Search This Blog

Wednesday, August 31, 2005

About Antivirus Software: Trading privacy for protection; NIS review

 
Antivirus Software
 
In the Spotlight | More Topics | Specials at About.com
  from Mary Landesman
After another lengthy bout of testing anti-spyware scanners, I was left with a nagging question. Why do so many of these products - that pledge to protect our privacy - ask us to relinquish so much private information in the process. This week, details on that plus a review of Norton Internet Security 2005 AntiSpyware Edition.
 
 In the Spotlight
Trading privacy for protection
Anti-spyware apps promise to protect us from programs that spy on our surfing habits and ferret out personal details about us. But what private details are we giving up for this protection?

 
          More Topics
Review: Norton Internet Security 2005 AntiSpyware Edition
An all-in-one suite, Norton Internet Security 2005 AntiSpyware Edition offers the generic standard of antivirus, antispam, antispyware, firewall, and privacy controls. But infrequent updates and conflicting alert messages make it difficult to recommend.

 
Zotob, Mytob alleged authors arrested
The FBI has announced the arrests of two alleged authors of some of this year's most prevalent threats.

 
 
Sponsored Links
 
 Featured Offer
 
 Specials at About.com
Win a $5,000 Shopping Spree from About.com!
Register for your chance to win a Visa Gift Card worth $5,000 from About.com. Click here to enter!

Pregnancy Blog
Follow mom-to-be Kimber Jean as she writes "From Waddle to Swaddle," a blog about her pregnancy and eventual transition to becoming a mother. Get involved and leave comments to show your support, lend advice or share whatever else is on your mind. Read more

Leslie Stops Smoking
Join Leslie Bainbridge as she blogs about the ups and downs of kicking the nicotine habit. Get involved and leave comments to show your support, lend advice or share whatever else is on your mind. Read more

 
 
Visit Related About GuideSites:
Internet / Network Security Wireless / Networking Focus on Windows
Email Urban Legends and Folklore  
Search About  

 
More Newsletters: To sign up for more free newsletters on What You Need to Know About your favorite topics, visit: http://talk.about.com

You are receiving this newsletter because you subscribed to the About Antivirus Software newsletter as security.world@GMAIL.COM. If you no longer wish to receive emails from us, please visit:
http://about.com/nl/usgs.htm?nl=antivirus&e=security.world@GMAIL.COM

About respects your privacy. Our Privacy Policy.

Our Contact Information.
249 West 17th Street
New York, NY, 10011

© 2005 About, Inc.

BMC acquires knowledge mgmt. company

All the week's news and views about Network/Systems Management,
08/31/05
_______________________________________________________________
This newsletter is sponsored by HP
FROM THE NETWORK CORE TO THE NETWORK EDGE

Traffic management becomes critical as your network
infrastructure expands to support different types of traffic and
users. Most traffic management solutions have serious
limitations: too expensive, difficult to use, and overly taxing
on bandwidth. However ProCurve Networking by HP addresses these
requirements, overcomes the limitations of other solutions, and
gives you valuable insight into LAN performance.
http://www.fattail.com/redir/redirect.asp?CID=111682
_______________________________________________________________
TROUBLE IN PARADISE?

As technologies such as VoIP emerge to advance networks, many
believe the tools to manage them are falling behind. Traditional
management software models simply can't keep up with the rate of
real-time change that today's applications sustain. Is there a
solution pending or should network managers rely on their own
innovations? Click here:
http://www.fattail.com/redir/redirect.asp?CID=111609
_______________________________________________________________

Network World's Network/Systems Management News Alert

BMC acquires knowledge mgmt. company, 08/30/05

BMC Software Tuesday announced it had acquired a maker of
knowledge management software in a deal that would equip BMC
with service-desk capabilities that it plans to incorporate into
its Remedy and Magic product suites.
<http://www.networkworld.com/news/2005/083005-bmc.html?nl>

Tivoli's take on SOA, 08/29/05

Tivoli, IBM's management software arm, last week said it would
soon offer software that will let customers manage
service-oriented architecture -based applications. Alfred
Zollar, general manager at Tivoli software, sat down at the
Share user ...
<http://www.networkworld.com/news/2005/082905mgmtside.html?nl>

Start-up targets security response, 08/29/05

Start-up Enira Technologies this week plans to roll out software
that lets users respond to security problems by applying filters
or shutting off access to LAN segments to protect desktops and
servers.
<http://www.networkworld.com/news/2005/082905-enira.html?nl>

Weblog: Backup checker, 08/29/05

Okay, here's a mouthful: Microsoft System Center Data Protection
Manager 2006 Management Pack for Microsoft Operations Manager
2005. Data Protection Manager is Microsoft's new backup
software. So here is the translation: The management pack for
DPM ...
<http://www.networkworld.com/weblogs/nos/009858.html?nl>

The top 5: Today's most-read stories

1. 2005 salary survey
<http://www.networkworld.com/nlnetsystemsmgmt3988>

2. Google dives deeper into networking
<http://www.networkworld.com/nlnetsystemsmgmt6276>

3. Cisco aims to simplify switch mgmt.
<http://www.networkworld.com/nlnetsystemsmgmt6277>

4. VoIP season about to heat up
<http://www.networkworld.com/nlnetsystemsmgmt6278>

5. A proposal for governing the 'Net
<http://www.networkworld.com/nlnetsystemsmgmt6279>

Today's most-forwarded story:

VoIP rollouts generate heat, power concerns
<http://www.networkworld.com/nlnetsystemsmgmt6280>

_______________________________________________________________
To contact:

Senior Writer Denise Dubie covers network and systems management
for Network World. Reach her at <mailto:ddubie@nww.com>.
_______________________________________________________________
This newsletter is sponsored by HP
FROM THE NETWORK CORE TO THE NETWORK EDGE

Traffic management becomes critical as your network
infrastructure expands to support different types of traffic and
users. Most traffic management solutions have serious
limitations: too expensive, difficult to use, and overly taxing
on bandwidth. However ProCurve Networking by HP addresses these
requirements, overcomes the limitations of other solutions, and
gives you valuable insight into LAN performance.
http://www.fattail.com/redir/redirect.asp?CID=111681
_______________________________________________________________
ARCHIVE LINKS

Management news page
Latest management news, analysis and newsletters
http://www.networkworld.com/topics/management.html
_______________________________________________________________
Why wireless?

Learn about the key issues surrounding the use of wireless in
the enterprise.
http://www.fattail.com/redir/redirect.asp?CID=111534
_______________________________________________________________
FEATURED READER RESOURCE
VoIP

For the latest in VoIP, check out NW's Research Center on this
very topic. Here you will find a collection of the latest news,
reviews, product testing results and more all related to keeping
VoIP networks performing at their best. Click here for more:
<http://www.networkworld.com/topics/voip.html>
_______________________________________________________________
May We Send You a Free Print Subscription?
You've got the technology snapshot of your choice delivered
at your fingertips each day. Now, extend your knowledge by
receiving 51 FREE issues to our print publication. Apply
today at http://www.subscribenw.com/nl2

International subscribers click here:
http://nww1.com/go/circ_promo.html
_______________________________________________________________
SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World e-mail
newsletters, go to:
<http://www.nwwsubscribe.com/Changes.aspx>

To change your e-mail address, go to:
<http://www.nwwsubscribe.com/ChangeMail.aspx>

Subscription questions? Contact Customer Service by replying to
this message.

This message was sent to: security.world@gmail.com
Please use this address when modifying your subscription.
_______________________________________________________________

Have editorial comments? Write Jeff Caruso, Newsletter Editor,
at: <mailto:jcaruso@nww.com>

Inquiries to: NL Customer Service, Network World, Inc., 118
Turnpike Road, Southborough, MA 01772

For advertising information, write Kevin Normandeau, V.P. of
Online Development, at: <mailto:sponsorships@nwfusion.com>

Copyright Network World, Inc., 2005

Opinion: Gambling forces the question: Who controls the 'Net?

All the week's news about network standards, 08/31/05
_______________________________________________________________
This newsletter is sponsored by HP
FROM THE NETWORK CORE TO THE NETWORK EDGE

Traffic management becomes critical as your network
infrastructure expands to support different types of traffic and
users. Most traffic management solutions have serious
limitations: too expensive, difficult to use, and overly taxing
on bandwidth. However ProCurve Networking by HP addresses these
requirements, overcomes the limitations of other solutions, and
gives you valuable insight into LAN performance.
http://www.fattail.com/redir/redirect.asp?CID=111700
_______________________________________________________________
TROUBLE IN PARADISE?

