Search This Blog

Friday, May 04, 2007

Security Management Weekly - May 4, 2007

header

  Learn more! ->   sm professional  

May 4, 2007
 
 
CORPORATE SECURITY  
  1. " Campus Safety Gains Sharper Vision With New Breed of Surveillance Cameras"
  2. " U.S. Officials Recommend Better RFID Security"
  3. " College Rampage Renews School Safety Concerns for K-12 Leaders"
  4. " Respectful Cameras" UC Berkeley Scientists Develop Privacy-Protecting Surveillance Cameras
  5. " Counterfeit Products and Faulty Supply Chain"
  6. " Identity Theft: How Do We Manage the Risk?"
  7. " Preparing a Workplace for Pandemic"

HOMELAND SECURITY   sponsored by  
  8. " U.S. Seeks Closing of Visa Loophole for Britons" DHS Concerned About British Pakistanis Entering U.S.
  9. " 5 Britons Guilty in Bomb Plot; Tied to 2005 London Attackers" Fertilizer-Bomb Plotters Had Ties to 7/7 London Bombers
  10. " U.S. to Plug Border-Security Gap" DHS to Use Interpol Stolen and Lost Travel Document Database
  11. " Cargo Screening Finally Taking Off" Cargo-Screening Pilot Program to Launch at San Francisco Airport
  12. " New Sensor Developed for Homeland Security" Sandia National Laboratories Researchers Develop Bioagent Detection System
  13. " Secret Service Guards Obama, Taking Unusually Early Step" DHS Authorizes Security Detail for Barack Obama

CYBER SECURITY  
  14. " Using a Good Name for Bad Deeds: Cybercrooks Turn to 'Brandjacking'"
  15. " Navigate the NAC Choices" Factors to Consider Before Pursuing a Network Access-Control Strategy


   








 

"Campus Safety Gains Sharper Vision With New Breed of Surveillance Cameras"
Chronicle of Higher Education (04/27/07) Vol. 53, No. 34, P. 15 ; Fischman, Josh; Foster, Andrea L.

To boost security in its dormitories, Johns Hopkins University relies on "smart TV," according to Edmund G. Skrodzki, executive director of campus safety and security. Over the past two years, the university installed 101 surveillance cameras in dormitories along Charles Street in addition to some off-campus sites. The cameras are linked to computer software that can determine such things as when a person has his or her arms in the air or a vehicle is moving in a suspiciously slow manner; the software also issues alerts to campus security. Skrodzki says the new cameras at Johns Hopkins have made the campus "more proactive rather than reactive," and have already helped catch a person trying to steal a motorbike and identify an armed thief. Campus crime at Hopkins has declined by 43 percent since 2004, and some of that can be attributed to the cameras, he says. Before installation of the cameras began, Johns Hopkins officials asked the student chapter of the American Civil Liberties Union to talk about the system in an effort to reduce concerns over privacy. The students learned, for example, that the cameras block out any footage of direct window views. The technology reflects the growing presence of camera-based surveillance at universities, which may increase even more in the wake of the April 16 Virginia Tech shootings.
(go to web site)

"U.S. Officials Recommend Better RFID Security"
Network World (04/30/07) ; Brodkin, Jon

Radio frequency identification (RFID) systems pose unique security challenges, which is why all organizations employing RFID devices should conduct comprehensive evaluations of the technology's potential security risks, suggests a new report from the federal government. Security and privacy risks stem from the fact that multiple organizations--including manufacturers, suppliers, and retailers--may handle RFID tags. Experts note that in hospitals, unauthorized RFID use or eavesdropping could lead to security breaches involving test results or dangerous materials. The report, which was mandated by Congress and released by the Department of Commerce's National Institute of Standards and Technology, includes hypothetical case studies. The report also delineates best practices for RFID use by federal agencies, hospitals, manufacturers, and retailers, such as using firewalls, encrypting radio signals, and authenticating approved RFID users.
(go to web site)

"College Rampage Renews School Safety Concerns for K-12 Leaders"
Education Week (04/25/07) Vol. 26, No. 34, P. 1 ; Maxwell, Lesli A.

The Virginia Tech shooting on April 16 has raised concerns over school security similar to those in the aftermath of the 1999 Columbine High School incident. Jill L. Martin, the principal at Thomas B. Doherty High School in Colorado, says students at her school are urged to notify officials if they see something out of the ordinary, and "students have become very aware that it can be a big mistake to ignore something." Gregory A. Thomas, who directs a school-preparedness program at Columbia University's National Center for Disaster Preparedness, notes that the Virginia Tech shooting "was perpetrated by a student shooter who apparently had showed many of the signs we've seen in the shooters that have done this in our high schools." The signs exhibited by the shooter, Seung-Hui Cho, include being uncommunicative, solitary, and writing alarming compositions, says school psychologist Cathy Paine. She recommends that school staff, including teachers, counselors, and administrators, look out for and report to the appropriate authorities any threatening writings, isolation, and depression. However, they also need to make that decision based on their knowledge of the student in a wider context, she says, including the observations of fellow students, parents, teachers, and school counselors.
(go to web site)

"Respectful Cameras"
Technology Review (05/02/07) ; Borrell, Brendan

University of California, Berkeley computer scientists have developed "respectful cameras," a new type of video surveillance technology that covers a person's face with an oval for privacy but removes the oval in the event of an investigation. Respectful cameras are still in the research phase, as they are only capable of covering someone's face if that person is wearing a marker such as a green vest or yellow hat, but the cameras could be a compromise between privacy advocates and those concerned about security, according to UC Berkeley computer scientist Ken Goldberg. The researchers used a statistical classification approach called adaptive boosting to teach the system to identify the marker in a visually complicated environment, and added a tracker to compensate for the subject's velocity and other interframe information. When the system was tested using a vest at a construction site, the marker was correctly identified 93 percent of the time, and under more uniform lighting conditions while testing a hat in a lab, the system was 96 percent successful, even when two marked individuals crossed paths. Goldberg said the marker is necessary as face-detection algorithms are not advanced enough yet, but that a less conspicuous marker, like a button, could be used, particularly with systems of multiple cameras. Still, even if privacy protection camera systems were widely deployed, there likely would be debate on how difficult it should be for governments and law enforcement to see fully unobscured video footage.
(go to web site)

"Counterfeit Products and Faulty Supply Chain"
Risk Management (04/07) Vol. 54, No. 4, P. 58 ; Wald, Jerry; Holleran, Jack

Counterfeiting and gray-marketing of a company's products are particularly frightening areas of risk for many businesses because they span strategic, operational, and reputational risks. However, effective risk management can help companies better protect their customers from counterfeit products and ensure that their supply chains are not corrupted. Johnson & Johnson's Medical Device & Diagnostic (MD&D) business recently discovered that unauthorized dealers were selling its products, which eventually led to MD&D products being mixed with counterfeits. After determining that some of the products being sold as MD&D were in fact counterfeit, the company sought the advice of consulting firm Ernst & Young to study business practices throughout the supply chain to determine which links in the chain were most vulnerable to integrity issues. Ernst & Young found the decentralized nature of Johnson & Johnson's operations resulted in too many disparate brand protection policies, which were deemed ineffectual as a means to protect brand image and reputation. In addition, having a single person at MD&D who would be responsible for brand protection would make it easier for the company to aggressively combat counterfeits. Consultants also suggested improvements be made to information gathering and reporting processes to ensure that problems were easily identified and quickly remedied. MD&D followed the advice of Ernst & Young, which the firm credits with improved monitoring programs and tracking for its products and marketing endeavors.
(go to web site)

"Identity Theft: How Do We Manage the Risk?"
Claims (04/07) Vol. 55, No. 4, P. 19 ; Quinley, Kevin M.

