|
Everything related to Computer Security - Security Audits, Security Vulnerabilities, Intrusion Detection, Incident Handling, Forensics and Investigation, Information Security Policies, and a whole lot more.
Search This Blog
Friday, May 04, 2007
Security Management Weekly - May 4, 2007
About Net Security: Go Back In Time
| Net Security | |
| In the Spotlight | More Topics | Give Your Home a Makeover |
| from Tony Bradley, CISSP-ISSAP Why bother trying to figure out what is wrong with your computer? It might be nice to know what your computer is infected with or how it got compromised so you can avoid doing that again in the future, but you don't need to take the time to remove the malicious software or clean your system up. Not if you have System Restore. You can simply restore your system to a point in time before it was infectwed and voila! | |
| In the Spotlight | |
| Advertisement | ||||||||||||||||||
| | ||
| Visit Related About GuideSites: | ||
| Wireless / Networking | Antivirus Software | Focus on Windows |
| internet | ||
You are receiving this newsletter because you subscribed to the About Net Security newsletter as security.world@GMAIL.COM. If you wish to change or remove your email address, please visit: About respects your privacy. Our Privacy Policy. Our Contact Information. | ||
firewall-wizards Digest, Vol 13, Issue 2
firewall-wizards@listserv.icsalabs.com
To subscribe or unsubscribe via the World Wide Web, visit
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
or, via email, send a message with subject or body 'help' to
firewall-wizards-request@listserv.icsalabs.com
You can reach the person managing the list at
firewall-wizards-owner@listserv.icsalabs.com
When replying, please edit your Subject line so it is more specific
than "Re: Contents of firewall-wizards digest..."
Today's Topics:
1. Re: Cisco ASA and FWSM (Timo Schoeler)
2. Re: ASA 5510 problem (Skough Axel U/IT-S)
3. Re: ASA 5510 problem (Chris Wargaski)
----------------------------------------------------------------------
Message: 1
Date: Mon, 30 Apr 2007 15:34:51 +0200
From: Timo Schoeler <timo.schoeler@riscworks.net>
Subject: Re: [fw-wiz] Cisco ASA and FWSM
To: Firewall Wizards Security Mailing List
<firewall-wizards@listserv.icsalabs.com>
Cc: drsharp@pacbell.net
Message-ID: <20070430153451.24c27006.timo.schoeler@riscworks.net>
Content-Type: text/plain; charset="us-ascii"
On Sat, 28 Apr 2007 14:23:43 -0700
D Sharp <drsharp@pacbell.net> wrote:
> Hi;
>
> We have a Internet Portal inplace for some 2+ years based on a
> redundant set of 6500 switches with sup720s, IDS-SM, NAM, FWSM,
> switch blades. We also use the FWSM to create isolated non-production
> developement/test/QA areas. We also have PIX and ASA firewalls.
>
> Would we use FWSM again, not likely. We spent a great deal of time
> finding a stable version of software for both SUP720 and FWSM. The
> problems we have experienced may no longer exist in current code
> releases.
>
> But the FWSM is very compelling, yet it has to meet your
> requirements. You asked for a comparision, and as others have
> responded with some points. These are more on the design.
>
> Chassis versus standalone:
> FWSM 'interface' is a set of virtual gigabit intfs. bound into a
> single GEC (gigabit ether channel). Packets are 'load balanced' over
> these. You work with vlans, not interfaces.
> ASA top model supports (8) gig interfaces, but ether channel
> still does not appear to be supported. Not a big deal as the top ASA
> only supports up to 1.2gbs throughput.
yeah, and for the ASA-5520 (e.g.) they share one single interrupt.
worst hardware design ever.
> FWSM uses the shared bus of the chassis, not the switched bus.
> Thus the SUP32 and SUP720 modules are supported.
> Or less desireable, as your switched bus cards still have to send
> traffic over the shared bus for the FWSM.
> With externally connected firewalls, you save a chassis slot for
> another (48) port switch card, or some other special purpose module.
>
> There is another interesting design "feature" of the FWSM, it
> uses ONE MAC address per module. Thus all interfaces, layer 3, across
> all virtual firewalls share this MAC. This precludes some designs
> that would share a vlan.
>
> Capabilities, there are dozens of comparison points, my top 5 are:
> FWSM vs ASA5500
> 1: FWSM 5gbs over ASA 1.2gbs
> 2: flexible vlans, FWSM over ASA.