As technologies such as VoIP emerge to advance networks, many
believe the tools to manage them are falling behind. Traditional
management software models simply can't keep up with the rate of
real-time change that today's applications sustain. Is there a
solution pending or should network managers rely on their own
innovations? Click here:
http://www.fattail.com/redir/redirect.asp?CID=111625
_______________________________________________________________

Network World's Standards and Regulations News Alert

Opinion: Gambling forces the question: Who controls the 'Net?
08/29/05

Antigua and Barbuda, a nation comprising a pair of Caribbean
islands with a combined area about 2.5 times that of Washington,
D.C., and a population of about 68,000, decided a while back to
invest in Internet casinos as a way to augment the tourist ...
<http://www.networkworld.com/nlstandardsandre6268>

Tech Update: Federation gateway bridges identity standards,
08/29/05

In an environment where federated identity management standards
are still evolving, a federation gateway enables companies to
deploy federated identity management with the confidence of
knowing they can seamlessly connect with their business partners
...
<http://www.networkworld.com/nlstandardsandre6269>

Internet trade group calls for self-regulation, 08/25/05

An Internet-focused trade group has called for the industry to
establish its own customer-rights code before Congress steps in.
<http://www.networkworld.com/news/2005/082505-usiia.html?nl>

W3C objects to U.S. Copyright Office's browser plan, 08/24/05

The World Wide Web Consortium is protesting a proposal by the
U.S. Copyright Office that may temporarily require online forms
to be submitted using only Microsoft's Internet Explorer Web
browser or Netscape browsers.
<http://www.networkworld.com/nlstandardsandre6270>

The top 5: Today's most-read stories

1. 2005 salary survey
<http://www.networkworld.com/nlstandardsandre3980>

2. Google dives deeper into networking
<http://www.networkworld.com/nlstandardsandre6271>

3. Cisco aims to simplify switch mgmt.
<http://www.networkworld.com/nlstandardsandre6272>

4. VoIP season about to heat up
<http://www.networkworld.com/nlstandardsandre6273>

5. A proposal for governing the 'Net
<http://www.networkworld.com/nlstandardsandre6274>

Today's most-forwarded story:

VoIP rollouts generate heat, power concerns
<http://www.networkworld.com/nlstandardsandre6275>

_______________________________________________________________
To contact:

Contact Online News Editor Jeff Caruso at
<mailto:jcaruso@nww.com>
_______________________________________________________________
This newsletter is sponsored by HP
FROM THE NETWORK CORE TO THE NETWORK EDGE

Traffic management becomes critical as your network
infrastructure expands to support different types of traffic and
users. Most traffic management solutions have serious
limitations: too expensive, difficult to use, and overly taxing
on bandwidth. However ProCurve Networking by HP addresses these
requirements, overcomes the limitations of other solutions, and
gives you valuable insight into LAN performance.
http://www.fattail.com/redir/redirect.asp?CID=111699
_______________________________________________________________
ARCHIVE LINKS

Standards breaking news:
http://www.networkworld.com/topics/standards.html

Regulatory compliance breaking news:
http://www.networkworld.com/topics/compliance.html
_______________________________________________________________
FEATURED READER RESOURCE
VoIP

For the latest in VoIP, check out NW's Research Center on this
very topic. Here you will find a collection of the latest news,
reviews, product testing results and more all related to keeping
VoIP networks performing at their best. Click here for more:
<http://www.networkworld.com/topics/voip.html>
_______________________________________________________________
May We Send You a Free Print Subscription?
You've got the technology snapshot of your choice delivered
at your fingertips each day. Now, extend your knowledge by
receiving 51 FREE issues to our print publication. Apply
today at http://www.subscribenw.com/nl2

International subscribers click here:
http://nww1.com/go/circ_promo.html
_______________________________________________________________
SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World e-mail
newsletters, go to:
<http://www.nwwsubscribe.com/Changes.aspx>

To change your e-mail address, go to:
<http://www.nwwsubscribe.com/ChangeMail.aspx>

Subscription questions? Contact Customer Service by replying to
this message.

This message was sent to: security.world@gmail.com
Please use this address when modifying your subscription.
_______________________________________________________________

Have editorial comments? Write Jeff Caruso, Newsletter Editor,
at: <mailto:jcaruso@nww.com>

Inquiries to: NL Customer Service, Network World, Inc., 118
Turnpike Road, Southborough, MA 01772

For advertising information, write Kevin Normandeau, V.P. of
Online Development, at: <mailto:sponsorships@nwfusion.com>

Copyright Network World, Inc., 2005

VoIP season about to heat up

All the week's VoIP news and analysis, 08/31/05
_______________________________________________________________
This newsletter is sponsored by HP
FROM THE NETWORK CORE TO THE NETWORK EDGE

Traffic management becomes critical as your network
infrastructure expands to support different types of traffic and
users. Most traffic management solutions have serious
limitations: too expensive, difficult to use, and overly taxing
on bandwidth. However ProCurve Networking by HP addresses these
requirements, overcomes the limitations of other solutions, and
gives you valuable insight into LAN performance.
http://www.fattail.com/redir/redirect.asp?CID=111711
_______________________________________________________________
TROUBLE IN PARADISE?

As technologies such as VoIP emerge to advance networks, many
believe the tools to manage them are falling behind. Traditional
management software models simply can't keep up with the rate of
real-time change that today's applications sustain. Is there a
solution pending or should network managers rely on their own
innovations? Click here:
http://www.fattail.com/redir/redirect.asp?CID=111628
_______________________________________________________________

Network World's VoIP News Alert

VoIP season about to heat up, 08/29/05

September should be a big month for VoIP technology, with
vendors expected to launch a host of offerings at a pair of big
trade shows focused on converged networks.
<http://www.networkworld.com/news/2005/082905-voip.html?nl>

VoIP rollouts generate heat, power concerns, 08/29/05

Things are about to heat up at Charter Steel. We're not talking
smelters here, but network wiring closets. Over the next few
months, the company plans to roll out hundreds of IP phones to
corporate desktops, with Power over Ethernetswitches to run ...
<http://www.networkworld.com/news/2005/082905-poe-heat.html?nl>

Opinion: The fairy tale of 'net neutrality', 08/29/05

Service providers could comply with the letter and the spirit of
any such regulation while simultaneously undermining the VoIP
providers to the benefit of their own services. Their secret
weapon? Benign neglect. Ultimately, to thwart the competition,
...
<http://www.networkworld.com/columnists/2005/082905tolly.html?nl>

Content, control and the 'Net, 08/29/05

How much control can - or should - communications transport
providers exert over the content they carry?
<http://www.networkworld.com/nlvoipalert6252>

Google dives deeper into networking, 08/29/05

No longer content with indexing billions of items on the Web,
Google during the past year or so has been expanding its
offerings into areas such as desktop search, 3-D mapping and
location-aware services.
<http://www.networkworld.com/news/2005/082905-google.html?nl>

FCC delays VoIP emergency dialing requirement, 08/26/05

The FCC has delayed an Aug. 28 deadline for VoIP providers to
warn customers about limitations of enhanced 911 emergency
dialing service, after VoIP carriers complained that tens of
thousands customers could lose service next week.
<http://www.networkworld.com/news/2005/082605-fcc-voip.html?nl>

Intel-Cisco deal may be big for Wi-Fi, 08/26/05

A joint development project announced this week at Fall Intel
Developer Forum by Intel and Cisco could have significant
effects on enterprise wireless LANs.
<http://www.networkworld.com/nlvoipalert6253>

The top 5: Today's most-read stories

1. 2005 salary survey
<http://www.networkworld.com/nlvoipalert3960>

2. Google dives deeper into networking
<http://www.networkworld.com/nlvoipalert6254>

3. Cisco aims to simplify switch mgmt.
<http://www.networkworld.com/nlvoipalert6255>

4. VoIP season about to heat up
<http://www.networkworld.com/nlvoipalert6256>

5. A proposal for governing the 'Net
<http://www.networkworld.com/nlvoipalert6257>

Today's most-forwarded story:

VoIP rollouts generate heat, power concerns
<http://www.networkworld.com/nlvoipalert6258>

_______________________________________________________________
To contact:

Senior Editor Phil Hochmuth covers VoIP for Network World.
Reach him at <mailto:phochmuth@nww.com>.

Senior Editor Tim Greene covers VoIP carrier issues for Network
World.
Reach him at <mailto:tgreene@nww.com>
_______________________________________________________________
This newsletter is sponsored by HP
FROM THE NETWORK CORE TO THE NETWORK EDGE

Traffic management becomes critical as your network
infrastructure expands to support different types of traffic and
users. Most traffic management solutions have serious
limitations: too expensive, difficult to use, and overly taxing
on bandwidth. However ProCurve Networking by HP addresses these
requirements, overcomes the limitations of other solutions, and
gives you valuable insight into LAN performance.
http://www.fattail.com/redir/redirect.asp?CID=111710
_______________________________________________________________
ARCHIVE LINKS

Convergence/VoIP Research Center
http://www.networkworld.com/topics/voip.html
_______________________________________________________________
FEATURED READER RESOURCE
VoIP

For the latest in VoIP, check out NW's Research Center on this
very topic. Here you will find a collection of the latest news,
reviews, product testing results and more all related to keeping
VoIP networks performing at their best. Click here for more:
<http://www.networkworld.com/topics/voip.html>
_______________________________________________________________
May We Send You a Free Print Subscription?
You've got the technology snapshot of your choice delivered
at your fingertips each day. Now, extend your knowledge by
receiving 51 FREE issues to our print publication. Apply
today at http://www.subscribenw.com/nl2

International subscribers click here:
http://nww1.com/go/circ_promo.html
_______________________________________________________________
SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World e-mail
newsletters, go to:
<http://www.nwwsubscribe.com/Changes.aspx>

To change your e-mail address, go to:
<http://www.nwwsubscribe.com/ChangeMail.aspx>

Subscription questions? Contact Customer Service by replying to
this message.

This message was sent to: security.world@gmail.com
Please use this address when modifying your subscription.
_______________________________________________________________

Have editorial comments? Write Jeff Caruso, Newsletter Editor,
at: <mailto:jcaruso@nww.com>

Inquiries to: NL Customer Service, Network World, Inc., 118
Turnpike Road, Southborough, MA 01772

For advertising information, write Kevin Normandeau, V.P. of
Online Development, at: <mailto:sponsorships@nwfusion.com>

Copyright Network World, Inc., 2005

Malware may hide behind long names in Windows registry

All the week's news and views about Security, 08/31/05
_______________________________________________________________
This newsletter is sponsored by HP
FROM THE NETWORK CORE TO THE NETWORK EDGE

Traffic management becomes critical as your network
infrastructure expands to support different types of traffic and
users. Most traffic management solutions have serious
limitations: too expensive, difficult to use, and overly taxing
on bandwidth. However ProCurve Networking by HP addresses these
requirements, overcomes the limitations of other solutions, and
gives you valuable insight into LAN performance.
http://www.fattail.com/redir/redirect.asp?CID=111696
_______________________________________________________________
FREE NETWORK WORLD PRINT SUBSCRIPTIONS - SIGN UP NOW!