Identity theft can be a significant risk for both individuals and the companies managing individuals' data; the average monetary loss from identity theft hovers around $6,000, plus the amount of time victims spend closing fraudulent accounts and restoring damaged credit. In addition, the longer it takes consumers to notice the fraud, the more compounded losses become. Companies should be proactive in their strategies to reduce identity theft possibilities, and these strategies can mirror those already in use to mitigate losses from other risks. Insurance is always one of the major tools in the risk manager's arsenal; many insurers offer both stand-alone identity theft insurance and identity theft clauses for general policies. The most useful risk-management techniques, however, are likely to be in the area of loss control. Regular credit reports and the retention of important financial information will help consumers spot an identity-theft attempt soon after it occurs. Prompt filing of a report with the U.S. Federal Trade Commission should also help reduce potential fraud losses. Other techniques may include retention of enough funds to cover potential identity-theft losses, and behavioral changes to reduce consumer vulnerabilities, although to become totally invulnerable, a consumer would essentially have to stop participating in modern banking systems. Even though identity theft appears to be a consumer-oriented risk, third-party businesses may also find themselves at risk, especially if cases are successful at pinpointing inefficiencies in business systems that allowed consumer information to remain unsecured.
(go to web site)

"Preparing a Workplace for Pandemic"
Risk & Insurance (04/07) Vol. 18, No. 4, P. 8 ; Fogg, Erin

The Occupational Safety and Health Administration has released new safety guidelines for a bird-flu pandemic. Titled "Guidance on Preparing Workplaces for an Influenza Pandemic," the handbook classifies company operations into four zones, according to risk of exposure during an outbreak. The report includes recommendations for each category for work practices, engineering controls, and the use of personal protective equipment. Companies are also instructed on how to maintain operations during an outbreak and about the importance of educating employees and customers on social distancing and proper hygiene.
(go to web site)

"U.S. Seeks Closing of Visa Loophole for Britons"
New York Times (05/02/07) ; Perlez, Jane

The Department of Homeland Security (DHS), alarmed by the number of British Pakistanis who have been tied to terrorism plots against Britain, is talking with the U.K. government about ways to prevent U.K. Pakistanis from entering the United States via the visa-waiver program that allows U.K. citizens to enter the United States without a visa. There are about 800,000 British Pakistanis living in the United Kingdom, and these citizens make about 400,000 trips to Pakistan per year. The vast majority of these trips are legitimate, but some U.K. Pakistanis are using these trips to meet with extremists and receive terrorism training. The DHS is concerned that radicalized U.K. Pakistanis will travel to the United States without a visa to launch attacks against the United States; thus, DHS Secretary Michael Chertoff has been talking with U.K. officials for the past several months on ways to mitigate this threat. U.K. officials say that Chertoff is especially concerned about radicalized U.K. Pakistanis who do not have a prior criminal record--such as the ringleader of the U.K. fertilizer-bomb plot who was convicted on Monday. U.S. and U.K. officials are discussing several proposals, the most drastic of which would eliminate the visa-waiver program in its entirety. Another proposal would require that U.K. Pakistanis make visa applications for the United States, but this is considered to be politically sensitive.
(go to web site)

"5 Britons Guilty in Bomb Plot; Tied to 2005 London Attackers"
New York Times (05/01/07) P. A1 ; Perlez, Jane; Sciolino, Elaine

Two of five British Muslim men who were found guilty Monday of plotting to bomb targets around London had ties to two of the four suicide bombers who carried out the deadly July 7, 2005, attacks in London. This information was revealed during the trial but was revealed publicly for the first time on Monday because the judge overseeing the case had placed a gag order on the press until the conclusion of the trial. Monday's verdict marked the end of a one-year trial of seven suspects, five of whom were found guilty of plotting fertilizer bombings that targeted an airliner, a major shopping center, a popular nightclub, and public utilities. The five guilty suspects have been sentenced to life in prison. The evidence produced during the trial shows that the leader of the fertilizer bombing plot met several times with the leader of the July 7 bombings and that several of the fertilizer bombing plotters had trained at the same terrorist training camp in Pakistan as the leader of the July 7 plot. Thousands of police and investigators were involved in monitoring the fertilizer bombing plot, and two of the July 7 bombers actually came under investigation, but authorities ended this investigation after wrongly concluding that they were merely petty criminals who had loose contact with members of the fertilizer bombing plot.
(go to web site)

"U.S. to Plug Border-Security Gap"
Wall Street Journal (05/02/07) P. A6 ; Block, Robert; Fields, Gary

The Department of Homeland Security (DHS), recognizing the serious threat that stolen or lost passports pose to U.S. border security, will begin using Interpol's database of stolen passports by year's end. The Interpol Stolen and Lost Travel Document database will be used by U.S. Customs and Immigration officers at 225 U.S. points of entry. Interpol made the database available to the U.S. government about two years ago, but until recently the DHS was reluctant to use the system, citing the system's inconsistency and slowness, among other things. This two-year delay has prompted criticism from some observers. DHS spokesman Russ Knocke said that technology procurements related to the Interpol database are already underway. "It's going to be an added tool for front-line personnel and an important contribution to their decision-making about who they let into the country and who they send back," Knocke said.
(go to web site)

"Cargo Screening Finally Taking Off"
Los Angeles Times (04/30/07) ; Oldham, Jennifer

Beginning this summer, the Transportation Security Administration (TSA) and Department of Homeland Security (DHS) Directorate for Science and Technology will launch a six-month cargo-screening pilot program at San Francisco International Airport. The pilot program will screen six times the amount of cargo that is currently screened; an $8 million sorting facility dedicated to screening cargo has been constructed. A group of specially trained airport security screeners will check cargo by taking apart pallets and removing the merchandise inside. Depending on their size and shape, individual pieces of merchandise will be subjected to different screening technologies--for example, paper will be placed in one system, while fruit will be placed in another. Federal lawmakers are currently considering the introduction of legislation that would require the TSA to screen all cargo aboard passenger airliners by 2009. The TSA justifies its current screening procedures by saying that cargo placed aboard passenger airliners passes through several layers of security, including inspection of all individual packages checked at airports and subjection of some shipments to bomb-sniffing dogs. "All cargo carried on passenger planes is only handled by companies that have security programs that have met our requirements," says TSA spokesman Nico Melendez. "These companies are subject to our inspections to make sure they're complying with the rules." The TSA is also running a cargo-screening pilot program at Cincinnati/Northern Kentucky International Airport and a stowaway-detecting pilot program at Seattle-Tacoma International Airport. DHS will submit a report to Congress on the results of all three pilot programs by the end of 2007.
(go to web site)

"New Sensor Developed for Homeland Security"
United Press International (05/02/07)

Government scientists at Sandia National Laboratories are developing a unique bioagent detection system that is capable of detecting thousands of different biomolecules on a single platform. The sensor could have applications in homeland security as an anti-bioterrorism device, the researchers said. Most existing biosensors are of limited use in homeland security because they are only capable of detecting one kind of biomolecule at a time, according to the researchers. In contrast, the Sandia sensor is capable of testing numerous characteristics of multiple bioagent targets on a single platform, allowing the sensor to detect thousands of biomolecules at the same time.
(go to web site)