> 3: FWSM support for more ACLs, vlans, connections over ASA.
> 4: ASA for VPNs, not possible with FWSM.
> 5: ASA uses (8) network ports versus the FWSM usage of a slot.
>
> Hope this helps.
>
> Yours,
> Duncan Sharp
>
> Security Guy wrote:
>
> >As Avishai said, the FWSM is just a firewall, no VPN or IDS support
> >at all (those are different modules ;)
> >
> >If you can do without the features, you still have to consider cost:
> >the last time I looked at FWSMs they were in the 20k USD range..
> >
> >The main thing you get with FWSM is performance (supposedly about
> >6gb/s limited by the 6-gb etherchannel it takes from the backplane)
> >tied directly to your core switch/router, if that's what you're
> >looking for.
> >
> >
> >On 4/12/07, Kimberly Fields <kimberlymfields@gmail.com> wrote:
> >
> >
> >>Can anyone tell me what, if any, are the differences between the
> >>Cisco ASA firewall features and the Cisco FWSM firewall features?
> >>
> >>_______________________________________________
> >>firewall-wizards mailing list
> >>firewall-wizards@listserv.icsalabs.com
> >>https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
> >>
> >>
> >>
> >>
> >
> >
> >
> >
>
> _______________________________________________
> firewall-wizards mailing list
> firewall-wizards@listserv.icsalabs.com
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 187 bytes
Desc: not available
Url : https://listserv.icsalabs.com/pipermail/firewall-wizards/attachments/20070430/9493f4e1/attachment-0001.pgp
------------------------------
Message: 2
Date: Wed, 2 May 2007 21:58:01 +0200
From: "Skough Axel U/IT-S" <axel.skough@scb.se>
Subject: Re: [fw-wiz] ASA 5510 problem
To: "Firewall Wizards Security Mailing List"
<firewall-wizards@listserv.icsalabs.com>
Message-ID: <7D5607434F895540B2A717820399633D14B090@exs13.scb.intra>
Content-Type: text/plain; charset="iso-8859-1"
Hi,
Have you specified the VPN Pool range properly? It should be for example 10.10.10.0/24.
/ Axel
________________________________
From: firewall-wizards-bounces@listserv.icsalabs.com on behalf of Dehnert James Sr
Sent: Tue 2007-05-01 02:04
To: firewall-wizards@listserv.icsalabs.com
Subject: [fw-wiz] ASA 5510 problem
I have a Cisco ASA 5510 with an External, Internal, and DMZ
interfaces. I have a mail server in the DMZ and I have configured
the ASA so that I can get to it internally an externally, however,
when I log in using the IPSEC VPN I cannot connect.
The internal address range is 192.168.100.0/24
The dmz address range is 192.168.200.0/24
The VPM pool range is 10.10.10.10/24
I have mappings internally to so that any 192.168.100 host can
connect to the mail server at 192.168.200.25, but the VPN access
issue has me flummoxed.
Cisco has examples of VPN or DMZ, bit nothing with info on both.
Any pointers would be greatly appreciated.
Thanks,
Zeke
--
James "Zeke" Dehnert
mailto:jdehnert@norcalnetworks.com
Phone: +1 707.546.6620 x602 Fax: +1 707.324.8043
"Life is racing, everything else is just waiting"
_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/ms-tnef
Size: 4362 bytes
Desc: not available
Url : https://listserv.icsalabs.com/pipermail/firewall-wizards/attachments/20070502/f6d27ba7/attachment-0001.bin
------------------------------
Message: 3
Date: Thu, 3 May 2007 01:00:10 -0500
From: "Chris Wargaski" <cwargaski@rmstsi.com>
Subject: Re: [fw-wiz] ASA 5510 problem
To: "Firewall Wizards Security Mailing List"
<firewall-wizards@listserv.icsalabs.com>
Message-ID: <F7B8D9BB39700E48AAFAAC978C7ABB731DBD24@cliff.rmsbg.com>
Content-Type: text/plain; charset="iso-8859-1"
Zeke--
Are you able to access anything when you establish the VPN tunnel? How are you trying to access? (ping, email client?) Also, when you connect, is your connecting workstation directly connected to a public network, or are you behind a device performing NAT (like a home firewall)?