Security is one of the most pressing issues in all of IT, and
you need to stay on top of it. Network World delivers the
hottest security news. Network IT Executives depend upon Network
World for the information they need to keep their networks
secure! SUBSCRIBE TODAY AT:
http://www.fattail.com/redir/redirect.asp?CID=111744
_______________________________________________________________

Network World's Security News Alert

Malware may hide behind long names in Windows registry, 08/30/05

Security experts have found a vulnerability in the Windows
operating system that could allow malware to lurk undetected in
long string names of the Windows Registry.
<http://www.networkworld.com/nlsecuritynewsal6219>

Weblog: Communist China spying via the 'Net?, 08/29/05

The Washington Post caused a stir last week with a page 1 story
that officials in the Defense Department, speaking anonymously,
are concerned that network attacks originating in China have
breached "hundreds of unclassified networks" in federal
agencies, without citing which networks those might be.
<http://www.networkworld.com/weblogs/security/009856.html>

'Loverspy' program creator indicted, on the run, 08/29/05

The creator of Loverspy, software to surreptitiously observe
individuals' online activities, has been indicted for allegedly
violating federal computer privacy laws, local and federal
authorities announced Friday.
<http://www.networkworld.com/news/2005/082905-loverspy.html>

DOJ deploys software to track crime data, 08/29/05

The U.S. Department of Justice's Bureau of Justice Statistics
has deployed predictive analysis software from SPSS to analyze
crime data and produce reports on key justice-related issues.
<http://www.networkworld.com/nlsecuritynewsal6220>

The top 5: Today's most-read stories

1. 2005 salary survey
<http://www.networkworld.com/nlsecuritynewsal3996>

2. Google dives deeper into networking
<http://www.networkworld.com/nlsecuritynewsal6221>

3. Cisco aims to simplify switch mgmt.
<http://www.networkworld.com/nlsecuritynewsal6222>

4. VoIP season about to heat up
<http://www.networkworld.com/nlsecuritynewsal6223>

5. A proposal for governing the 'Net
<http://www.networkworld.com/nlsecuritynewsal6224>

Today's most-forwarded story:

VoIP rollouts generate heat, power concerns
<http://www.networkworld.com/nlsecuritynewsal6225>

_______________________________________________________________
To contact:

Senior Editor Ellen Messmer covers security for Network World.
Contact her at <mailto:emessmer@nww.com>.
_______________________________________________________________
This newsletter is sponsored by HP
FROM THE NETWORK CORE TO THE NETWORK EDGE

Traffic management becomes critical as your network
infrastructure expands to support different types of traffic and
users. Most traffic management solutions have serious
limitations: too expensive, difficult to use, and overly taxing
on bandwidth. However ProCurve Networking by HP addresses these
requirements, overcomes the limitations of other solutions, and
gives you valuable insight into LAN performance.
http://www.fattail.com/redir/redirect.asp?CID=111695
_______________________________________________________________
ARCHIVE LINKS

Security research center
Latest security news, analysis, newsletters and resource links.
http://www.networkworld.com/topics/security.html
_______________________________________________________________
FEATURED READER RESOURCE
VoIP

For the latest in VoIP, check out NW's Research Center on this
very topic. Here you will find a collection of the latest news,
reviews, product testing results and more all related to keeping
VoIP networks performing at their best. Click here for more:
<http://www.networkworld.com/topics/voip.html>
_______________________________________________________________
May We Send You a Free Print Subscription?
You've got the technology snapshot of your choice delivered
at your fingertips each day. Now, extend your knowledge by
receiving 51 FREE issues to our print publication. Apply
today at http://www.subscribenw.com/nl2

International subscribers click here:
http://nww1.com/go/circ_promo.html
_______________________________________________________________
SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World e-mail
newsletters, go to:
<http://www.nwwsubscribe.com/Changes.aspx>

To change your e-mail address, go to:
<http://www.nwwsubscribe.com/ChangeMail.aspx>

Subscription questions? Contact Customer Service by replying to
this message.

This message was sent to: security.world@gmail.com
Please use this address when modifying your subscription.
_______________________________________________________________

Have editorial comments? Write Jeff Caruso, Newsletter Editor,
at: <mailto:jcaruso@nww.com>

Inquiries to: NL Customer Service, Network World, Inc., 118
Turnpike Road, Southborough, MA 01772

For advertising information, write Kevin Normandeau, V.P. of
Online Development, at: <mailto:sponsorships@nwfusion.com>

Copyright Network World, Inc., 2005

IBM eyes SOA management

All the week's IBM news and analysis, 08/31/05
_______________________________________________________________
This newsletter is sponsored by HP
FROM THE NETWORK CORE TO THE NETWORK EDGE

Traffic management becomes critical as your network
infrastructure expands to support different types of traffic and
users. Most traffic management solutions have serious
limitations: too expensive, difficult to use, and overly taxing
on bandwidth. However ProCurve Networking by HP addresses these
requirements, overcomes the limitations of other solutions, and
gives you valuable insight into LAN performance.
http://www.fattail.com/redir/redirect.asp?CID=111656
_______________________________________________________________
TROUBLE IN PARADISE?

As technologies such as VoIP emerge to advance networks, many
believe the tools to manage them are falling behind. Traditional
management software models simply can't keep up with the rate of
real-time change that today's applications sustain. Is there a
solution pending or should network managers rely on their own
innovations? Click here:
http://www.fattail.com/redir/redirect.asp?CID=111595
_______________________________________________________________

Network World's IBM News Alert

IBM eyes SOA management, 08/29/05

IBM Tivoli executives last week said the company would by
year-end deliver software to keep tabs on service-oriented
architecture-enabled applications.
<http://www.networkworld.com/news/2005/082905-tivoli-soa.html?nl>

Tivoli's take on SOA, 08/29/05

Tivoli, IBM's management software arm, last week said it would
soon offer software that will let customers manage
service-oriented architecture -based applications. Alfred
Zollar, general manager at Tivoli software, sat down at the
Share user ...
<http://www.networkworld.com/news/2005/082905mgmtside.html?nl>

IBM moves on continuous back-up market, 08/29/05

IBM last week introduced software that continuously backs up the
files on workstations, laptops and file servers throughout the
network.
<http://www.networkworld.com/news/2005/082905-ibm-cdpf.html?nl>

Reconsidering the IBM-Lenovo deal, 08/29/05

I always thought the economics of this sale made sense. Now I've
come around to thinking that freeing PCD from the clutches of
IBM might be good for the PC market, as well as for Lenovo.
<http://www.networkworld.com/nlibmnewsalert6245>

Weblog: The real story behind continuous data protection,
08/29/05

Continuous data protection (CDP) has been getting a lot of play
in the media of late. The Storage Networking Industry
Association recently printed a guide to CDP products, and IBM
last week announced CDP software of its own . There's a lot of
...
<http://www.networkworld.com/weblogs/storage/009850.html?nl>

Weblog: Oracle lone hold out, 08/29/05

If you paid attention to last week's Intel Developer Forum, you
know that dual-core and multi-core chips are the new way of the
world. The question is how does this changing architecture i
mpact your software licensing budgets ? During the past year ...
<http://www.networkworld.com/weblogs/datacenter/009852.html?nl>

IBM rolls out continuous data protection, 08/26/05

IBM Friday introduced software that continuously backs up the
files on workstations, laptops and file servers throughout the
network.
<http://www.networkworld.com/nlibmnewsalert6246>

The top 5: Today's most-read stories

1. 2005 salary survey
<http://www.networkworld.com/nlibmnewsalert3949>

2. Google dives deeper into networking
<http://www.networkworld.com/nlibmnewsalert6247>

3. Cisco aims to simplify switch mgmt.
<http://www.networkworld.com/nlibmnewsalert6248>

4. VoIP season about to heat up
<http://www.networkworld.com/nlibmnewsalert6249>

5. A proposal for governing the 'Net
<http://www.networkworld.com/nlibmnewsalert6250>

Today's most-forwarded story:

VoIP rollouts generate heat, power concerns
<http://www.networkworld.com/nlibmnewsalert6251>

_______________________________________________________________
To contact:

Contact Online News Editor Jeff Caruso at
<mailto:jcaruso@nww.com>.
_______________________________________________________________
This newsletter is sponsored by HP
FROM THE NETWORK CORE TO THE NETWORK EDGE

Traffic management becomes critical as your network
infrastructure expands to support different types of traffic and
users. Most traffic management solutions have serious
limitations: too expensive, difficult to use, and overly taxing
on bandwidth. However ProCurve Networking by HP addresses these
requirements, overcomes the limitations of other solutions, and
gives you valuable insight into LAN performance.
http://www.fattail.com/redir/redirect.asp?CID=111655
_______________________________________________________________
ARCHIVE LINKS

IBM news page
Latest IBM news and analysis.
http://www.networkworld.com/news/financial/ibm.html
_______________________________________________________________
FEATURED READER RESOURCE
VoIP

For the latest in VoIP, check out NW's Research Center on this
very topic. Here you will find a collection of the latest news,
reviews, product testing results and more all related to keeping
VoIP networks performing at their best. Click here for more:
<http://www.networkworld.com/topics/voip.html>
_______________________________________________________________
May We Send You a Free Print Subscription?
You've got the technology snapshot of your choice delivered
at your fingertips each day. Now, extend your knowledge by
receiving 51 FREE issues to our print publication. Apply
today at http://www.subscribenw.com/nl2

International subscribers click here:
http://nww1.com/go/circ_promo.html
_______________________________________________________________
SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World e-mail
newsletters, go to:
<http://www.nwwsubscribe.com/Changes.aspx>

To change your e-mail address, go to:
<http://www.nwwsubscribe.com/ChangeMail.aspx>

Subscription questions? Contact Customer Service by replying to
this message.

