Wednesday, May 20, 2009

Narbik's Bootcamp In India This Year

Narbik Kocharians
CCIE#12410 (R&S, SP, Security) CCSI# 30832

Narbik has over 30 years of experience in the industry. Narbik has designed, implemented and supported numerous enterprise networks. Some of the companies that Narbik has worked for are IBM, Carlton United Breweries, Australian cable and wireless, BP, and in US, 20th Century Ins., Home Saving of America, Verizon, TTI, Trinet Inc, and many more. Narbik has been a dedicated CCIE instructor for over 10 years.

http://www.micronicstraining.com/ccie-routing-switching-lab.html

IPSEC Basics

The IPsec standard provides a method to manage authentication and data
protection between multiple
crypto peers engaging in secure data transfer.
IPsec includes the Internet Security Association and Key
Management Protocol
(ISAKMP)/Oakley and two IPsec IP protocols: Encapsulating Security Protocol
(ESP) and Authentication Header (AH).

IPsec uses symmetrical encryption algorithms for data protection. Symmetrical
encryption algorithms
are more efficient and easier to implement in hardware.
These algorithms need a secure method of key
exchange to ensure data protection.
Internet Key Exchange (IKE) ISAKMP/Oakley protocols provide
this capability.

This solution requires a standards-based way to secure data from eavesdropping
and modification. IPsec
provides such a method. IPsec provides a choice of
transform sets so that a user can choose the strength
of their data protection.
IPsec also has several Hashed Message Authentication Codes (HMAC) from

which to choose, each giving different levels of protection for attacks such as
man-in-the-middle, packet
replay (anti-replay), and data integrity attacks.

Best Regards,
Deepak Arora

Tuesday, May 19, 2009

Zone-Based Policy Firewall (ZFW)

Cisco IOS® Software Release 12.4(6)T introduced Zone-Based Policy Firewall (ZFW), a new configuration model for the Cisco IOS Firewall feature set. This new configuration model offers intuitive policies for multiple-interface routers, increased granularity of firewall policy application, and a default deny-all policy that prohibits traffic between firewall security zones until an explicit policy is applied to allow desirable traffic.

Nearly all classic Cisco IOS Firewall features implemented before Cisco IOS Software Release 12.4(6)T are supported in the new zone-based policy inspection interface:

  • Stateful packet inspection

  • VRF-aware Cisco IOS Firewall

  • URL filtering

  • Denial-of-Service (DoS) mitigation

Cisco IOS Software Release 12.4(9)T added ZFW support for per-class session/connection and throughput limits, as well as application inspection and control:

  • HTTP

  • Post Office Protocol (POP3), Internet Mail Access Protocol (IMAP), Simple Mail Transfer Protocol/Enhanced Simple Mail Transfer Protocol (SMTP/ESMTP)

  • Sun Remote Procedure Call (RPC)

  • Instant Messaging (IM) applications:

    • Microsoft Messenger

    • Yahoo! Messenger

    • AOL Instant Messenger

  • Peer-to-Peer (P2P) File Sharing:

    • Bittorrent

    • KaZaA

    • Gnutella

    • eDonkey

Cisco IOS Software Release 12.4(11)T added statistics for easier DoS protection tuning.

Some Cisco IOS Classic Firewall features and capabilities are not yet supported in a ZFW in Cisco IOS Software Release 12.4(15)T:

  • Authentication proxy

  • Stateful firewall failover

  • Unified firewall MIB

  • IPv6 stateful inspection

  • TCP out-of-order support

ZFW generally improves Cisco IOS performance for most firewall inspection activities.

Neither Cisco IOS ZFW or Classic Firewall include stateful inspection support for multicast traffic.

Best Regards,
Deepak Arora