"Secret Service Guards Obama, Taking Unusually Early Step"
New York Times (05/04/07) P. A19 ; Zeleny, Jeff

Voting in the Democratic primaries is still nine months away, but Department of Homeland Security Secretary Michael Chertoff has authorized the Secret Service to provide protection for Democratic presidential candidate Barack Obama. The decision marks the earliest that a presidential candidate has ever received a Secret Service security detail. A Secret Service spokesman would not say why security was increased for Obama, and he said that he was not aware of any direct threats against Obama. Department of Homeland Security spokesman Russ Knocke would not comment about any specific threats to Obama, but he did say that several factors were taken into account. "That includes things like the candidate having certain financial standings, pre-eminence in public opinion polls, and actively campaigning," Knocke said. Obama's campaign hired private security guards to protect him after he announced his candidacy four months ago, and some of these guards are former federal agents. Obama's wife, Michelle, has said that she fears for her husband's safety on the campaign trail. "Security was one of many issues that I have and will have in the course of this campaign," she said.
(go to web site)

"Using a Good Name for Bad Deeds: Cybercrooks Turn to 'Brandjacking'"
Investor's Business Daily (05/01/07) P. A5 ; Howell, Donna

Anti-fraud firm MarkMonitor has released its inaugural "Brandjacking Index" report, which looks at how the top 25 brands in the world (as ranked by Interbrand) are abused on the Internet. The term brandjacking refers to the various ways that criminals on the Internet can take advantage of a brand's name, such as weaving brand names in their Web site content in order to rank highly on search engine results. Cybercriminals also sometimes register misspelled variations of popular brands as domain names, in order to mimic branded Web sites. Cybersquatting is still the greatest threat to brands in terms of sheer numbers--for example, MarkMonitor reported 286,000 instances of cybersquatting during a one-month period this year. MarkMonitor CMO Frederick Feldman explains that cybersquatting is usually combined with e-commerce abuse or another form of brand abuse. Feldman also says that one of the biggest problems related to registering trademarks is enforcing the registrations. "You might have 10,000 active cybersquatter instances against your organization and brands," he says. Domain kiting--the practice of trying out domains during a free five-day trial period--can also be a form of brand abuse, although it is more a nuisance than a threat.
(go to web site)

"Navigate the NAC Choices"
Communications News (04/07) Vol. 44, No. 4, P. 18 ; Lee, Alfred

There are a number of considerations that must be made before an organization begins to pursue a network access-control (NAC) strategy. The first is whether or not the organization can benefit from a NAC solution. Organizations can make this determination by taking a look at the problems their network is facing. If the most common source of network infection was from an unmanaged user's laptop, an employee's laptop, or a virtual private network tunnel from a remote worker who accessed the organization's network from his home computer, chances are good that the organization could benefit from having a NAC solution. Another consideration is whether to use an agentless NAC option or an installed-agent method. An agentless NAC strategy does not require client installs or downloads, which allows test results to be gathered before a security policy is enforced. Such a strategy is beneficial for networks that are totally comprised of Windows devices, since a domain administrative account can be used to log onto the device for testing. However, the installed-agent method offers the largest number of possible capabilities, including the ability to take full advantage of a platform's application programming interface. Finally, organizations need to consider the various deployment options for NAC, including hardware, software, all-in-one appliances, and secure switches. Organizations should consider a number of factors when deciding which option is appropriate for their network, including the size of their network, the variety of operating systems and networking gear, and their budget.
(go to web site)

Abstracts Copyright © 2007 Information, Inc. Bethesda, MD


  ASIS also offers a daily and a non-sponsored, special-content Professional Edition of
Security Newsbriefs. Please click to see a sample or to contact us for more information.

Unsubscribe | Change E-mail | Advertising Opportunities | Security Management Online | ASIS Online

About Net Security: Go Back In Time

About.com   Net Security
In the Spotlight | More Topics | Give Your Home a Makeover
  from Tony Bradley, CISSP-ISSAP
Why bother trying to figure out what is wrong with your computer? It might be nice to know what your computer is infected with or how it got compromised so you can avoid doing that again in the future, but you don't need to take the time to remove the malicious software or clean your system up. Not if you have System Restore. You can simply restore your system to a point in time before it was infectwed and voila!

 
In the Spotlight
Undo Malware Infections On Your System
Have you ever been infected with a virus or worm? How about compromised with some spyware? Has your computer ever been taken over by a Bot of some kind? There are tools available...read more

 
         More Topics
Secure Your Wireless Network
Do you have a wireless network at home? Did you buy a wireless router or home wireless networking "kit" and just plug it in? If so, you are probably enjoying the many benefits and freedoms that come with not being tied down to a specific wired network connection. It is a beautiful thing. However, if you didn't take the time to implement some basic security...read more

 
What Does That Mean?
If you're not a computer, networking, or security guru, you might find a number of terms and acronyms perplexing. Just trying to read basic information you might come across TCP/IP, DNS, DHCP, IDS, ISP, P2P, IM, etc., etc.. The world of computer technology is second only to the government / military when it comes to creating confusing terms and meaningless...read more

 
 
Sponsored Links
 
Give Your Home a Makeover
Give Your Home a Makeover
Spring has always been a time for new beginnings, and what better way to start fresh than to give your home a new look? Whether you're hoping to just get your house in order or take on a full home renovation, we have the tips for tackling those do-it-yourself projects. See the full Home Makeover Madness special section.

Advertisement
 
 
Visit Related About GuideSites:
Wireless / Networking Antivirus Software Focus on Windows
Email internet  
Search About  

 
More Newsletters: To sign up for more free newsletters on What You Need to Know About your favorite topics, visit: http://talk.about.com

You are receiving this newsletter because you subscribed to the About Net Security newsletter as security.world@GMAIL.COM. If you wish to change or remove your email address, please visit:
http://about.com/nl/usgs.htm?nl=netsecurity&e=security.world@GMAIL.COM

About respects your privacy. Our Privacy Policy.

Our Contact Information.
249 West 17th Street
New York, NY, 10011

© 2007 About, Inc.

firewall-wizards Digest, Vol 13, Issue 2

Send firewall-wizards mailing list submissions to
firewall-wizards@listserv.icsalabs.com

To subscribe or unsubscribe via the World Wide Web, visit
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
or, via email, send a message with subject or body 'help' to
firewall-wizards-request@listserv.icsalabs.com

You can reach the person managing the list at
firewall-wizards-owner@listserv.icsalabs.com

When replying, please edit your Subject line so it is more specific
than "Re: Contents of firewall-wizards digest..."