This message was sent to: security.world@gmail.com
Please use this address when modifying your subscription.
_______________________________________________________________

Have editorial comments? Write Jeff Caruso, Newsletter Editor,
at: <mailto:jcaruso@nww.com>

Inquiries to: NL Customer Service, Network World, Inc., 118
Turnpike Road, Southborough, MA 01772

For advertising information, write Kevin Normandeau, V.P. of
Online Development, at: <mailto:sponsorships@nwfusion.com>

Copyright Network World, Inc., 2005

It's time for XML (and more!) in your network

All the week's Cisco news and analysis, 08/31/05
_______________________________________________________________
This newsletter is sponsored by HP
FROM THE NETWORK CORE TO THE NETWORK EDGE

Traffic management becomes critical as your network
infrastructure expands to support different types of traffic and
users. Most traffic management solutions have serious
limitations: too expensive, difficult to use, and overly taxing
on bandwidth. However ProCurve Networking by HP addresses these
requirements, overcomes the limitations of other solutions, and
gives you valuable insight into LAN performance.
http://www.fattail.com/redir/redirect.asp?CID=111648
_______________________________________________________________
TROUBLE IN PARADISE?

As technologies such as VoIP emerge to advance networks, many
believe the tools to manage them are falling behind. Traditional
management software models simply can't keep up with the rate of
real-time change that today's applications sustain. Is there a
solution pending or should network managers rely on their own
innovations? Click here:
http://www.fattail.com/redir/redirect.asp?CID=111591
_______________________________________________________________

Network World's Cisco News Alert

Opinion: It's time for XML (and more!) in your network

By Daniel Briere and Patrick Hurley
Network World, 08/30/05

As you have no doubt been hearing (at least in bits and pieces),
there's a big move within the networks of your enterprise
customers towards application -aware switching and networking.
Application switching is not happening as one big
paradigm-shifting overnight revolution, but it is revolutionary,
and it is coming towards as a series of smaller steps forward.

The first place we are seeing application switching enter the
market is in the realm of XML. XML will soon become ubiquitous
in the enterprise for no other reason than the fact that the
next iteration of Microsoft Office will rely upon XML as a file
format - moving away from today's ".ppt" , ".xls" and ".doc"
formats. XML is already increasingly common for other enterprise
applications, and particularly whenever a Web-based application
or Web service touches the enterprise (not to mention the rise
of XML-based syndication feeds for all sorts of new other data
services.

Microsoft is not the only enterprise vendor getting serious
about XML. Intel, for example, just placed a bet on XML and the
importance of XML- and application-awareness when it purchased
XML appliance vendor, Sarvega . All of a sudden the leading
desktop and server vendor - not to mention a primary vendor of
network processors - is bringing XML into its software fold.
Intel has the reach to bring XML-awareness to just about all
levels of the network - just as Centrino has helped spread
802.11, and as Intel's WiMAX efforts are working to boost that
technology.

Full story: <http://www.networkworld.com/nlciscoalert6239>

The top 5: Today's most-read stories

1. 2005 salary survey
<http://www.networkworld.com/nlciscoalert3939>

2. Google dives deeper into networking
<http://www.networkworld.com/nlciscoalert6240>

3. Cisco aims to simplify switch mgmt.
<http://www.networkworld.com/nlciscoalert6241>

4. VoIP season about to heat up
<http://www.networkworld.com/nlciscoalert6242>

5. A proposal for governing the 'Net
<http://www.networkworld.com/nlciscoalert6243>

Today's most-forwarded story:

VoIP rollouts generate heat, power concerns
<http://www.networkworld.com/nlciscoalert6244>

_______________________________________________________________
To contact:

Senior Editor Phil Hochmuth covers Cisco for Network World.
Reach him at <mailto:phochmuth@nww.com>.
_______________________________________________________________
This newsletter is sponsored by HP
FROM THE NETWORK CORE TO THE NETWORK EDGE

Traffic management becomes critical as your network
infrastructure expands to support different types of traffic and
users. Most traffic management solutions have serious
limitations: too expensive, difficult to use, and overly taxing
on bandwidth. However ProCurve Networking by HP addresses these
requirements, overcomes the limitations of other solutions, and
gives you valuable insight into LAN performance.
http://www.fattail.com/redir/redirect.asp?CID=111647
_______________________________________________________________
ARCHIVE LINKS

Cisco news page
Breaking Cisco news, analysis and profile
http://www.networkworld.com/news/financial/cisco.html
_______________________________________________________________
FEATURED READER RESOURCE
VoIP

For the latest in VoIP, check out NW's Research Center on this
very topic. Here you will find a collection of the latest news,
reviews, product testing results and more all related to keeping
VoIP networks performing at their best. Click here for more:
<http://www.networkworld.com/topics/voip.html>
_______________________________________________________________
May We Send You a Free Print Subscription?
You've got the technology snapshot of your choice delivered
at your fingertips each day. Now, extend your knowledge by
receiving 51 FREE issues to our print publication. Apply
today at http://www.subscribenw.com/nl2

International subscribers click here:
http://nww1.com/go/circ_promo.html
_______________________________________________________________
SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World e-mail
newsletters, go to:
<http://www.nwwsubscribe.com/Changes.aspx>

To change your e-mail address, go to:
<http://www.nwwsubscribe.com/ChangeMail.aspx>

Subscription questions? Contact Customer Service by replying to
this message.

This message was sent to: security.world@gmail.com
Please use this address when modifying your subscription.
_______________________________________________________________

Have editorial comments? Write Jeff Caruso, Newsletter Editor,
at: <mailto:jcaruso@nww.com>

Inquiries to: NL Customer Service, Network World, Inc., 118
Turnpike Road, Southborough, MA 01772

For advertising information, write Kevin Normandeau, V.P. of
Online Development, at: <mailto:sponsorships@nwfusion.com>

Copyright Network World, Inc., 2005

firewall-wizards digest, Vol 1 #1655 - 10 msgs

Send firewall-wizards mailing list submissions to
firewall-wizards@honor.icsalabs.com

To subscribe or unsubscribe via the World Wide Web, visit
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
or, via email, send a message with subject or body 'help' to
firewall-wizards-request@honor.icsalabs.com

You can reach the person managing the list at
firewall-wizards-admin@honor.icsalabs.com

When replying, please edit your Subject line so it is more specific
than "Re: Contents of firewall-wizards digest..."

Today's Topics:

1. Re: PIX denying SSH Access - until I run PDM? (Tichomir Kotek)
2. Re: PIX denying SSH Access - until I run PDM? (Greg Padden)
3. RE: Layer 2 firewalls ... (Paul Melson)
4. firewall rule lifecycle management (Michael Cox)
5. RE: firewall rule lifecycle management (Bruce Smith)
6. Re: firewall rule lifecycle management (Skip Carter)
7. Re: firewall rule lifecycle management (Joe Matusiewicz)
8. Re: Layer 2 firewalls ... (Dale W. Carder)
9. Re: firewall rule lifecycle management (Kevin)
10. Re: firewall rule lifecycle management (Christoph Haas)

--__--__--

Message: 1
Date: Tue, 30 Aug 2005 12:48:38 +0200
From: Tichomir Kotek <tichomir.kotek@lynx.sk>
To: firewall-wizards@honor.icsalabs.com
Cc: Paul Pershing <streamfile@gmail.com>
Subject: Re: [fw-wiz] PIX denying SSH Access - until I run PDM?

Paul Pershing wrote:
> Hi,

Hi,

> The odd part is that I discovered through trial and error that if
> access the PIX via PDM after the failed SSH attempt - even if the PDM
> connection is not completed - I can then attach via SSH.

I observerd the same weird behavior. Somehow I figured out that
before connecting with ssh one must generate certificate on pix.
("show ca mypubkey rsa " to verify if you have any)

BUT using pdm pix auto-generates self-signed certificate automagically
(I think even connecting to https generates one) and after that ssh
is working fine.
before using ssh do not forget to "ca generate rsa key 1024"
"ca save all" to save those keys to permanent storage.

> This is such a bizarre problem that I've been reluctant to post it;
> but I've encountered it so many times now that my curiousity has
> gotten the better of me!

hope that helps

tk

--__--__--

Message: 2
Date: Tue, 30 Aug 2005 07:34:21 -0500
From: Greg Padden <paddeng@biostat.wisc.edu>
Reply-To: paddeng@biostat.wisc.edu
To: Paul Melson <pmelson@gmail.com>
Cc: "'Paul Pershing'" <streamfile@gmail.com>,
firewall-wizards@honor.icsalabs.com
Subject: Re: [fw-wiz] PIX denying SSH Access - until I run PDM?

Nope, you need to issue the command (in config mode) ca save all.

If you don't save the CA cert, you get a new one every reboot. And you
don't generate a new CA until you fire up the https interface.