Can you post snippets of the configuration? (group-policy block, and any line beginning with the word crypto).
cjw
Christopher J. Wargaski
RMS Technology Solutions, Inc.
cwargaski@rmstsi.com
(847) 215-1661 x223
-----Original Message-----
From: firewall-wizards-bounces@listserv.icsalabs.com on behalf of Dehnert James Sr
Sent: Mon 4/30/2007 7:04 PM
To: firewall-wizards@listserv.icsalabs.com
Subject: [fw-wiz] ASA 5510 problem
I have a Cisco ASA 5510 with an External, Internal, and DMZ
interfaces. I have a mail server in the DMZ and I have configured
the ASA so that I can get to it internally an externally, however,
when I log in using the IPSEC VPN I cannot connect.
The internal address range is 192.168.100.0/24
The dmz address range is 192.168.200.0/24
The VPM pool range is 10.10.10.10/24
I have mappings internally to so that any 192.168.100 host can
connect to the mail server at 192.168.200.25, but the VPN access
issue has me flummoxed.
Cisco has examples of VPN or DMZ, bit nothing with info on both.
Any pointers would be greatly appreciated.
Thanks,
Zeke
--
James "Zeke" Dehnert
mailto:jdehnert@norcalnetworks.com
Phone: +1 707.546.6620 x602 Fax: +1 707.324.8043
"Life is racing, everything else is just waiting"
_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/ms-tnef
Size: 3598 bytes
Desc: not available
Url : https://listserv.icsalabs.com/pipermail/firewall-wizards/attachments/20070503/b5f71d4c/attachment-0001.bin
------------------------------
_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
End of firewall-wizards Digest, Vol 13, Issue 2
***********************************************
The Virtual Reality Check
consolidated IT infrastructures built on standardized parts
that can be manipulated, moved, and redeployed in an
instant. Companies are virtualizing at the OS and server
levels in droves. So why does your IT staff continue to
spend 60% of its time fixing problems? Because your
applications have been left behind!
You are invited to attend a Webcast that will discuss
application virtualization and how it can be used with
other virtualization technologies to complete the
vision of true, total enterprise efficiency.
The Virtual Reality Check
Tuesday, May 8th
10:00 AM PT / 1:00 PM ET
Click on the following link to attend this Webcast, brought
to you by Trigence and InfoWorld:
http://ifw-media.com/lrd0_AAcGRgAAcK4B
Applications are the last holdouts in the unvirtualized
world because they are, by nature, anything but standard. They
start adapting to their environments the second they are
installed and, once planted, nearly impossible to uproot
without change or damage.
Discover how applications can be turned into standardized
parts, even as custom settings and unique characteristics
are preserved.
Join us for an insightful discussion on this topic. Register
now to attend this Webcast:
http://ifw-media.com/lrd1_AAcGRgAAcK4B
*****************************************************************
When you applied for, or renewed your subscription, registered
at InfoWorld.com, subscribed to one of our email newsletters,
or registered for one of our events, you indicated that you would
like to receive e-mail about InfoWorld Products and Services.
To unsubscribe, click:
http://ifw-media.com/unsubscribe/u.html?u=AAcGRgAAcK4B
To view InfoWorld's Privacy Policy, click:
http://ifw-media.com/lrd2_AAcGRgAAcK4B
InfoWorld Media Group Circulation Dept.
501 Second St, San Francisco, CA, 94107-1496
InfoWorld Customer Service
PO Box 3511, Northbrook, IL 60065-3511
The color of information security; Microsoft pencils in seven bug fixes
Security News AlertThis newsletter is sponsored by SymantecNetwork World's Security News Alert, 05/04/07The color of information security, 05/01/07: If information security were a color, it most definitely would be gray. Like life in general, information security is rarely black and white. Click here for more. Microsoft pencils in seven bug fixes for next week, 05/03/07: Microsoft will issue seven security updates next week for Windows, Office, Exchange and BizTalk, the company announced Thursday. Click here for more. Microsoft weaving security, management into single platform, 05/03/07: Evident of a larger industry trend, Microsoft on Wednesday began to lay out a strategy to integrate security and management tools into its Forefront and System Center brands of products. Click here for more.