Today's Topics:

1. Re: Cisco ASA and FWSM (Timo Schoeler)
2. Re: ASA 5510 problem (Skough Axel U/IT-S)
3. Re: ASA 5510 problem (Chris Wargaski)


----------------------------------------------------------------------

Message: 1
Date: Mon, 30 Apr 2007 15:34:51 +0200
From: Timo Schoeler <timo.schoeler@riscworks.net>
Subject: Re: [fw-wiz] Cisco ASA and FWSM
To: Firewall Wizards Security Mailing List
<firewall-wizards@listserv.icsalabs.com>
Cc: drsharp@pacbell.net
Message-ID: <20070430153451.24c27006.timo.schoeler@riscworks.net>
Content-Type: text/plain; charset="us-ascii"

On Sat, 28 Apr 2007 14:23:43 -0700
D Sharp <drsharp@pacbell.net> wrote:

> Hi;
>
> We have a Internet Portal inplace for some 2+ years based on a
> redundant set of 6500 switches with sup720s, IDS-SM, NAM, FWSM,
> switch blades. We also use the FWSM to create isolated non-production
> developement/test/QA areas. We also have PIX and ASA firewalls.
>
> Would we use FWSM again, not likely. We spent a great deal of time
> finding a stable version of software for both SUP720 and FWSM. The
> problems we have experienced may no longer exist in current code
> releases.
>
> But the FWSM is very compelling, yet it has to meet your
> requirements. You asked for a comparision, and as others have
> responded with some points. These are more on the design.
>
> Chassis versus standalone:
> FWSM 'interface' is a set of virtual gigabit intfs. bound into a
> single GEC (gigabit ether channel). Packets are 'load balanced' over
> these. You work with vlans, not interfaces.
> ASA top model supports (8) gig interfaces, but ether channel
> still does not appear to be supported. Not a big deal as the top ASA
> only supports up to 1.2gbs throughput.

yeah, and for the ASA-5520 (e.g.) they share one single interrupt.
worst hardware design ever.

> FWSM uses the shared bus of the chassis, not the switched bus.
> Thus the SUP32 and SUP720 modules are supported.
> Or less desireable, as your switched bus cards still have to send
> traffic over the shared bus for the FWSM.
> With externally connected firewalls, you save a chassis slot for
> another (48) port switch card, or some other special purpose module.
>
> There is another interesting design "feature" of the FWSM, it
> uses ONE MAC address per module. Thus all interfaces, layer 3, across
> all virtual firewalls share this MAC. This precludes some designs
> that would share a vlan.
>
> Capabilities, there are dozens of comparison points, my top 5 are:
> FWSM vs ASA5500
> 1: FWSM 5gbs over ASA 1.2gbs
> 2: flexible vlans, FWSM over ASA.
> 3: FWSM support for more ACLs, vlans, connections over ASA.
> 4: ASA for VPNs, not possible with FWSM.
> 5: ASA uses (8) network ports versus the FWSM usage of a slot.
>
> Hope this helps.
>
> Yours,
> Duncan Sharp
>
> Security Guy wrote:
>
> >As Avishai said, the FWSM is just a firewall, no VPN or IDS support
> >at all (those are different modules ;)
> >
> >If you can do without the features, you still have to consider cost:
> >the last time I looked at FWSMs they were in the 20k USD range..
> >
> >The main thing you get with FWSM is performance (supposedly about
> >6gb/s limited by the 6-gb etherchannel it takes from the backplane)
> >tied directly to your core switch/router, if that's what you're
> >looking for.
> >
> >
> >On 4/12/07, Kimberly Fields <kimberlymfields@gmail.com> wrote:
> >
> >
> >>Can anyone tell me what, if any, are the differences between the
> >>Cisco ASA firewall features and the Cisco FWSM firewall features?
> >>
> >>_______________________________________________
> >>firewall-wizards mailing list
> >>firewall-wizards@listserv.icsalabs.com
> >>https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
> >>
> >>
> >>
> >>
> >
> >
> >
> >
>
> _______________________________________________
> firewall-wizards mailing list
> firewall-wizards@listserv.icsalabs.com
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 187 bytes
Desc: not available
Url : https://listserv.icsalabs.com/pipermail/firewall-wizards/attachments/20070430/9493f4e1/attachment-0001.pgp


------------------------------

Message: 2
Date: Wed, 2 May 2007 21:58:01 +0200
From: "Skough Axel U/IT-S" <axel.skough@scb.se>
Subject: Re: [fw-wiz] ASA 5510 problem
To: "Firewall Wizards Security Mailing List"
<firewall-wizards@listserv.icsalabs.com>
Message-ID: <7D5607434F895540B2A717820399633D14B090@exs13.scb.intra>
Content-Type: text/plain; charset="iso-8859-1"

Hi,

Have you specified the VPN Pool range properly? It should be for example 10.10.10.0/24.

/ Axel

________________________________

From: firewall-wizards-bounces@listserv.icsalabs.com on behalf of Dehnert James Sr
Sent: Tue 2007-05-01 02:04
To: firewall-wizards@listserv.icsalabs.com
Subject: [fw-wiz] ASA 5510 problem

I have a Cisco ASA 5510 with an External, Internal, and DMZ
interfaces. I have a mail server in the DMZ and I have configured
the ASA so that I can get to it internally an externally, however,
when I log in using the IPSEC VPN I cannot connect.

The internal address range is 192.168.100.0/24
The dmz address range is 192.168.200.0/24
The VPM pool range is 10.10.10.10/24

I have mappings internally to so that any 192.168.100 host can
connect to the mail server at 192.168.200.25, but the VPN access
issue has me flummoxed.

Cisco has examples of VPN or DMZ, bit nothing with info on both.

Any pointers would be greatly appreciated.

Thanks,
Zeke

--
James "Zeke" Dehnert
mailto:jdehnert@norcalnetworks.com
Phone: +1 707.546.6620 x602 Fax: +1 707.324.8043
"Life is racing, everything else is just waiting"


_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/ms-tnef
Size: 4362 bytes
Desc: not available
Url : https://listserv.icsalabs.com/pipermail/firewall-wizards/attachments/20070502/f6d27ba7/attachment-0001.bin


------------------------------

Message: 3
Date: Thu, 3 May 2007 01:00:10 -0500
From: "Chris Wargaski" <cwargaski@rmstsi.com>
Subject: Re: [fw-wiz] ASA 5510 problem
To: "Firewall Wizards Security Mailing List"
<firewall-wizards@listserv.icsalabs.com>
Message-ID: <F7B8D9BB39700E48AAFAAC978C7ABB731DBD24@cliff.rmsbg.com>
Content-Type: text/plain; charset="iso-8859-1"

Zeke--

Are you able to access anything when you establish the VPN tunnel? How are you trying to access? (ping, email client?) Also, when you connect, is your connecting workstation directly connected to a public network, or are you behind a device performing NAT (like a home firewall)?

Can you post snippets of the configuration? (group-policy block, and any line beginning with the word crypto).

cjw

Christopher J. Wargaski
RMS Technology Solutions, Inc.
cwargaski@rmstsi.com
(847) 215-1661 x223

-----Original Message-----
From: firewall-wizards-bounces@listserv.icsalabs.com on behalf of Dehnert James Sr
Sent: Mon 4/30/2007 7:04 PM
To: firewall-wizards@listserv.icsalabs.com
Subject: [fw-wiz] ASA 5510 problem

I have a Cisco ASA 5510 with an External, Internal, and DMZ
interfaces. I have a mail server in the DMZ and I have configured
the ASA so that I can get to it internally an externally, however,
when I log in using the IPSEC VPN I cannot connect.

The internal address range is 192.168.100.0/24
The dmz address range is 192.168.200.0/24
The VPM pool range is 10.10.10.10/24

I have mappings internally to so that any 192.168.100 host can
connect to the mail server at 192.168.200.25, but the VPN access
issue has me flummoxed.