Paul Melson wrote:

>I have a hunch that you may have an 'aaa authentication' rule that's causing
>this problem. Would you be willing to post the output of 'show aaa' from a
>PIX with this affliction? Of course, sanitize it to prevent any unnecessary
>disclosures such as user names or public IP addresses.
>
>PaulM
>
>-----Original Message-----
>Subject: [fw-wiz] PIX denying SSH Access - until I run PDM?
>
>The symptom is that a few weeks will pass since I last logged onto the fw
>using ssh; and I'll attempt to; but instead of being prompted for a
>userid/password the client will simply sit there and stare at me while doing
>nothing - no errors. If I'm using Kermit (usual) it'll just sit on the blank
>black screen until it times out. Other clients produce similar behavior.
>
>The odd part is that I discovered through trial and error that if access the
>PIX via PDM after the failed SSH attempt - even if the PDM connection is not
>completed - I can then attach via SSH.
>
>This is such a bizarre problem that I've been reluctant to post it; but I've
>encountered it so many times now that my curiousity has gotten the better of
>me!
>
>_______________________________________________
>firewall-wizards mailing list
>firewall-wizards@honor.icsalabs.com
>http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
>
>

--__--__--

Message: 3
From: "Paul Melson" <pmelson@gmail.com>
To: "'Andrew K. Adams'" <akadams@psc.edu>,
<firewall-wizards@honor.icsalabs.com>
Subject: RE: [fw-wiz] Layer 2 firewalls ...
Date: Tue, 30 Aug 2005 09:52:36 -0400

If we're talking about the same thing, layer 2 firewalls are just bridges
that inspect packets and act on them, much the same way a typical network
firewall would. You can still perform NAT and its subsets (PAT,
port-forwarding, etc.) with a bridging firewall. (OK, *some* bridging
firewalls perform NAT, others can't and are junk. )

The main drawback that I am aware of is a lack of flexibility in network
architecture surrounding bridges and thus, bridging firewalls. If you want
to use routed networks on both sides of your firewall, it must be in the
physical path between two routers. This can make fail-over and
load-balancing designs more complicated than they otherwise might be if the
firewall were a layer 3 hop that could be inserted into a route.

Anyway, I don't know how much I buy into the advantage of non-addressed
interfaces. If the goal is to keep an attacker from being able to send
packets directly to the firewall interfaces while traffic still passes
across them, you can use ACLs to filter that traffic on a typical firewall.
(Check Point has branded this the "stealth rule." Sounds better than the
"duuhrrr rule.") Also, if there's a bug in your firewall code, that bug can
likely still be exploited by passing that packet across the bridge. I'm
still not sure what I've gained, but now I have a firewall I can't ping. ;)

PaulM

-----Original Message-----
Subject: [fw-wiz] Layer 2 firewalls ...

Is anyone aware of any *disadvantages* of layer 2 firewalls?

Current marketing seems to be pushing layer 2 firewalls mostly, as far as I
can tell, to reduce the possibility of the device being compromised (no ip
address.) And it seems to me, that any network using a media of Ethernet
could (and should?) be doing this, unless of course, they needed the device
to perform layer 3 or 4 utility (e.g., NAT), additionally.

I readily admit that I don't possess "link layer" expertise, and thus, I
suspect that I must be missing something further, if layer 2 firewalls are
indeed a trade-off.

--__--__--

Message: 4
From: Michael Cox <michael@wanderingbark.net>
To: firewall-wizards@honor.icsalabs.com
Date: Tue, 30 Aug 2005 10:25:02 -0500
Subject: [fw-wiz] firewall rule lifecycle management

Hi all.

Question: What do those of you in large environments do to manage your
rulesets in terms of removing access that is no longer required? We get
lots of requests to add access, but are almost never told when
something can be removed. This is a large corporation with lots of
subcontractors, B2B, etc., and we're looking for ideas on how others
get a handle on this (or does anybody?).

Thanks in advance!
Michael

--__--__--

Message: 5
From: "Bruce Smith" <bruce_the_loon@tiscali.co.za>
To: "'Michael Cox'" <michael@wanderingbark.net>,
<firewall-wizards@honor.icsalabs.com>
Subject: RE: [fw-wiz] firewall rule lifecycle management
Date: Tue, 30 Aug 2005 20:09:12 +0200

Hi

From my PIX experience, clear rule counters every month. After a while, look
for the rules that have zero counts and then remove them. Can be scripted
and searched with grep.

Bruce

-----Original Message-----
From: firewall-wizards-admin@honor.icsalabs.com
[mailto:firewall-wizards-admin@honor.icsalabs.com] On Behalf Of Michael Cox
Sent: Tuesday, August 30, 2005 5:25 PM
To: firewall-wizards@honor.icsalabs.com
Subject: [fw-wiz] firewall rule lifecycle management

Hi all.

Question: What do those of you in large environments do to manage your
rulesets in terms of removing access that is no longer required? We get
lots of requests to add access, but are almost never told when
something can be removed. This is a large corporation with lots of
subcontractors, B2B, etc., and we're looking for ideas on how others
get a handle on this (or does anybody?).

Thanks in advance!
Michael
_______________________________________________
firewall-wizards mailing list
firewall-wizards@honor.icsalabs.com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards

--__--__--

Message: 6
To: firewall-wizards@honor.icsalabs.com
Cc: Michael Cox <michael@wanderingbark.net>
Subject: Re: [fw-wiz] firewall rule lifecycle management
Date: Tue, 30 Aug 2005 12:03:37 -0700
From: Skip Carter <skip@taygeta.com>

> Question: What do those of you in large environments do to manage your
> rulesets in terms of removing access that is no longer required? We get
> lots of requests to add access, but are almost never told when
> something can be removed. This is a large corporation with lots of
> subcontractors, B2B, etc., and we're looking for ideas on how others
> get a handle on this (or does anybody?).

We once provided an external firewall audit and in reviewing the special
access rules such as those described above, we noticed that one remote
location that had special access to Victoria's Secret (the client was
NOT any sort of retailer)! It turned out that the IP address once
belonged to a genuine business partner, who later gave up the address
which ultimately ended up in the possession of Victoria's Secret.

They now use a formal written change control procedure to help
manage this problem. We will see how well that works next audit.

Perhaps periodic external review is the best way.

Skip

--
Dr. Everett (Skip) Carter Phone: 831-641-0645 FAX: 831-641-0647
Taygeta Network Security Services email: skip@taygeta.net
1340 Munras Ave., Suite 314 WWW: http://www.taygeta.net/
Monterey, CA. 93940

--__--__--

Message: 7
Date: Tue, 30 Aug 2005 15:08:33 -0400
To: Michael Cox <michael@wanderingbark.net>,
firewall-wizards@honor.icsalabs.com
From: Joe Matusiewicz <joem@nist.gov>
Subject: Re: [fw-wiz] firewall rule lifecycle management

At 11:25 AM 8/30/2005, Michael Cox wrote:
>Hi all.
>
>Question: What do those of you in large environments do to manage your
>rulesets in terms of removing access that is no longer required? We get
>lots of requests to add access, but are almost never told when
>something can be removed. This is a large corporation with lots of
>subcontractors, B2B, etc., and we're looking for ideas on how others
>get a handle on this (or does anybody?).

Once a year we get the diverse groups in a room and review the rules. It's
a long meeting and you will always hear the words "that box doesn't exist
anymore".

-- Joe

--__--__--

Message: 8
Date: Tue, 30 Aug 2005 14:29:14 -0500
From: "Dale W. Carder" <dwcarder@doit.wisc.edu>
To: "Andrew K. Adams" <akadams@psc.edu>
Cc: firewall-wizards@honor.icsalabs.com
Subject: Re: [fw-wiz] Layer 2 firewalls ...

I doubt that there's much gained from the marketing material,
but some pluses for layer-2 firewalls include not having to
renumber end stations during integration and the ability to
pass through non-ipv4 or non-unicast traffic easily.

The downsides are that you better know your layer 2. Not everyone
thinks about layer 2 because it usually just "works". You need
to be careful about vlans, stp roots, bpdu's and other fun stuff
when layer2 firewalls bridge lans.

Dale

----------------------------------
Dale W. Carder - Network Engineer
University of Wisconsin at Madison
http://net.doit.wisc.edu/~dwcarder

--__--__--

Message: 9
Date: Tue, 30 Aug 2005 23:44:04 -0500
From: Kevin <kkadow@gmail.com>
To: firewall-wizards@honor.icsalabs.com
Subject: Re: [fw-wiz] firewall rule lifecycle management
Cc: Michael Cox <michael@wanderingbark.net>

On 8/30/05, Michael Cox <michael@wanderingbark.net> wrote:
> Question: What do those of you in large environments do to manage your
> rulesets in terms of removing access that is no longer required?

This can be a real problem, especially for services which are only
used for quarterly or biannual reports, if that often.

We're just now migrating a number of B2B rules to new firewalls,
and in this process we're discovering that fully half of the current
rules are no longer used; in many cases the source or destination
IP address no longer exists, often the employee listed as the
contact on the original request is no longer with the company.

Last week I was trying to track down a port and determined that the
vendor offering the B2B service had been bought out, no longer
exists under the original name. But the service is still running,
I wonder if they know? (legacy firewall policies cut both ways!)

> We get lots of requests to add access, but are almost never told when
> something can be removed. This is a large corporation with lots of
> subcontractors, B2B, etc., and we're looking for ideas on how others
> get a handle on this (or does anybody?).

Our Sidewinder G2 firewalls offers fields for an end time and date
under the "authentication" settings for each rule, and we are starting
to request a termination date for all "short term" requests and
entering this into the firewall. The vendor also offers an add-on
reporting tool which can provide rule-based reports showing
unused rules in the active firewall policy. I haven't tried this yet,
as the "Security Reporter" only runs on Windows.

It should be interesting to see what happens six months down the road,
when these rules start to expire...

Kevin Kadow
--
Moderator, Unofficial Sidewinder Firewall Users group:
http://groups.yahoo.com/group/sidewinder-users/

--__--__--

Message: 10
Date: Wed, 31 Aug 2005 14:29:54 +0200
From: Christoph Haas <email@christoph-haas.de>
To: firewall-wizards@honor.icsalabs.com
Subject: Re: [fw-wiz] firewall rule lifecycle management

Hi, Michael...

On Tue, Aug 30, 2005 at 10:25:02AM -0500, Michael Cox wrote:
> Question: What do those of you in large environments do to manage your
> rulesets in terms of removing access that is no longer required? We get
> lots of requests to add access, but are almost never told when
> something can be removed. This is a large corporation with lots of
> subcontractors, B2B, etc., and we're looking for ideas on how others
> get a handle on this (or does anybody?).