SonicWall bundles security services with firewall/VPN gear, 05/03/07: SonicWall is wrapping a reduced-price package of security services around some of its branch-office firewall/VPN hardware to provide what it calls unified threat management (UTM) for offices where such features formerly might have been too expensive. Click here for more. New bug-a-day project targets Microsoft's ActiveX, 05/02/07: Another bug-a-day campaign surfaced Tuesday as the "Month of ActiveX Bugs" debuted. Although some researchers have already dismissed the project as copycat, others are warning its findings might put Windows users at risk of attack. Click here for more. Entrust unveils online anti-fraud service, 05/02/07: Entrust Wednesday announced an online anti-fraud service that can be a source for information research as well as provide Entrust’s fraud-protection and third-party risk-assessment services. Click here for more. Montage update fixes bugs, 05/02/07: Mariner Software on Wednesday released Montage 1.2.2, a free update to their screenwriting software for Mac OS X. Montage costs $139.99. Click here for more. From John Obeto on Microsoft Blog: Microsoft security - no longer an oxymoron: From Cisco Press Author Expert Blog: Jeff Doyle: Managing your network's biggest risk: |
| Contact the author: Senior Editor Ellen Messmer covers security for Network World. E-mail Ellen. This newsletter is sponsored by SymantecBONUS FEATUREIT PRODUCT RESEARCH AT YOUR FINGERTIPS Get detailed information on thousands of products, conduct side-by-side comparisons and read product test and review results with Network World’s IT Buyer’s Guides. Find the best solution faster than ever with over 100 distinct categories across the security, storage, management, wireless, infrastructure and convergence markets. Click here for details. PRINT SUBSCRIPTIONS AVAILABLE International subscribers, click here. SUBSCRIPTION SERVICESTo subscribe or unsubscribe to any Network World newsletter, change your e-mail address or contact us, click here. This message was sent to: security.world@gmail.com. Please use this address when modifying your subscription. Advertising information: Write to Associate Publisher Online Susan Cardoza Network World, Inc., 118 Turnpike Road, Southborough, MA 01772 Copyright Network World, Inc., 2007 |
The rise of Alfresco
Linux & Open Source News AlertThis newsletter is sponsored by NovellLinuxWorld's Linux and Open Source News Alert, 05/04/07LinuxWorld.com Feature Story The rise of Alfresco: ECM that people will really use - LinuxWorld, 04/27/07 More of this week's Linux news
New Linux kernel version pumps up virtualization - LinuxWorld, 05/02/07 Proposed Microsoft, IBM identity protocol standard spawns controversy - LinuxWorld, 05/02/07 Sun's Rock rolls further along - LinuxWorld, 05/02/07 Dell to offer preinstalled Ubuntu on laptops, desktops - LinuxWorld, 05/01/07 Kernel space: Chunkfs and reiser4 - LinuxWorld, 05/01/07 School system taps Novell to control network identity - LinuxWorld, 05/01/07 Search Wikia hires Jabber founder, expands concept - LinuxWorld, 05/01/07 Oracle’s Linux initiative continues to build momentum against Red Hat - LinuxWorld, 04/30/07 Spring Java framework gets a Java 6 upgrade - LinuxWorld, 04/30/07 LinuxWorld Community Three problems (or opportunities) in Linux |
| Contact the author: Don Marti is editor of LinuxWorld.com. Phil Hochmuth writes Network World's Linux Newsletter. This newsletter is sponsored by NovellBONUS FEATUREIT PRODUCT RESEARCH AT YOUR FINGERTIPS Get detailed information on thousands of products, conduct side-by-side comparisons and read product test and review results with Network World’s IT Buyer’s Guides. Find the best solution faster than ever with over 100 distinct categories across the security, storage, management, wireless, infrastructure and convergence markets. Click here for details. PRINT SUBSCRIPTIONS AVAILABLE International subscribers, click here. SUBSCRIPTION SERVICESTo subscribe or unsubscribe to any Network World newsletter, change your e-mail address or contact us, click here. This message was sent to: security.world@gmail.com. Please use this address when modifying your subscription. Advertising information: Write to Associate Publisher Online Susan Cardoza Network World, Inc., 118 Turnpike Road, Southborough, MA 01772 Copyright Network World, Inc., 2007 |
Spammers use new technique to evade filters; E-mail harvesters hit with antispam lawsuit
Antispam News AlertThis newsletter is sponsored by Arsenal Digital Solutions Automated Off-Site Data Protection for SMBs Network World's Anti-spam News Alert, 05/04/07Spammers use new technique to evade filters, 05/03/07: Spammers have stepped up efforts to use encrypted attachments to evade filtering systems, service provider Email Systems has reported. Proofpoint releases dynamic reputation service, 05/03/07: Proofpoint this week announced an e-mail reputation service for its security software and appliances that drops connections from known spammers and other questionable senders, cutting down on unwanted messages while saving valuable resources on a corporation’s network. E-mail harvesters hit with $1 billion antispam lawsuit, 04/26/07: A $1 billion lawsuit filed Thursday promises to open up a new front in the battle against spam: It targets not just spammers, but -- for the first time -- also those responsible for harvesting e-mail addresses on behalf of spammers.