Cisco has examples of VPN or DMZ, bit nothing with info on both.

Any pointers would be greatly appreciated.

Thanks,
Zeke

--
James "Zeke" Dehnert
mailto:jdehnert@norcalnetworks.com
Phone: +1 707.546.6620 x602 Fax: +1 707.324.8043
"Life is racing, everything else is just waiting"


_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/ms-tnef
Size: 3598 bytes
Desc: not available
Url : https://listserv.icsalabs.com/pipermail/firewall-wizards/attachments/20070503/b5f71d4c/attachment-0001.bin


------------------------------

_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


End of firewall-wizards Digest, Vol 13, Issue 2
***********************************************

The Virtual Reality Check

Virtualization offers us a vision of more efficient, better
consolidated IT infrastructures built on standardized parts
that can be manipulated, moved, and redeployed in an
instant. Companies are virtualizing at the OS and server
levels in droves. So why does your IT staff continue to
spend 60% of its time fixing problems? Because your
applications have been left behind!

You are invited to attend a Webcast that will discuss
application virtualization and how it can be used with
other virtualization technologies to complete the
vision of true, total enterprise efficiency.

The Virtual Reality Check
Tuesday, May 8th
10:00 AM PT / 1:00 PM ET

Click on the following link to attend this Webcast, brought
to you by Trigence and InfoWorld:
http://ifw-media.com/lrd0_AAcGRgAAcK4B

Applications are the last holdouts in the unvirtualized
world because they are, by nature, anything but standard. They
start adapting to their environments the second they are
installed and, once planted, nearly impossible to uproot
without change or damage.

Discover how applications can be turned into standardized
parts, even as custom settings and unique characteristics
are preserved.

Join us for an insightful discussion on this topic. Register
now to attend this Webcast:

http://ifw-media.com/lrd1_AAcGRgAAcK4B

*****************************************************************
When you applied for, or renewed your subscription, registered
at InfoWorld.com, subscribed to one of our email newsletters,
or registered for one of our events, you indicated that you would
like to receive e-mail about InfoWorld Products and Services.

To unsubscribe, click:

http://ifw-media.com/unsubscribe/u.html?u=AAcGRgAAcK4B

To view InfoWorld's Privacy Policy, click:

http://ifw-media.com/lrd2_AAcGRgAAcK4B

InfoWorld Media Group Circulation Dept.
501 Second St, San Francisco, CA, 94107-1496
InfoWorld Customer Service
PO Box 3511, Northbrook, IL 60065-3511

The color of information security; Microsoft pencils in seven bug fixes

Network World

Security News Alert




Network World's Security News Alert, 05/04/07

The color of information security, 05/01/07:  If information security were a color, it most definitely would be gray. Like life in general, information security is rarely black and white. Click here for more.

Microsoft pencils in seven bug fixes for next week, 05/03/07: Microsoft will issue seven security updates next week for Windows, Office, Exchange and BizTalk, the company announced Thursday. Click here for more.

Microsoft weaving security, management into single platform, 05/03/07:  Evident of a larger industry trend, Microsoft on Wednesday began to lay out a strategy to integrate security and management tools into its Forefront and System Center brands of products. Click here for more.

From servers to storage: Virtualization saves

It's touted as one of the fastest and easiest ways to better manage and control your infrastructure. Download this guide today and see how network IT execs are making virtualization pay off in the real world; discover the 8 virtualization gotchas you need to know; and much more.
Click here to download.

SonicWall bundles security services with firewall/VPN gear, 05/03/07:  SonicWall is wrapping a reduced-price package of security services around some of its branch-office firewall/VPN hardware to provide what it calls unified threat management (UTM) for offices where such features formerly might have been too expensive. Click here for more.

New bug-a-day project targets Microsoft's ActiveX, 05/02/07:  Another bug-a-day campaign surfaced Tuesday as the "Month of ActiveX Bugs" debuted. Although some researchers have already dismissed the project as copycat, others are warning its findings might put Windows users at risk of attack. Click here for more.

Entrust unveils online anti-fraud service, 05/02/07:  Entrust Wednesday announced an online anti-fraud service that can be a source for information research as well as provide Entrust’s fraud-protection and third-party risk-assessment services. Click here for more.

Montage update fixes bugs, 05/02/07:  Mariner Software on Wednesday released Montage 1.2.2, a free update to their screenwriting software for Mac OS X. Montage costs $139.99. Click here for more.

From John Obeto on Microsoft Blog:  Microsoft security - no longer an oxymoron:
Yesterday, I was at the Microsoft Forefront and System Center launch event in Beverly Hills, Calif., where Microsoft demoed both products to an impressed audience ... Click here for more.

From Cisco Press Author Expert Blog: Jeff Doyle:  Managing your network's biggest risk:
The greatest risk to your network is the human being legitimately logged in to a router or server, making authorized changes. Now and then, I get someone who disagrees and a little questioning usually reveals one of two circumstances ... Click here for more.

TODAY'S MOST-READ STORIES:

1. Homeless man disrupts Internet2 service
2. Top 15 all-time 'network-iest' TV characters
3. Google home page bug strikes again
4. Top 15 controversial Miscrosoft quotes
5. The 50 best consumer tech products ever
6. Is MPLS alternative DOA?
7. Slideshow: Cisco's New Catalyst 6500 blade
8. Google urges shareholders to permit censorship
9. Vonage files to vacate patent ruling
10. 'Evil twin' Wi-Fi access points proliferate

MOST DOWNLOADED PODCAST:
Don't take DNS for granted


Contact the author:

Senior Editor Ellen Messmer covers security for Network World. E-mail Ellen.



BONUS FEATURE

IT PRODUCT RESEARCH AT YOUR FINGERTIPS

Get detailed information on thousands of products, conduct side-by-side comparisons and read product test and review results with Network World’s IT Buyer’s Guides. Find the best solution faster than ever with over 100 distinct categories across the security, storage, management, wireless, infrastructure and convergence markets. Click here for details.


PRINT SUBSCRIPTIONS AVAILABLE
You've got the technology snapshot of your choice delivered to your inbox each day. Extend your knowledge with a print subscription to the Network World newsweekly, Apply here today.

International subscribers, click here.


SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World newsletter, change your e-mail address or contact us, click here.

This message was sent to: security.world@gmail.com. Please use this address when modifying your subscription.


Advertising information: Write to Associate Publisher Online Susan Cardoza

Network World, Inc., 118 Turnpike Road, Southborough, MA 01772

Copyright Network World, Inc., 2007

The rise of Alfresco

LinuxWorld

Linux & Open Source News Alert




LinuxWorld's Linux and Open Source News Alert, 05/04/07

LinuxWorld.com Feature Story

The rise of Alfresco: ECM that people will really use - LinuxWorld, 04/27/07
Alfresco is an enterprise content management system that, according to some users, is beating legacy content management systems in speed, quality and ease of use.

More of this week's Linux news

From servers to storage: Virtualization saves

It's touted as one of the fastest and easiest ways to better manage and control your infrastructure. Download this guide today and see how network IT execs are making virtualization pay off in the real world; discover the 8 virtualization gotchas you need to know; and much more.
Click here to download.

New Linux kernel version pumps up virtualization - LinuxWorld, 05/02/07
Linus Torvalds signed off on the latest Linux kernel version last week - 2.6.21 - with several virtualization- and networking-focused improvements in the mix.