"We" are also a large company (50,000 employees, worldwide subsidiaries).
There is a form on dead trees that we want to have signed before we
grant any access/change any firewall rule. This is to make sure most
people switch on their brains before they want anything. And by signing
the form they become responsible for the machines in question in case
they get hacked.

That very form contains an expiry date. New accesses are only allowed up
to a duration of one year. Many accesses are only needed for a test so
they are activated for a week or a month. Since we have a counter on
every form we can more or less easily "expire" them by looking through
old ones. The comment field in our firewall rules corresponds to the
numers on the forms.

I'm currently working on digital forms so that the users can extend that
period. If they don't react we will get an information that the rule can
be deleted. (Sorry, this isn't open-source since the company is paying
me to do it.)

In addition we have an internal revision department that checks our
rulebase every now and then. Although I have to be honest... they don't
understand every detail. And neither do we. Often the administrators of
the servers do not even know what they do. But that's where theory
differs from reality. :)

This may not be the greatest solution. But it works for us so far.

Regards
Christoph
--
~
~
~
".signature" [Modified] 3 lines --100%-- 3,41 All

--__--__--

_______________________________________________
firewall-wizards mailing list
firewall-wizards@honor.icsalabs.com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards

End of firewall-wizards Digest

NetFlash: VoIP rollouts generate heat, power concerns

NetFlash: VoIP rollouts generate heat, power concerns
08/31/05

In this issue:

* VoIP rollouts generate heat, power concerns
* Microsoft acquires VoIP provider Teleo
* Cell phone service takes a big hit in hurricane states
* BMC acquires knowledge mgmt. company
* IT director lends a hand in Thailand
* Today on Layer 8
* Links related to NetFlash
* Featured reader resource
_______________________________________________________________
This newsletter is sponsored by HP
FROM THE NETWORK CORE TO THE NETWORK EDGE

Traffic management becomes critical as your network
infrastructure expands to support different types of traffic and
users. Most traffic management solutions have serious
limitations: too expensive, difficult to use, and overly taxing
on bandwidth. However ProCurve Networking by HP addresses these
requirements, overcomes the limitations of other solutions, and
gives you valuable insight into LAN performance.
http://www.fattail.com/redir/redirect.asp?CID=111676
_______________________________________________________________
TROUBLE IN PARADISE?

As technologies such as VoIP emerge to advance networks, many
believe the tools to manage them are falling behind. Traditional
management software models simply can't keep up with the rate of
real-time change that today's applications sustain. Is there a
solution pending or should network managers rely on their own
innovations? Click here:
http://www.fattail.com/redir/redirect.asp?CID=111603
_______________________________________________________________

NETFLASH: BREAKING NEWS FROM NETWORKWORLD.COM

By Jeff Caruso

VoIP is spreading to many enthusiastic organizations - but those
organizations are starting to see the flipside of VoIP. With
VoIP, you need to run power to all those IP-enabled phones, and
that raises all sorts of other issues.
VoIP rollouts generate heat, power concerns
<http://www.networkworld.com/nlnetflash6226>

Microsoft acquires VoIP provider Teleo

Microsoft is going after Skype, the popular Internet-based
calling service. Its secret weapon is a start-up that's fresh
out of beta.
<http://www.networkworld.com/nlnetflash6227>

Cell phone service takes a big hit in hurricane states

In the destructive aftermath of Hurricane Katrina, hundreds of
repair crews from Verizon Wireless and Cingular Wireless are on
standby to get into ravaged parts Louisiana, Mississippi and
Alabama to repair waterlogged cell phone systems and equipment.
<http://www.networkworld.com/nlnetflash6228>

BMC acquires knowledge mgmt. company

BMC Software Tuesday announced it had acquired a maker of
knowledge management software in a deal that would equip BMC
with service-desk capabilities that it plans to incorporate into
its Remedy and Magic product suites.
<http://www.networkworld.com/nlnetflash6229>

IT director lends a hand in Thailand

Hurricane Katrina's devastation this week has brought home the
power of Mother Nature to many in the U.S. Earlier this summer,
Senior IT Director K.C. Tomsheck got a first-hand look at Mother
Nature's force abroad.
<http://www.networkworld.com/nlnetflash6230>

Today on Layer 8, news for the nerdy set:

Digital photography changes the way we take pictures; the
world's worst network acronym; iTunes music phone set for
launch; and will Google turn evil?; all this today and more at
your home for not-just-networking news.
<http://www.networkworld.com/weblogs/layer8/?net&story=layer8>

The top 5: Today's most-read stories

1. 2005 salary survey
<http://www.networkworld.com/nlnetflash3929>

2. Google dives deeper into networking
<http://www.networkworld.com/nlnetflash6132>

3. Cisco aims to simplify switch mgmt.
<http://www.networkworld.com/nlnetflash6135>

4. VoIP season about to heat up
<http://www.networkworld.com/nlnetflash6134>

5. A proposal for governing the 'Net
<http://www.networkworld.com/nlnetflash6231>

Today's most-forwarded story:

VoIP rollouts generate heat, power concerns
<http://www.networkworld.com/nlnetflash6232>

_______________________________________________________________
To contact: Jeff Caruso

Jeff Caruso is managing editor of online news for Network World.
He oversees daily online news posting and newsletter editing,
and writes the NetFlash daily news summary, the High-Speed LANs
newsletter and the Voices of Networking newsletter. Contact him
at <mailto:jcaruso@nww.com>
_______________________________________________________________
This newsletter is sponsored by HP
FROM THE NETWORK CORE TO THE NETWORK EDGE

Traffic management becomes critical as your network
infrastructure expands to support different types of traffic and
users. Most traffic management solutions have serious
limitations: too expensive, difficult to use, and overly taxing
on bandwidth. However ProCurve Networking by HP addresses these
requirements, overcomes the limitations of other solutions, and
gives you valuable insight into LAN performance.
http://www.fattail.com/redir/redirect.asp?CID=111675
_______________________________________________________________
ARCHIVE LINKS

NetFlash breaking news:
http://www.networkworld.com/news/netflash.html
_______________________________________________________________
Managed Network Services and Lowering Total Cost of Ownership

No IT organization can provide all services to all its users
without using external resources. A key task is to identify
which functions can be performed internally and which functions
should be outsourced. Learn more now.
http://www.fattail.com/redir/redirect.asp?CID=111532
_______________________________________________________________
FEATURED READER RESOURCE
VoIP

For the latest in VoIP, check out NW's Research Center on this
very topic. Here you will find a collection of the latest news,
reviews, product testing results and more all related to keeping
VoIP networks performing at their best. Click here for more:
<http://www.networkworld.com/topics/voip.html>
_______________________________________________________________
May We Send You a Free Print Subscription?
You've got the technology snapshot of your choice delivered
at your fingertips each day. Now, extend your knowledge by
receiving 51 FREE issues to our print publication. Apply
today at http://www.subscribenw.com/nl2

International subscribers click here:
http://nww1.com/go/circ_promo.html
_______________________________________________________________
SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World e-mail
newsletters, go to:
<http://www.nwwsubscribe.com/Changes.aspx>

To change your e-mail address, go to:
<http://www.nwwsubscribe.com/ChangeMail.aspx>

Subscription questions? Contact Customer Service by replying to
this message.

This message was sent to: security.world@gmail.com
Please use this address when modifying your subscription.
_______________________________________________________________

Have editorial comments? Write Jeff Caruso, Newsletter Editor,
at: <mailto:jcaruso@nww.com>

Inquiries to: NL Customer Service, Network World, Inc., 118
Turnpike Road, Southborough, MA 01772

For advertising information, write Kevin Normandeau, V.P. of
Online Development, at: <mailto:sponsorships@nwfusion.com>

Copyright Network World, Inc., 2005

Re: rules for FTP access

On Wednesday 31 August 2005 15:52, Fabrizio Sannicolo' wrote:
> yes, I have had this configuration since last July without
> problems...now my boss ask me to open FTP clients...
>
> I also let SSH connections, POPS, IMAPS ans so on ..

try to open also port 20.
or try an ftp-passive mode

--

denis

--
To UNSUBSCRIBE, email to debian-firewall-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org

Re: rules for FTP access

On 2005-08-31 Fabrizio Sannicolo' wrote:
> I use iptables to forward traffic from Intranet to Internet and
> viceversa using a rule such as
>
> iptables -t nat -A POSTROUTING -o eth0 -j SNAT --to-source $SERV_EXT
[...]
> for any chain I let ESTABLISHED and RELATED connection...
>
> iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
>
> and, at the end of each chain (INPUT, OUTPUT and FORWARD), I put
>
> iptables -A INPUT -j DROP

That's what the default policies are for:

iptables -P INPUT DROP

> my problem is that I am not able to enable ftp connections ...

You'll need connection tracking, since FTP uses two channels one of which
is dynamically determined when establishing the connection.

Regards
Ansgar Wiechers
--
"Another option [for defragmentation] is to back up your important files,
erase the hard disk, then reinstall Mac OS X and your backed up files."
--http://docs.info.apple.com/article.html?artnum=25668

--
To UNSUBSCRIBE, email to debian-firewall-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org

rules for FTP access

dear Sir/Madam,

I have a linux box (sarge) as router/firewall in my organization. At the
moment that Linux box has 3 ethernet cards as follows:

eth0 with public IP
eth1 private subnet
eth2 DMZ and WiFi

I use iptables to forward traffic from Intranet to Internet and
viceversa using a rule such as

iptables -t nat -A POSTROUTING -o eth0 -j SNAT --to-source $SERV_EXT

I also enable specific services with rules such as

iptables -A INPUT -i eth2 -s 192.168.3.0/24 -p tcp --dport 22 -m state
--state NEW -j ACCEPT

or

iptables -A FORWARD -i eth1 -o eth0 -p tcp --dport 80 -m state --state
NEW -j ACCEPT

for any chain I let ESTABLISHED and RELATED connection...

iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT

and, at the end of each chain (INPUT, OUTPUT and FORWARD), I put

iptables -A INPUT -j DROP

my problem is that I am not able to enable ftp connections ...

