Archive for October, 2007
Block IM Traffic on ASA
Ok so in a prior blog entry, I gave you my yahoo messenger ID and said you could communicate with me in real-time. I thought it only appropriate to also so you how you could deny IM traffic on the ASA without using a CSC module, IronPort Appliance or any other filtering software/tool. This functionality [...]
31Oct2007 | Joe Harris | 8 comments | ContinuedDaily Trivia - 10/31
Ok so I missed a day or two of the Daily Trivia Questions, I’ll do a better job of staying on top of this one …
Which of the following queuing tools allows for WRED to be configured inside a single queue?
A) First-In, First-Out Queuing (FIFO)
B) Priority Queuing (PQ)
C) Custom Queuing (CQ)
D) Weighted Fair Queuing (WFQ)
E) [...]
Partner Blogs
Hi Team,
I wanted to make sure you were aware of and visited two very well put together and informative blogs that I partner with. The links for these blogs are located on the left-hand sidebar in the section titled blogroll. The first is Chris Durkin’s MARS blog which has some very detailed and relevant [...]
Cisco IntelliShield Alert Manager Service
Have you heard of the Cisco Security IntelliShield Alert Manager Service? If not then let me tell you about it….the service provides a comprehensive, cost-effective solution for delivering the intelligence organizations need to identify, prevent, and quickly mitigate IT attacks. It’s a customizable, Web-based threat and vulnerability alert service that allows security staff to easily [...]
30Oct2007 | Joe Harris | 0 comments | ContinuedIntelliShield Periodic Security Activity Report
The IntelliShield Periodic Security Activity Report (PSAR) is a strategic intelligence product that highlights current security activity and mid- to long-range perspectives. The report addresses seven major risk management categories: vulnerability, physical, legal, trust, identity, human, and geopolitical. The PSARs are a result of collaborative efforts, information sharing, and collective security expertise of senior analysts [...]
30Oct2007 | Joe Harris | 0 comments | ContinuedReal-Time Communication
Want to communicate with me in real-time? Have a question regarding the site or a demo? Add me to your buddy list and you can contact me anytime…I use Yahoo Messenger and my ID is: jfh6200. I know there are many other programs out there that provide IM services but I have been using Yahoo [...]
29Oct2007 | Joe Harris | 0 comments | ContinuedInterface Level Redundancy
View this post via video : Click Here for Video Post
Interface-Level Redundancy is another new feature introduced in the 8.x version of the ASA/PIX code. In a nutshell, Interface-Level Redundancy is achieved by configuring a logical interface on top of two physical interfaces that reside on the same VLAN. One physical interface passes traffic whilst the [...]
Daily Trivia - 10/29
True or False, the SSL VPN (WebVPN) features in v7.0.x were included as a free trial. Starting with v7.1, use of SSL VPN features require the purchase and installation of a separate SSL VPN feature license. Cisco ASA Software v7.1/8.0 introduces significantly enhanced SSL VPN capabilities and scale to meet the needs of complex clientless environments.
Please [...]
29Oct2007 | Joe Harris | 0 comments | ContinuedWAN Emulation Toolkit
When I give WAAS demo’s to customers and partners alike, I typically use a standard network topology to keep my demo kit easy to administer but also the demo kit topology mimics most enterprises branch design connectivity options where there is a branch office connected back to the head end/data center. One of the major [...]
28Oct2007 | Joe Harris | 5 comments | ContinuedNetwork Topology Icons
Ever wanted to use those cool icons in your Visio diagram like they used to use in Packet Magazine before it was discontinued in Sept 2006? or have you ever wanted to use an exact replica of the physical hardware in a diagram for management? Or maybe even wanted to use a different color of [...]
27Oct2007 | Joe Harris | 0 comments | ContinuedRouter Security Bundles
One of the most frequently asked questions I receive when discussing security on IOS routers is the question that focuses on the different security bundles that Cisco offers. The question is usually like “What are all the different Security Bundles comprised of and how do they differ?”
This is a very fair question, because without [...]
Daily Trivia - 10/26
When discussing EIGRP’s DUAL algorithm, a feasible successor is considered loop-free if which condition is true?
A) its AD is equal to the metric of the successor
B) its FD is equal to the metric of the successor
C) its AD is greater than the successor’s FD
D) its AD is equal to the successor’s [...]
Daily Trivia - 10/25
True or False, Cisco WAAS provides an automatic discovery mechanism that uses TCP options during the initial three-way handshake to identify Cisco WAE appliances transparently. After automatic discovery, optimized connections experience a shift in the TCP sequence number to allow endpoints to distinguish between optimized and non-optimized flows.
Please email me your answer to be entered [...]
ASA with WAAS Deployment
Had a partner that is evaluating an ASA 5520 with an AIP-SSM-20 (IPS module) installed in the SSM slot in a WAAS deployment scenario. They wanted to confirm the behavior of the ASA when the ‘inspect wccp’ command was enabled.
policy-map global_policy
class inspection_default
inspect waas
After enabling the command they checked the output of the ‘show service-policy [...]
Pre-order CCIE Routing and Switching Exam Certification Guide
The completely revised and updated third edition of CCIE Routing and Switching Exam Certification Guide helps you master the concepts and techniques that will enable you to succeed on the exam the first time.
• Master CCIE 350-001 exam topics with the official study guide
• Assess your knowledge with chapter-opening quizzes
• Review key concepts with foundation [...]
Announcing the Cisco IPS AIM for ISRs.
The Cisco® Intrusion Prevention System Advanced Integration Module (IPS AIM) brings integrated intrusion prevention to enterprise branch offices and expands network security to the edge. The Cisco IPS AIM for the Cisco 1841 and Cisco 2800 and 3800 Series Integrated Services Routers brings Cisco IPS to branch offices and small businesses.
Cisco IPS is an integral [...]
Announcing the Cisco NAC Guest Server
Cisco® NAC Guest Server is a new appliance that works with either Cisco NAC Appliance or Cisco Wireless LAN controllers to manage the entire lifecycle of guest access, including:
Provisioning - Allows any internal sponsor to create accounts
Notification - Provides access details by print, email or sms
Management - Change and Suspend Accounts
Reporting - [...]
HTTP Troubleshooting Tool
Many times throughout the day, I get tasked with helping customers trace and troubleshoot HTTP issues related to their firewall implementations. Some these issues may be related to application layer protocol inspection features that the ASA/PIX provide and the customer may or may not have enabled. On other occasions it could be issues with how [...]
24Oct2007 | Joe Harris | 2 comments | ContinuedDaily Trivia - 10/23
When sizing your CSC-SSM module (anti-x module), what is considered a “user”?
A) Each unique IP address that is visible on any interface during a twenty-four (24) hour period will count as a user.
B) Each unique MAC address that is visible on any interface during a twenty-four (24) hour period will count as a user. [...]
BackTrack - Pen Test Tool
Pen Test tool BackTrack is the most Top rated linux live distribution focused on penetration testing. With no installation whatsoever, the analysis platform is started directly from the CD-Rom and is fully accessible within minutes. It’s evolved from the merge of the two wide spread distributions Whax and Auditor Security Collection. By joining forces and [...]
23Oct2007 | Joe Harris | 3 comments | Continued