Proposed Microsoft, IBM identity protocol standard spawns controversy - LinuxWorld, 05/02/07
A protocol developed by IBM and Microsoft for standardizing the sharing of user identities between companies was turned over to a standards body on Wednesday amid controversy that it overlaps with similar protocols already recognized as standards.

Sun's Rock rolls further along - LinuxWorld, 05/02/07
Sun is reporting another step in the development of its 16-core Rock microprocessor after successfully booting up its own Solaris 10 operating system on a computer with Rock installed.

Dell to offer preinstalled Ubuntu on laptops, desktops - LinuxWorld, 05/01/07
In a response to user comments on a new Dell discussion site, the company is announcing today that it will offer some desktop and laptop models preloaded with the Ubuntu Linux distribution, and seek certification for those models from Canonical Ltd.

Kernel space: Chunkfs and reiser4 - LinuxWorld, 05/01/07
As disks continue to get bigger faster than data transfer rates improve, we will need better filesystem software to prevent an fsck crisis.

School system taps Novell to control network identity - LinuxWorld, 05/01/07
The Fairfax County School District in Virginia, with more than 200 schools and 164,000 students, this week announced it will begin upgrading its legacy network provisioning and password management system with Novell’s Identity Manager.

Search Wikia hires Jabber founder, expands concept - LinuxWorld, 05/01/07
Jabber creator Jeremie Miller is joining Jimmy Wales, the founder of Wikipedia and Wikia, in building an open source, community-driven search service.

Oracle’s Linux initiative continues to build momentum against Red Hat - LinuxWorld, 04/30/07
Oracle continued its enterprise Linux power play last week, this time bringing a host of big-name enterprise IT partners into the fold of its Unbreakable Linux and Oracle Enterprise Linux efforts, and possibly marginalizing Red Hat.

Spring Java framework gets a Java 6 upgrade - LinuxWorld, 04/30/07
Improvements to the open-source Spring Java framework and a companion Web technology focus on annotations, scripting, and Java (Java Platform Standard Edition) 6, developers of the framework said. The upgrades are being unveiled on Monday.

LinuxWorld Community

Three problems (or opportunities) in Linux
Linux developer Andrew Morton, best known for maintaining the "-mm" test kernels, pointed out three deficiencies in Linux: storage, power management, and instrumentation.


Contact the author:

Don Marti is editor of LinuxWorld.com.

Phil Hochmuth writes Network World's Linux Newsletter.



BONUS FEATURE

IT PRODUCT RESEARCH AT YOUR FINGERTIPS

Get detailed information on thousands of products, conduct side-by-side comparisons and read product test and review results with Network World’s IT Buyer’s Guides. Find the best solution faster than ever with over 100 distinct categories across the security, storage, management, wireless, infrastructure and convergence markets. Click here for details.


PRINT SUBSCRIPTIONS AVAILABLE
You've got the technology snapshot of your choice delivered to your inbox each day. Extend your knowledge with a print subscription to the Network World newsweekly, Apply here today.

International subscribers, click here.


SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World newsletter, change your e-mail address or contact us, click here.

This message was sent to: security.world@gmail.com. Please use this address when modifying your subscription.


Advertising information: Write to Associate Publisher Online Susan Cardoza

Network World, Inc., 118 Turnpike Road, Southborough, MA 01772

Copyright Network World, Inc., 2007

Spammers use new technique to evade filters; E-mail harvesters hit with antispam lawsuit

Network World

Antispam News Alert




Network World's Anti-spam News Alert, 05/04/07

Spammers use new technique to evade filters, 05/03/07:  Spammers have stepped up efforts to use encrypted attachments to evade filtering systems, service provider Email Systems has reported.

Proofpoint releases dynamic reputation service, 05/03/07:  Proofpoint this week announced an e-mail reputation service for its security software and appliances that drops connections from known spammers and other questionable senders, cutting down on unwanted messages while saving valuable resources on a corporation’s network.

E-mail harvesters hit with $1 billion antispam lawsuit, 04/26/07:  A $1 billion lawsuit filed Thursday promises to open up a new front in the battle against spam: It targets not just spammers, but -- for the first time -- also those responsible for harvesting e-mail addresses on behalf of spammers.

VoIP: Lessons from Early Adopters

Experts say VoIP isn't a magic wand that will solve all of an organization's communications challenges right out of the box. Learn why VoIP may not produce expected savings and productivity gains, and other lessons from early adopters.

Click Here to Watch

Podcast: Striking a Microsoft nerve, 05/04/07:  Jason and Keith share listener reaction to Keith's "I am never buying another Microsoft operating system" rant hits a chord with listeners, why spam won't go away, whether IT managers should be fired if their company has a major security breach, and guess how much money Spider-Man 3 will make this weekend. (39:09)

TODAY'S MOST-READ STORIES:

1. Homeless man disrupts Internet2 service
2. Top 15 all-time 'network-iest' TV characters
3. Google home page bug strikes again
4. Top 15 controversial Miscrosoft quotes
5. The 50 best consumer tech products ever
6. Is MPLS alternative DOA?
7. Slideshow: Cisco's New Catalyst 6500 blade
8. Google urges shareholders to permit censorship
9. Vonage files to vacate patent ruling
10. 'Evil twin' Wi-Fi access points proliferate

MOST DOWNLOADED PODCAST:
Don't take DNS for granted


Contact the author:

Contact Site Editor Jeff Caruso



BONUS FEATURE

IT PRODUCT RESEARCH AT YOUR FINGERTIPS

Get detailed information on thousands of products, conduct side-by-side comparisons and read product test and review results with Network World’s IT Buyer’s Guides. Find the best solution faster than ever with over 100 distinct categories across the security, storage, management, wireless, infrastructure and convergence markets. Click here for details.


PRINT SUBSCRIPTIONS AVAILABLE
You've got the technology snapshot of your choice delivered to your inbox each day. Extend your knowledge with a print subscription to the Network World newsweekly, Apply here today.

International subscribers, click here.


SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World newsletter, change your e-mail address or contact us, click here.

This message was sent to: security.world@gmail.com. Please use this address when modifying your subscription.


Advertising information: Write to Associate Publisher Online Susan Cardoza

Network World, Inc., 118 Turnpike Road, Southborough, MA 01772

Copyright Network World, Inc., 2007

Microsoft reportedly intensifies interest in Yahoo

Network World

Special News Alert



NETWORK WORLD SPECIAL NEWS ALERT, 05/04/07

Microsoft reportedly intensifies interest in Yahoo

Having lost to Google in a bid for Internet advertising company DoubleClick, Microsoft has initiated a new round of talks with Yahoo, The New York Post reported Friday, citing sources familiar with the talks.

The Wall Street Journal also reported the talks.

For more on this developing story, please click here.


TODAY'S MOST-READ STORIES:

1. Homeless man disrupts Internet2 service
2. Top 15 all-time 'network-iest' TV characters
3. Google home page bug strikes again
4. Top 15 controversial Miscrosoft quotes
5. The 50 best consumer tech products ever
6. Is MPLS alternative DOA?
7. Slideshow: Cisco's New Catalyst 6500 blade
8. Google urges shareholders to permit censorship
9. Vonage files to vacate patent ruling
10. 'Evil twin' Wi-Fi access points proliferate

MOST DOWNLOADED PODCAST:
Don't take DNS for granted


Contact the author:

Contact Site Editor Jeff Caruso



BONUS FEATURE

IT PRODUCT RESEARCH AT YOUR FINGERTIPS

Get detailed information on thousands of products, conduct side-by-side comparisons and read product test and review results with Network World’s IT Buyer’s Guides. Find the best solution faster than ever with over 100 distinct categories across the security, storage, management, wireless, infrastructure and convergence markets. Click here for details.