Podcast: Striking a Microsoft nerve, 05/04/07: Jason and Keith share listener reaction to Keith's "I am never buying another Microsoft operating system" rant hits a chord with listeners, why spam won't go away, whether IT managers should be fired if their company has a major security breach, and guess how much money Spider-Man 3 will make this weekend. (39:09) |
| Contact the author: Contact Site Editor Jeff Caruso This newsletter is sponsored by Arsenal Digital Solutions Automated Off-Site Data Protection for SMBs BONUS FEATUREIT PRODUCT RESEARCH AT YOUR FINGERTIPS Get detailed information on thousands of products, conduct side-by-side comparisons and read product test and review results with Network World’s IT Buyer’s Guides. Find the best solution faster than ever with over 100 distinct categories across the security, storage, management, wireless, infrastructure and convergence markets. Click here for details. PRINT SUBSCRIPTIONS AVAILABLE International subscribers, click here. SUBSCRIPTION SERVICESTo subscribe or unsubscribe to any Network World newsletter, change your e-mail address or contact us, click here. This message was sent to: security.world@gmail.com. Please use this address when modifying your subscription. Advertising information: Write to Associate Publisher Online Susan Cardoza Network World, Inc., 118 Turnpike Road, Southborough, MA 01772 Copyright Network World, Inc., 2007 |
Microsoft reportedly intensifies interest in Yahoo
Special News AlertNETWORK WORLD SPECIAL NEWS ALERT, 05/04/07Microsoft reportedly intensifies interest in Yahoo Having lost to Google in a bid for Internet advertising company DoubleClick, Microsoft has initiated a new round of talks with Yahoo, The New York Post reported Friday, citing sources familiar with the talks. The Wall Street Journal also reported the talks. For more on this developing story, please click here. |
| Contact the author: Contact Site Editor Jeff Caruso BONUS FEATUREIT PRODUCT RESEARCH AT YOUR FINGERTIPS Get detailed information on thousands of products, conduct side-by-side comparisons and read product test and review results with Network World’s IT Buyer’s Guides. Find the best solution faster than ever with over 100 distinct categories across the security, storage, management, wireless, infrastructure and convergence markets. Click here for details. PRINT SUBSCRIPTIONS AVAILABLE International subscribers, click here. SUBSCRIPTION SERVICESTo subscribe or unsubscribe to any Network World newsletter, change your e-mail address or contact us, click here. This message was sent to: security.world@gmail.com. Please use this address when modifying your subscription. Advertising information: Write to Associate Publisher Online Susan Cardoza Network World, Inc., 118 Turnpike Road, Southborough, MA 01772 Copyright Network World, Inc., 2007 |
Identity protocol standard spawns controversy; First WiMAX laptop card approved by FCC
Standards and Regulatory Compliance News AlertThis newsletter is sponsored by SolarWindsNetwork World's Standards and Regulations News Alert, 05/04/07Proposed Microsoft, IBM identity protocol standard spawns controversy,05/02/07: A protocol developed by IBM and Microsoft for standardizing the sharing of user identities between companies was turned over to a standards body on Wednesday amid controversy that it overlaps with similar protocols already recognized as standards. Meru unveils enterprise 802.11n WLAN gear, 04/30/07: The first enterprise-class wireless LAN products supporting the IEEE 802.11n draft standard, and promising data rates of 300Mbps, have been announced this week by Meru Networks. First WiMAX laptop card approved by FCC, Clearwire says, 05/01/07: Regulators have approved the first WiMAX wireless broadband laptop PC card to be offered by Clearwire, and it should be available to users later this year, the company said Tuesday.
