced Simple Mail Transfer Protocol (SMTP/ESMTP)
-
Sun Remote Procedure Call (RPC)
-
Instant Messaging (IM) applications:
-
Microsoft Messenger
-
Yahoo! Messenger
-
AOL Instant Messenger
-
-
Peer-to-Peer (P2P) File Sharing:
-
Bittorrent
-
KaZaA
-
Gnutella
-
eDonkey
-
Cisco IOS Software Release 12.4(11)T added statistics for easier DoS protection tuning.
Some Cisco IOS Classic Firewall features and capabilities are not yet supported in a ZFW in Cisco IOS Software Release 12.4(15)T:
-
Authentication proxy
-
Stateful firewall failover
-
Unified firewall MIB
-
IPv6 stateful inspection
-
TCP out-of-order support
ZFW generally improves Cisco IOS performance for most firewall inspection activities.
Neither Cisco IOS ZFW or Classic Firewall include stateful inspection support for multicast traffic.
Best Regards,
Deepak Arora