Could you help me, please?

thanks, fabrizio.

--
To UNSUBSCRIBE, email to debian-firewall-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org

[SECURITY] [DSA 792-1] New pstotext packages fix arbitrary command execution

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Debian Security Advisory DSA 792-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
August 31st, 2005 http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package : pstotext
Vulnerability : missing input sanitising
Problem-Type : remote
Debian-specific: no
CVE ID : CAN-2005-2536
BugTraq ID : 14378
Debian Bug : 319758

Max Vozeler discovered that pstotext, a utility to extract text from
PostScript and PDF files, did not execute ghostscript with the -dSAFER
argument, which prevents potential malicious operations to happen.

For the old stable distribution (woody) this problem has been fixed in
version 1.8g-5woody1.

For the stable distribution (sarge) this problem has been fixed in
version 1.9-1sarge1.

For the unstable distribution (sid) this problem has been fixed in
version 1.9-2.

We recommend that you upgrade your pstotext package.

Upgrade Instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody
- --------------------------------

Source archives:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g-5woody1.dsc
Size/MD5 checksum: 569 5e4999fac3cb50533b8fa55fa9b8d839
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g-5woody1.diff.gz
Size/MD5 checksum: 5551 e8656ca1e70907515dea96f646defbeb
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g.orig.tar.gz
Size/MD5 checksum: 36193 dfabf95fffea52cc03d8728617ca1b1e

Alpha architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g-5woody1_alpha.deb
Size/MD5 checksum: 33478 dc7994b7f762a99cda3f6e9eebfd5078

ARM architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g-5woody1_arm.deb
Size/MD5 checksum: 31158 64eb3bb5eaf13a54356bd8b55212ac93

Intel IA-32 architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g-5woody1_i386.deb
Size/MD5 checksum: 31140 ed687aa111ef4d56fd7b2fb220f8118a

Intel IA-64 architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g-5woody1_ia64.deb
Size/MD5 checksum: 37056 7ac97b49306cf896bb3d62b6b076ecb0

HP Precision architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g-5woody1_hppa.deb
Size/MD5 checksum: 32884 6e7b79977d550e6981b0a6849face1b9

Motorola 680x0 architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g-5woody1_m68k.deb
Size/MD5 checksum: 30124 5b23f0c04107d284c561d1621c4fd9d1

Big endian MIPS architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g-5woody1_mips.deb
Size/MD5 checksum: 32978 56283a3ef2931d2c4759c4c56218f83a

Little endian MIPS architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g-5woody1_mipsel.deb
Size/MD5 checksum: 32624 29ed7091abca377c4b91fa68d7bc48cb

PowerPC architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g-5woody1_powerpc.deb
Size/MD5 checksum: 32082 c8b4af3f34d681f9dabe4ff31bf0434a

IBM S/390 architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g-5woody1_s390.deb
Size/MD5 checksum: 31354 ce7f8f5b398350e9d779a847b7c5ef2f

Sun Sparc architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.8g-5woody1_sparc.deb
Size/MD5 checksum: 35050 e6e74a1ccfc2cb7246911b2f0427609f

Debian GNU/Linux 3.1 alias sarge
- --------------------------------

Source archives:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1sarge1.dsc
Size/MD5 checksum: 566 a4a25eaf8322a20742fb0eac628c096c
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1sarge1.diff.gz
Size/MD5 checksum: 7817 634b242dbb68cbb6cf1595e6fa390d0e
http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9.orig.tar.gz
Size/MD5 checksum: 37461 64576e8a10ff5514e285d98b3898ae78

Alpha architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1sarge1_alpha.deb
Size/MD5 checksum: 34084 82b71b24a4248ea05d243aa1d7b00e7c

AMD64 architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1sarge1_amd64.deb
Size/MD5 checksum: 33670 b5911eb9b067b55315dadfba9c8cb590

ARM architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1sarge1_arm.deb
Size/MD5 checksum: 32260 426147c50900aba089a9eb430e2094bb

Intel IA-32 architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1sarge1_i386.deb
Size/MD5 checksum: 32632 e2f9a3859fe3061c85d4f1a54253062e

Intel IA-64 architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1sarge1_ia64.deb
Size/MD5 checksum: 37624 76f3ed1bb870504692fe7fadbeb6e9b7

HP Precision architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1sarge1_hppa.deb
Size/MD5 checksum: 34282 7570594eef38d55ebb26e981c8de306b

Motorola 680x0 architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1sarge1_m68k.deb
Size/MD5 checksum: 31370 b9bd589dbbaf0d516cefb4f0b40397be

Big endian MIPS architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1sarge1_mips.deb
Size/MD5 checksum: 34196 ac148736eaeedd368b6114c79c45b569

Little endian MIPS architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1sarge1_mipsel.deb
Size/MD5 checksum: 33800 f9bad656d356e522daf2de44c0cc5f26

PowerPC architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1sarge1_powerpc.deb
Size/MD5 checksum: 33408 1b7b3cf7e04b3bf313d798ee822f7e92

IBM S/390 architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1sarge1_s390.deb
Size/MD5 checksum: 32948 b10976913ca43591166801bb9844f096

Sun Sparc architecture:

http://security.debian.org/pool/updates/main/p/pstotext/pstotext_1.9-1sarge1_sparc.deb
Size/MD5 checksum: 32992 c15517e727b7c38adec0f5f85282c430

These files will probably be moved into the stable distribution on
its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iD8DBQFDFZL/W5ql+IAeqTIRArUzAJ95vyOxW+1CZU4UgSatkCljhARCmACfXkYb
gWLcQm6OQ8nZTV05XMkOg94=
=v5XA
-----END PGP SIGNATURE-----

--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org

ISAserver.org - August 2005 Newsletter

ISAserver.org Newsletter of August 2005
Sponsored by: GFI Software Ltd
------------------------------------------------------------------------------
In this issue:
How to Communicate Your Problems with the ISA Firewall
Tom and Deb Shinder's Configuring ISA Server 2004 -- Order Today!
ISAserver.org Learning Zone Articles of Interest
KB Articles of the Month
Tip of the Month
ISA Firewall Links of the Month
Ask Dr. Tom

Welcome to the ISAserver.org newsletter! Each month we will bring you interesting and helpful information on ISA Server. We want to know what all *you* are interested in hearing about. Please send your suggestions for future newsletter content to: tshinder@isaserver.org

------------------------------------------------------------------------------
------------------------------------------------------------------------------
GFI WebMonitor for ISA Server 3 out now in BETA - Includes content filtering & virus scanning features!
The latest version of GFI WebMonitor for ISA Server, a utility for ISA server that allows for real time monitoring of web sites being browsed by network users and the files they are downloading, is now available in BETA! Version 3, BETA now includes a real-time online adult content filter, virus scanning and file type blocking capabilities and byte transfer stats per user/per site.

Click here (http://www.gfi.com/inj/) to download the new and improved BETA version!
------------------------------------------------------------------------------
------------------------------------------------------------------------------

1. How to Communicate Your Problems with the ISA Firewall
By Thomas W Shinder MD, MVP

We try to answer as many questions as possible on the ISAServer.org messages boards and mailing list. Sometimes there are some very interesting and potentially solvable questions, but there's not enough information provided to answer the question. Here are some things you can do to help all of us be more effective in answering your questions:

- Let us know what you have done to prove that it's an ISA firewall issue. From my experience, over 95% of connectivity issues are falsely attributed to the ISA firewall where the problem actually lies with some other network service or network infrastructure device
- Provide IP addressing information, including DNS settings, for your ISA firewall's NICs
- Provide information on what Access Rules are created on the ISA firewall and in what order they appear
- Tell us exactly what you want to accomplish. Don't give vague examples, tell us exactly what it is your trying to do
- Tell us exactly what you have done to make happen what you want to happen. Don't provide vague descriptions, tell us exactly what you did
- Provide exact descriptions of error messages seen on the client side, and also what appears in the ISA firewall's log files. Also, provide any information related to ISA firewall errors in the Windows Event Viewer
- If asked for an exact configuration of an Access Rule or Web Publishing Rule, give exact information. That means you put in real FQDNs, IP addresses, etc. If you use www.example.com, that doesn't help and it will likely end the discussion

If you follow these simple guidelines, the chances that your question will be answered quickly and correctly will be increased significantly. It will also show you've performed appropriate due diligence to solve the problem yourself and keep everyone's interest in making sure you get to your desired result.

=======================

Quote of the Month - "I'd rather be lucky than good. It's even better to be both" -Tom Shinder speaking of his post-undergraduate days as a semiprofessional gambler

=======================

------------------------------------------------------------------------------

2. Tom and Deb Shinder's Configuring ISA Server 2004 -- Order Today!
By Thomas W Shinder

Tom and Deb Shinder's best selling books on ISA Server 2000 were the "ISA Server Bibles" for thousands of ISA Server 2000 network administrators. Tom and Deb Shinder present you with their next ISA Server book, Configuring ISA Server 2004. This book leverages the over two years of pre-release experience Tom and Deb have had with ISA Server 2004, from pre-alpha to RTM and all the versions and builds in between. They've logged literally 1000's of flight hours with ISA Server 2004 and they have shared the Good, the Great, the Bad and the Ugly of ISA Server 2004 with their no holds barred coverage of Microsoft's new one of a kind application layer inspection firewall.