PRINT SUBSCRIPTIONS AVAILABLE
You've got the technology snapshot of your choice delivered to your inbox each day. Extend your knowledge with a print subscription to the Network World newsweekly, Apply here today.

International subscribers, click here.


SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World newsletter, change your e-mail address or contact us, click here.

This message was sent to: security.world@gmail.com. Please use this address when modifying your subscription.


Advertising information: Write to Associate Publisher Online Susan Cardoza

Network World, Inc., 118 Turnpike Road, Southborough, MA 01772

Copyright Network World, Inc., 2007

Identity protocol standard spawns controversy; First WiMAX laptop card approved by FCC

Network World

Standards and Regulatory Compliance News Alert




Network World's Standards and Regulations News Alert, 05/04/07

Proposed Microsoft, IBM identity protocol standard spawns controversy,05/02/07: A protocol developed by IBM and Microsoft for standardizing the sharing of user identities between companies was turned over to a standards body on Wednesday amid controversy that it overlaps with similar protocols already recognized as standards.

Meru unveils enterprise 802.11n WLAN gear, 04/30/07: The first enterprise-class wireless LAN products supporting the IEEE 802.11n draft standard, and promising data rates of 300Mbps, have been announced this week by Meru Networks.

First WiMAX laptop card approved by FCC, Clearwire says, 05/01/07: Regulators have approved the first WiMAX wireless broadband laptop PC card to be offered by Clearwire, and it should be available to users later this year, the company said Tuesday.

The IDC Enterprise Panel:

Join IDC's panel of IT influencers and decision-makers. Your contributions will be compiled and distributed to technology and telecommunications vendors all over the world. As a thank you for joining, you will receive select free IDC research, and discounted IDC conference passes. Learn more at the following:

Steak n Shake beefs up security, 04/30/07: Credit card security may not exactly be a top-of-mind item for customers dining on steakburgers and milkshakes at any of the 450-odd Steak n Shake restaurants scattered around the Midwest and Southeast.

TODAY'S MOST-READ STORIES:

1. Homeless man disrupts Internet2 service
2. Top 15 all-time 'network-iest' TV characters
3. Google home page bug strikes again
4. Top 15 controversial Miscrosoft quotes
5. The 50 best consumer tech products ever
6. Is MPLS alternative DOA?
7. Slideshow: Cisco's New Catalyst 6500 blade
8. Google urges shareholders to permit censorship
9. Vonage files to vacate patent ruling
10. 'Evil twin' Wi-Fi access points proliferate

MOST DOWNLOADED PODCAST:
Don't take DNS for granted


Contact the author:

Contact Site Editor Jeff Caruso



BONUS FEATURE

IT PRODUCT RESEARCH AT YOUR FINGERTIPS

Get detailed information on thousands of products, conduct side-by-side comparisons and read product test and review results with Network World’s IT Buyer’s Guides. Find the best solution faster than ever with over 100 distinct categories across the security, storage, management, wireless, infrastructure and convergence markets. Click here for details.


PRINT SUBSCRIPTIONS AVAILABLE
You've got the technology snapshot of your choice delivered to your inbox each day. Extend your knowledge with a print subscription to the Network World newsweekly, Apply here today.

International subscribers, click here.


SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World newsletter, change your e-mail address or contact us, click here.

This message was sent to: security.world@gmail.com. Please use this address when modifying your subscription.


Advertising information: Write to Associate Publisher Online Susan Cardoza

Network World, Inc., 118 Turnpike Road, Southborough, MA 01772

Copyright Network World, Inc., 2007

Court rejects Vonage request for retrial; Do we really need a security industry?

Network World

Daily News: AM




Network World Daily News: AM, 05/04/07

Court rejects Vonage request for retrial
A U.S. federal appeals court has rejected Vonage's request that it order a lower court to retry a patent-infringement case against the company, Vonage confirmed Thursday.

SLAs are just 'marketing fodder,' says provider exec
Service-level agreements, as currently defined, are of little use to enterprises, a service provider said at a conference here this week.

Microsoft weaving security, management into single platform
Evident of a larger industry trend, Microsoft on Wednesday began to lay out a strategy to integrate security and management tools into its Forefront and System Center brands of products.

Network World Security Buyer's Guide

Find the right security products for your enterprise - fast. From anti-spam to wireless LAN security, our Buyer's Guides have detailed information on hundreds of products in more than 20 categories. With the side-by-side comparison tool you can evaluate product features to make the best decision for your enterprise.

Click here to go to the Security Buyer's Guide now.

Management heavies get poor grades in Gartner survey
Management software heavyweights BMC, CA, HP and IBM are barely making the grade with their customers, earning C and D averages and driving IT buyers to look elsewhere for their operations management needs, according to a recent Gartner poll.

T-Mobile offering free Windows Mobile upgrade
T-Mobile is reportedly offering T-Mobile Dash customers a free upgrade to Windows Mobile 6.

SaaS adopters in for big challenges
Use of software-as-a-service has more than doubled since the beginning of 2006 and will double again by the end of the decade, creating challenges for customers and vendors as they attempt to integrate hosted offerings with on-premise software, according to research released this week by Saugatuck Technology, a business and market strategy consulting firm focused on emerging IT markets.

Google opens Singapore office, eyes Southeast Asia
Google formally opened an office in Singapore on Thursday, a long anticipated move that signals the company has its eyes on Southeast Asia.

Microsoft buys mobile advertising company ScreenTonic
Microsoft Thursday said it will buy ScreenTonic, a company that specializes in delivering localation-based ads to mobile devices.

Podcast

Striking a Microsoft nerve
Jason and Keith share listener reaction to Keith's "I am never buying another Microsoft operating system" rant hits a chord with listeners, why spam won't go away, whether IT managers should be fired if their company has a major security breach, and guess how much money Spider-Man 3 will make this weekend. (39:09)

Blogs

Buzzblog: "Do we really need a security industry?"
That's the headline atop a Bruce Schneier column on Wired's Web site. It's a trick question, too. Schneier doesn't argue that we don't need a security industry, but does contend we wouldn't if only his "utopian vision" of a larger IT industry dominated by services would become a reality. … Actually, he doesn't even go that far by the end of the column.

Today on Layer 8 where everything we say is at least colorful:
In the pantheon of controversial Microsoft comments CEO Steve Ballmer's quote this week about the Apple iPod: "There's no chance that the iPhone is going to get any significant market share. No chance. It's a $500 subsidized item," ranks right up there. But Between Ballmer and Chairman Bill Gates that comment would be hard pressed to crack the Top 15 all-time most controversial or even colorful things the two of them have uttered in the past oh, 20 years or so. These are my favorite quotes, there are many like them but these are mine...

Buzzblog: Some schools dropping laptop programs
Dropping them like a bad habit, which is exactly what critics say they are: “After seven years, there was literally no evidence it had any impact on student achievement — none,” one school official tells the New York Times.

From John Obeto on Microsoft Blog: Microsoft security - no longer an oxymoron:
Yesterday, I was at the Microsoft Forefront and System Center launch event in Beverly Hills, Calif., where Microsoft demoed both products to an impressed audience ...