Steak n Shake beefs up security, 04/30/07: Credit card security may not exactly be a top-of-mind item for customers dining on steakburgers and milkshakes at any of the 450-odd Steak n Shake restaurants scattered around the Midwest and Southeast. |
| Contact the author: Contact Site Editor Jeff Caruso This newsletter is sponsored by SolarWindsBONUS FEATUREIT PRODUCT RESEARCH AT YOUR FINGERTIPS Get detailed information on thousands of products, conduct side-by-side comparisons and read product test and review results with Network World’s IT Buyer’s Guides. Find the best solution faster than ever with over 100 distinct categories across the security, storage, management, wireless, infrastructure and convergence markets. Click here for details. PRINT SUBSCRIPTIONS AVAILABLE International subscribers, click here. SUBSCRIPTION SERVICESTo subscribe or unsubscribe to any Network World newsletter, change your e-mail address or contact us, click here. This message was sent to: security.world@gmail.com. Please use this address when modifying your subscription. Advertising information: Write to Associate Publisher Online Susan Cardoza Network World, Inc., 118 Turnpike Road, Southborough, MA 01772 Copyright Network World, Inc., 2007 |
Court rejects Vonage request for retrial; Do we really need a security industry?
Daily News: AMThis newsletter is sponsored by Arsenal Digital SolutionsNetwork World Daily News: AM, 05/04/07Court rejects Vonage request for retrial SLAs are just 'marketing fodder,' says provider exec Microsoft weaving security, management into single platform
Management heavies get poor grades in Gartner survey T-Mobile offering free Windows Mobile upgrade SaaS adopters in for big challenges Google opens Singapore office, eyes Southeast Asia Microsoft buys mobile advertising company ScreenTonic Podcast Striking a Microsoft nerve Blogs Buzzblog: "Do we really need a security industry?" Today on Layer 8 where everything we say is at least colorful: Buzzblog: Some schools dropping laptop programs From John Obeto on Microsoft Blog: Microsoft security - no longer an oxymoron: From Cisco Press Author Expert Blog: Jeff Doyle: Managing your network's biggest risk |
| Contact the author: Questions? Feedback? Contact NetworkWorld.com Site Editor Jeff Caruso. This newsletter is sponsored by Arsenal Digital SolutionsBONUS FEATUREIT PRODUCT RESEARCH AT YOUR FINGERTIPS Get detailed information on thousands of products, conduct side-by-side comparisons and read product test and review results with Network World’s IT Buyer’s Guides. Find the best solution faster than ever with over 100 distinct categories across the security, storage, management, wireless, infrastructure and convergence markets. Click here for details. PRINT SUBSCRIPTIONS AVAILABLE International subscribers, click here. SUBSCRIPTION SERVICESTo subscribe or unsubscribe to any Network World newsletter, change your e-mail address or contact us, click here. This message was sent to: security.world@gmail.com. Please use this address when modifying your subscription. Advertising information: Write to Associate Publisher Online Susan Cardoza Network World, Inc., 118 Turnpike Road, Southborough, MA 01772 Copyright Network World, Inc., 2007 |
Each Friday, we present a short list of the hottest whitepapers, webcasts and research available. Information you can use to solve problems that crept up during the week, and to prepare for the challenges you'll face in the days ahead. We also provide links to news stories you might have missed, plus facts, quotes and other forms of brain-candy. (Hint: The fun stuff is near the bottom, so don't forget to scroll.) Have a great weekend!
Arsenal Digital Solutions: Automated Off-Site Data Protection for SMBs
Many of today's users are remote, just like the chances of staying in business without backing them up.
Sunbelt Software: The SMART Way to Secure Messaging for Microsoft Exchange Environments
Because attacking email security with separate solutions is like trying to stay dry in a rainstorm with multiple cocktail umbrellas.
Novell: The Comprehensive Access Manager Solution for Your Enterprise
Progress your success in assessing excess access.
St. Bernard Software: Fighting the Hidden Dangers of Internet Access
Your hacked domain has a pharm, ee-oy-ee-oy-oh.