While the ISA Server 2000 books were good, Configuring ISA Server 2004 is even better. Tom and Deb bring their unique "insider's perspective" to provide you with information that isn't and won't be available anywhere else! Order your copy of Configuring ISA Server 2004 by clicking the link. You'll be glad you did.

Click here to Order your copy today: http://www.amazon.com/exec/obidos/ASIN/1931836191/isaserver/

------------------------------------------------------------------------------
------------------------------------------------------------------------------
GFI WebMonitor for ISA Server 3 out now in BETA - Includes content filtering & virus scanning features!
The latest version of GFI WebMonitor for ISA Server, a utility for ISA server that allows for real time monitoring of web sites being browsed by network users and the files they are downloading, is now available in BETA! Version 3, BETA now includes a real-time online adult content filter, virus scanning and file type blocking capabilities and byte transfer stats per user/per site.

Click here (http://www.gfi.com/inj/) to download the new and improved BETA version!
------------------------------------------------------------------------------
------------------------------------------------------------------------------

3. ISAserver.org Learning Zone Articles of Interest

Publishing an OWA Site in a Back to Back ISA Firewall Configuration (Part 2)
http://isaserver.org/tutorials/Publishing-OWA-Site-Back-to-Back-ISA-Firewall-Part2.html

Publishing an OWA Site in a Back to Back ISA Firewall Configuration (Part 1)
http://isaserver.org/tutorials/Publishing-OWA-Site-Back-to-Back-ISA-Firewall-Part1.html

Product Review: HP ProLiant DL320
http://isaserver.org/articles/HP-ProLiant-DL320-ISA-Hardware-Firewall.html

Redirecting OWA Users to the Correct Directories and Protocols (Part 2)
http://isaserver.org/tutorials/Redirecting-OWA-Users-Part2.html

Redirecting OWA Users to the Correct Directories and Protocols (Part 1) v.1.1
http://isaserver.org/tutorials/Redirecting-OWA-Users-Part1.html

Troubleshooting IPSec Tunnel Mode Scenarios
http://isaserver.org/tutorials/Troubleshooting-IPSec-Tunnel-Mode-Scenarios.html

How to Record URL and User Information in ISA 2004 Firewall Logs and Reports
http://isaserver.org/tutorials/2004recorduserinfo.html

------------------------------------------------------------------------------
4. KB Articles of the Month

Here are some interesting and useful ISA Server related Q articles posted by Microsoft in the last month:

You cannot use Netstat to verify holes in ISA Server 2004
http://support.microsoft.com/default.aspx?scid=kb;en-us;838127

FIX: The "Maximum number of VPN clients allowed" value is reset when you install ISA Server 2004 Enterprise Edition and join the server to an existing array
http://support.microsoft.com/default.aspx?scid=kb;en-us;898717

The Firewall service may not start in Internet Security and Acceleration (ISA) Server 2004 after you select a certificate for a, SSL listener
http://support.microsoft.com/default.aspx?scid=kb;en-us;896495

How to create a detailed firewall policy report for any firewall policy in Internet Security and Acceleration Server 2004
http://support.microsoft.com/default.aspx?scid=kb;en-us;841663

RPC data may be blocked, and Outlook may not start in Windows Server 2003 with SP1
http://support.microsoft.com/default.aspx?scid=kb;en-us;897716

Programs and services on a Firewall Client computer may not be able to access remote resources in ISA Server 2004
http://support.microsoft.com/default.aspx?scid=kb;en-us;888642

FIX: You cannot use a different SSL certificate for each array member in an ISA Server 2004, Enterprise Edition-based array
http://support.microsoft.com/default.aspx?scid=kb;en-us;898066

You receive a "Setup failed while registering Wspadmin.dll" error message when you try to install ISA Server 2004
http://support.microsoft.com/default.aspx?scid=kb;en-us;884494

------------------------------------------------------------------------------
5. Tip of the Month

You've created a very slick, very secure, and exquisitely functional split DNS infrastructure. Users never need to reconfigure any application depending on his location. The user just opens his laptop, opens the Web browser, e-mail client, or other network application, and it just works. You know it works because you've deployed a split DNS infrastructure.

However, you've been having problems with your VPN clients. They're not resolving internal names correctly when connected to the ISA firewall's remote access VPN server. The problem is a bug in Windows 2000 and Windows XP that prevents the RAS adapter from being automatically placed on the top of the adapter list. The KB article Cannot Change the Binding Order for Remote Access Connections at http://support.microsoft.com/default.aspx?scid=kb;en-us;311218&Product=winxp provides a workaround for this bug. HTH -Tom

------------------------------------------------------------------------------
------------------------------------------------------------------------------
GFI WebMonitor for ISA Server 3 out now in BETA - Includes content filtering & virus scanning features!
The latest version of GFI WebMonitor for ISA Server, a utility for ISA server that allows for real time monitoring of web sites being browsed by network users and the files they are downloading, is now available in BETA! Version 3, BETA now includes a real-time online adult content filter, virus scanning and file type blocking capabilities and byte transfer stats per user/per site.

Click here (http://www.gfi.com/inj/) to download the new and improved BETA version!
------------------------------------------------------------------------------
------------------------------------------------------------------------------

6. ISA Firewall Links of the Month

Compare Offerings from ISA Hardware Firewall Vendors

http://www.microsoft.com/isaserver/hardware/vendorcomparison.mspx

Reasons why a Hardware ISA Firewall might be best for you

http://www.microsoft.com/isaserver/hardware/default.mspx

ISA Firewall Webinars on the NS Hardware ISA Firewall

http://www.networkengines.com/sol/Webinars.aspx

Collection of New ISA Firewall Tools for FREE

http://www.microsoft.com/isaserver/downloads/2004/default.mspx

Check out this new ISA Firewall Scripts site

http://www.isascripts.org/

Microsoft Releases a TON of new ISA Firewall Troubleshooting Guides

http://www.microsoft.com/isaserver/techinfo/guidance/2004/planning.mspx

SSL Capacity Planning for ISA Firewalls

http://www.microsoft.com/technet/prodtechnol/isa/2004/plan/ssl_performance.mspx

------------------------------------------------------------------------------

7. Ask Dr. Tom

QUESTION: The guy that came in before me setup the ISA firewall with a single NIC configuration and has configured the clients to be Firewall and Web proxy clients of the ISA firewall. I'm concerned that this isn't a secure configuration, since the clients are also configured to use a simple stateful packet inspection "hardware" firewall as their default gateway. What's the best way to correct the security issues with this firewall infrastructure?

ANSWER: There are two major problems with this deployment:

- The single NIC ISA firewall configuration supports only a tiny subset of the ISA firewall's full firewall functionality
- A single NIC ISA firewall cannot perform reliable access control

A single NIC ISA firewall is a hamstrung ISA firewall that is at the mercy of any other firewall you have on the network. If your main network firewall is a simple stateful packet inspection firewall, you're in for some serious trouble. The following ISA firewall features are not available in a single NIC ISA firewall configuration:

- Multi-network firewall policy. In single network adapter mode, ISA Server recognizes itself (the Local Host network). Everything else is recognized as the Internal network. There is no concept of an External network. Microsoft Firewall service and application filters operate only in the context of the Local Host network. (ISA Server protects itself no matter what network template is applied.) Because the Firewall service and application filters operate in the context of the Local Host network, you can use access rules to allow non-Web protocols to the ISA Server computer itself.
- Application layer inspection. Application level filtering is not functional, except for the Web Proxy filter (for HTTP, HTTPS, and FTP over HTTP).
- Server publishing. Server publishing is not supported. There is no separation of Internal and External networks, so ISA Server cannot provide the network address translation (NAT) functionality required in a server publishing scenario.
- Firewall clients. The Firewall Client application handles requests from Winsock applications that use the Firewall service. This service is not available in a single network adapter environment.
- SecureNAT clients. SecureNAT clients use ISA Server as a router to the Internet, and SecureNAT client requests are handled by the Firewall service. Because the Firewall service is not available in a single network adapter configuration, such requests are not supported.
- Virtual private networking. Site-to-site virtual private networks (VPNs) and remote access VPNs are not supported in a single network adapter scenario.

A single NIC ISA firewall also cannot perform reliable access control. The reason for this is that the ISA firewall must be in the request/response path in order to prevent users, both internal and external, from compromising your network. It's a relatively simple affair to bypass a single NIC ISA firewall to access resources that would have otherwise been protected if the ISA firewall had been setup correctly.

For these reasons, and many more, we at ISAServer.org consider the unihomed, single-NIC ISA firewall to be a legacy configuration that is deprecated and should be eschewed by all serious network and firewall administrators.

You can correct the current configuration by putting a second NIC in the ISA firewall and reconfiguring it in a back to back firewall configuration, with the simple stateful packet inspection firewall in front of the ISA firewall. Configure the ISA firewall's external interface to use the LAN interface of the simple stateful packet inspection firewall as its default gateway.

Got a question for Dr. Tom? Send it to tshinder@isaserver.org

------------------------------------------------------------------------------
------------------------------------------------------------------------------
GFI WebMonitor for ISA Server 3 out now in BETA - Includes content filtering & virus scanning features!
The latest version of GFI WebMonitor for ISA Server, a utility for ISA server that allows for real time monitoring of web sites being browsed by network users and the files they are downloading, is now available in BETA! Version 3, BETA now includes a real-time online adult content filter, virus scanning and file type blocking capabilities and byte transfer stats per user/per site.

Click here (http://www.gfi.com/inj/) to download the new and improved BETA version!
------------------------------------------------------------------------------
------------------------------------------------------------------------------

Visit the Subscription Management section to unsubscribe.
ISAserver.org is in no way affiliated with Microsoft Corp.
For sponsorship information, contact us at advertising@isaserver.org.
Copyright © ISAserver.org 2005. All rights reserved.