From Cisco Press Author Expert Blog: Jeff Doyle: Managing your network's biggest risk
The greatest risk to your network is the human being legitimately logged in to a router or server, making authorized changes. Now and then, I get someone who disagrees and a little questioning usually reveals one of two circumstances ...

TODAY'S MOST-READ STORIES:

1. Homeless man disrupts Internet2 service
2. Top 15 all-time 'network-iest' TV characters
3. Google home page bug strikes again
4. Top 15 controversial Miscrosoft quotes
5. The 50 best consumer tech products ever
6. Is MPLS alternative DOA?
7. Slideshow: Cisco's New Catalyst 6500 blade
8. Google urges shareholders to permit censorship
9. Vonage files to vacate patent ruling
10. 'Evil twin' Wi-Fi access points proliferate

MOST DOWNLOADED PODCAST:
Don't take DNS for granted


Contact the author:

Questions? Feedback? Contact NetworkWorld.com Site Editor Jeff Caruso.



BONUS FEATURE

IT PRODUCT RESEARCH AT YOUR FINGERTIPS

Get detailed information on thousands of products, conduct side-by-side comparisons and read product test and review results with Network World’s IT Buyer’s Guides. Find the best solution faster than ever with over 100 distinct categories across the security, storage, management, wireless, infrastructure and convergence markets. Click here for details.


PRINT SUBSCRIPTIONS AVAILABLE
You've got the technology snapshot of your choice delivered to your inbox each day. Extend your knowledge with a print subscription to the Network World newsweekly, Apply here today.

International subscribers, click here.


SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World newsletter, change your e-mail address or contact us, click here.

This message was sent to: security.world@gmail.com. Please use this address when modifying your subscription.


Advertising information: Write to Associate Publisher Online Susan Cardoza

Network World, Inc., 118 Turnpike Road, Southborough, MA 01772

Copyright Network World, Inc., 2007

<FRIDAY May 4, 2007>

     Each Friday, we present a short list of the hottest whitepapers, webcasts and research available. Information you can use to solve problems that crept up during the week, and to prepare for the challenges you'll face in the days ahead. We also provide links to news stories you might have missed, plus facts, quotes and other forms of brain-candy. (Hint: The fun stuff is near the bottom, so don't forget to scroll.) Have a great weekend!

Arsenal Digital Solutions: Automated Off-Site Data Protection for SMBs
Many of today's users are remote, just like the chances of staying in business without backing them up.

Sunbelt Software: The SMART Way to Secure Messaging for Microsoft Exchange Environments
Because attacking email security with separate solutions is like trying to stay dry in a rainstorm with multiple cocktail umbrellas.

Novell: The Comprehensive Access Manager Solution for Your Enterprise
Progress your success in assessing excess access.

St. Bernard Software: Fighting the Hidden Dangers of Internet Access
Your hacked domain has a pharm, ee-oy-ee-oy-oh.

LinuxWorld Conference & Expo: August 6-9, 2007 - San Francisco, California
Immerse yourself in 100+ technical conference sessions and preview the latest products and services from hundreds of key Linux and open source exhibitors. Register for LinuxWorld today using priority code B0103 to save up to $500 off regular conference rates or receive a complimentary Exhibit Hall Pass.

Search the Premier IT Knowledge Base at IDG Connect
All the whitepapers, webcasts and other research you need to make smart decisions.

Give Your Opinions on IT and Business Issues
Join IDC's Survey Panel to receive complimentary IDC research and discounted conferences passes.

1975 Sony Betamax Promotional Video
Wait--watch one program and save another? Amazing!

On this day in 1910, the Royal Canadian Navy was created. In 1904, the United States began construction on the Panama Canal. In 1675, King Charles II of England ordered the construction of the Royal Greenwich Observatory. In 1626, Dutch explorer Peter Minuit arrived in New Netherland (present day Manhattan Island). And in 1494, Christopher Columbus landed in Jamaica. Happy Birthday Lance Bass (1979), Ana Gasteyer (1967), Randy Travis (1959), Keith Haring (1958) and Pia Zadora (1954). RIP cartoonist Bob Clampett (d. 1984), stooge Moe Howard (1975) and Kent State victims Allison Krause, Jeffrey Miller, Sandra Scheuer and William Schroeder (1970).

"It wasn't raining when Noah built the Ark."
  - Howard Ruff

</FRIDAY>

IDG Connect is a service of IDG Communications, Inc. - the world's leading technology media and event company. IDG Communications' company brands include CIO, CSO, Computerworld, GamePro, InfoWorld, Macworld, Network World, and PC World, as well as technology-related events including LinuxWorld Conference & Expo, Macworld Conference & Expo, and DEMO.

As a customer of one of the IDG Communications brands, you became eligible to receive email from IDG Connect. For more information, read the IDG Privacy Statement.

If you do not wish to receive future communication from IDG Connect, please modify your email preferences here.

IDG Connect 3 Speen Street, Framingham, MA 01701

Thursday, May 03, 2007

RE: Public WiFi Access Authentication

I am not quite sure from your details whether this is for private or for
business use.

Though this may offend some open source purists, for business use you may
also want to look into ready made, supported solutions. They range from
fairly cheap to fairly expensive. The advantage obviously is paid for, fast
support in case revenue gets lost with every minute of downtime.

Some solutions I've had good experience with are

MikroTik RouterOS - you can buy the OS (runs on standard Linux hardware) or
an appliance from them. Quite a large, helpful user base.
Nomadix - mid-range solution, often used in hotels to provide internet
services in the rooms.
BlueSocket - heavy duty, enterprise class appliance. Based on Linux,
administrated through an extensive web interface or via an XML-RPC API.
Their high end boxes support literally thousands of concurrent users.

HTH,

Felix

-----Original Message-----
From: Michelle Konzack [mailto:linux4michelle@freenet.de]
Sent: Wednesday, May 02, 2007 10:19 AM
To: debian-firewall
Subject: Public WiFi Access Authentication

Hello,

I have some 802.11a Access Point (privately) in Strasbourg and want to
open it public. The solutions I have found are not suitable and some
are realy strange.

What I have:

|
|
| 802.11a Auth-Router Main
+---- Access ---- (Etch) ---> Router <----> Internet
Point DHCP

I want, that the Auth-Router block ANY traffic until the $CLIENT which
connect over the Access-Point call ANY http-URL and autentificate.

Then the $CLIENT is allowed to use the connection until the last traffic
was on its MAC/IP for, e.g. 5 minutes, then the $CLIENT is required to
re-authenticate.

Also I need to prohibit that sevewral Clients use my Access-Point as
free bridge for there traffic.

I was searching the Net for a sample config how to do this but failed.

So, I want to install the authentication website directly on the Auth-
Router.

Does anyone has done this before and how must I make the iptables setup
to let this work?

Thanks, Greetings and nice Day
Michelle Konzack
Systemadministrator
Tamay Dogan Network
Debian GNU/Linux Consultant


--
Linux-User #280138 with the Linux Counter, http://counter.li.org/
##################### Debian GNU/Linux Consultant #####################
Michelle Konzack Apt. 917 ICQ #328449886
50, rue de Soultz MSN LinuxMichi
0033/6/61925193 67100 Strasbourg/France IRC #Debian (irc.icq.com)