LinuxWorld Conference & Expo: August 6-9, 2007 - San Francisco, California
Immerse yourself in 100+ technical conference sessions and preview the latest products and services from hundreds of key Linux and open source exhibitors. Register for LinuxWorld today using priority code B0103 to save up to $500 off regular conference rates or receive a complimentary Exhibit Hall Pass.
Search the Premier IT Knowledge Base at IDG Connect
All the whitepapers, webcasts and other research you need to make smart decisions.
Give Your Opinions on IT and Business Issues
Join IDC's Survey Panel to receive complimentary IDC research and discounted conferences passes.
1975 Sony Betamax Promotional Video
Wait--watch one program and save another? Amazing!
On this day in 1910, the Royal Canadian Navy was created. In 1904, the United States began construction on the Panama Canal. In 1675, King Charles II of England ordered the construction of the Royal Greenwich Observatory. In 1626, Dutch explorer Peter Minuit arrived in New Netherland (present day Manhattan Island). And in 1494, Christopher Columbus landed in Jamaica. Happy Birthday Lance Bass (1979), Ana Gasteyer (1967), Randy Travis (1959), Keith Haring (1958) and Pia Zadora (1954). RIP cartoonist Bob Clampett (d. 1984), stooge Moe Howard (1975) and Kent State victims Allison Krause, Jeffrey Miller, Sandra Scheuer and William Schroeder (1970).
"It wasn't raining when Noah built the Ark."
- Howard Ruff
</FRIDAY>
IDG Connect is a service of IDG Communications, Inc. - the world's leading technology media and event company. IDG Communications' company brands include CIO, CSO, Computerworld, GamePro, InfoWorld, Macworld, Network World, and PC World, as well as technology-related events including LinuxWorld Conference & Expo, Macworld Conference & Expo, and DEMO.
As a customer of one of the IDG Communications brands, you became eligible to receive email from IDG Connect. For more information, read the IDG Privacy Statement.
If you do not wish to receive future communication from IDG Connect, please modify your email preferences here.
IDG Connect 3 Speen Street, Framingham, MA 01701
Thursday, May 03, 2007
RE: Public WiFi Access Authentication
business use.
Though this may offend some open source purists, for business use you may
also want to look into ready made, supported solutions. They range from
fairly cheap to fairly expensive. The advantage obviously is paid for, fast
support in case revenue gets lost with every minute of downtime.
Some solutions I've had good experience with are
MikroTik RouterOS - you can buy the OS (runs on standard Linux hardware) or
an appliance from them. Quite a large, helpful user base.
Nomadix - mid-range solution, often used in hotels to provide internet
services in the rooms.
BlueSocket - heavy duty, enterprise class appliance. Based on Linux,
administrated through an extensive web interface or via an XML-RPC API.
Their high end boxes support literally thousands of concurrent users.
HTH,
Felix
-----Original Message-----
From: Michelle Konzack [mailto:linux4michelle@freenet.de]
Sent: Wednesday, May 02, 2007 10:19 AM
To: debian-firewall
Subject: Public WiFi Access Authentication
Hello,
I have some 802.11a Access Point (privately) in Strasbourg and want to
open it public. The solutions I have found are not suitable and some
are realy strange.
What I have:
|
|
| 802.11a Auth-Router Main
+---- Access ---- (Etch) ---> Router <----> Internet
Point DHCP
I want, that the Auth-Router block ANY traffic until the $CLIENT which
connect over the Access-Point call ANY http-URL and autentificate.
Then the $CLIENT is allowed to use the connection until the last traffic
was on its MAC/IP for, e.g. 5 minutes, then the $CLIENT is required to
re-authenticate.
Also I need to prohibit that sevewral Clients use my Access-Point as
free bridge for there traffic.
I was searching the Net for a sample config how to do this but failed.
So, I want to install the authentication website directly on the Auth-
Router.
Does anyone has done this before and how must I make the iptables setup
to let this work?
Thanks, Greetings and nice Day
Michelle Konzack
Systemadministrator
Tamay Dogan Network
Debian GNU/Linux Consultant
--
Linux-User #280138 with the Linux Counter, http://counter.li.org/
##################### Debian GNU/Linux Consultant #####################
Michelle Konzack Apt. 917 ICQ #328449886
50, rue de Soultz MSN LinuxMichi
0033/6/61925193 67100 Strasbourg/France IRC #Debian (irc.icq.com)