Home Resources Staff Blogs

Rob Chee's Network Security Blog

My musings on network security can be found here. Click on a title to read the complete article.

The Cisco AnyConnect VPN client is Cisco’s SSL VPN client offering.  Cisco currently supports this VPN client and the legacy IPSec VPN client, called the Cisco VPN Client.  The Cisco VPN client will be phased out over time.  This can be seen by the Cisco VPN Client FAQ explaining that 64 bit operating systems are not supported by the Cisco VPN client, but are supported by the Cisco AnyConnect VPN client. 


Creating Custom MARS IPS Signatures

Posted by: Rob Chee

Tagged in: MARS , IPS

MARS and Cisco IPS are synchronized for the official IPS signatures created by Cisco.  This is done through the automatic updates that occur on the IPS side and on the MARS side.  On the IPS side, this done by configuring “Configuration > Sensor Management > Auto/Cisco.com Update” within IPS Manager Express (IME).  This is shown below


Cisco NAC Appliance 4.7.1 released

Posted by: Rob Chee

Tagged in: NAC Appliance

Cisco NAC appliance 4.7.1 was just recently released.  The main new features are support for Windows 7 and Apple Macintosh OS 10.6 (Snow Leopard).


Using SMIME for Email Security

Posted by: Rob Chee

Tagged in: smime , email security

Email security is an important facet of data protection, both for enterprises and individuals.  Email security can be implemented to perform email authentication and/or email encryption.  Both authentication and encryption are provided using Secure/Multipurpose Internet Mail Extensions (S/MIME) with public key cryptography (PKI).  The basic requirements for PKI are a certificate authority (CA), a private key, and a public key.  An example is shown later that explains how to set up PKI for email using Comodo as the CA and Mozilla Thunderbird as the email client.


New Cisco Security Podcasts Available

Posted by: Rob Chee

Tagged in: TAC , Security , podcast

The Cisco Security team had started a podcast series through iTunes in 2008.  They had 7 podcasts and then it died out.  The podcasts are still available, on iTunes.  Just search on Cisco and you'll see the Cisco security podcasts as well as other Cisco podcasts.


SNMP is one of the key technologies used in out-of-band Cisco NAC Appliance deployments.  The NAC Manager sends SNMP GET commands to the access switches to learn about the switch port configuration.  The NAC Manager also sends SNMP SET commands to the access switches to change individual switch ports from the authentication VLAN to the access VLAN and vice versa.  The access switches send SNMP traps to the NAC Manager to tell the NAC Manager about individual switch ports that go up or down and switch ports that have new MAC addresses connected to them.  With that information, the NAC Manager can decide whether the switch port should be moved back to the authentication VLAN.


SNMP Testing with net-snmp

Posted by: Rob Chee

Tagged in: snmp , net-snmp

With most network management systems and network security systems, SNMP is a critical component. One great tool for checking SNMP functionality is net-snmp. This tool works with Windows and Linux. From a security perspective, this net-snmp can be used as another troubleshooting tool to ensure that Cisco MARS and Cisco NCM are working correctly.

One basic tool, included with the toolset, is snmpwalk. This can be used to determine the OIDs used for a network device. Here's a partial execution of the command against a Cisco 2523 router.


Creating Policies with Cisco NCM

Posted by: Rob Chee

Tagged in: NCM

Do you have security policy requirements that need to be enforced on your routers and switches?  One option to accomplish this task is to periodically check the configurations of all routers and switches. This approach is painful and time consuming.  Another option is to use an application to automate this process.  This is one of the areas where Cisco Network Compliance Manager (NCM) can assist.  With NCM you can create policies that regularly check for elements of your security policy and alert you if they are not being met.  NCM does this by first grabbing the router and switch configurations on a periodic basis.  NCM then matches these configurations against the NCM policies that you create to meet your security policy.  Here’s an example showing how this would be configured within NCM.


Troubleshooting Cisco NAC AD SSO

Posted by: Rob Chee

Tagged in: NAC , AD SSO

When deploying Cisco NAC for desktop computers, it is imperative minimize the impact to the end user experience as much as possible.  This helps to ensure that the NAC deployment does not get derailed by user complaints.  One way to minimize the impact is to implement Active Directory Single Sign-On (AD SSO).  With AD SSO, the user just has to complete their Microsoft logon.  The NAC Appliance uses Kerberos to verify the user’s authenticity instead of prompting for a NAC logon.  The NAC setup of AD SSO is easy to configure incorrectly even with the detailed steps in the Cisco NAC Server Configuration Guide.  The basic steps are listed below.


OMB has mandated the Federal Desktop Core Configuration (FDCC) security configuration.  NIST has a detailed set of configuration settings in an Excel spreadsheet that can be downloaded from http://fdcc.nist.gov. 


<< Start < Prev 1 2 3 Next > End >>

Tags

10 Gbps Ethernet 3G 7z 802.11 802.11 basics 802.11 course 802.11 project management 802.11 Traffic Flows 802.11 Wireless LAN 802.11n About Chesapeake NetCraftsmen Acrobits Acrobits Softphone AD Group Membership AD SSO Advanced Settings Tool alias anti-spoofing filters anti-virus anyconnect AnyConnect VPN AP vendor API Apple Apple iPhone ASA AT&T Attacks Attendant Console AXL Background Images Backup bandwidth BDP BFD BGP BGP neighbor soft-reconfiguration BGP redistribution BGP Route Reflector Design BGP Soft Reset bit error rate Bluetooth Boolean Expressions botnets bug business case C-MUG Call Globalization Call Optimization Call Queuing CallManager CallManager Express case study CCA CCDE CCDE practical CCDE written CCDE written practice CCIE CCIE Written CEF Certification CFUR Cisco 6500 Cisco 7200 Cisco Call Manager Cisco CallManager Cisco Design Zone Cisco Express Forwarding Cisco Live Cisco MPLS Cisco Phone Designer Cisco router Cisco switch Cisco TFTP Cisco Unified Presence Cisco VPN Client Cisco WebEx class of restriction CLI cloud computing CM co-channel interference COBRAS Communications Manager compliance configuration management configuration policy Contact Center Contact Center Express copSSH Corporate Directory CRS CRS Scripts CSA MC CUCM CUCM CLI CUCM troubleshooting CUCME CUPS customer mpls vpn customer mpls wan cygwin data center data center consolidation data center design data center infrastructure data center interconnect data center migration debug debugging design device configuration device discovery device groups device modeling devicelistx diagnostic tools diagnostics dial plan Directory Synchronization DirSync DNS SRV dual carrier MPLS VPN dual carrier MPLS WAN dual data center Dual WAN routing Dynagen Dynamips EIGRP email email security enterprise mpls vpn Enterprise MPLS WAN EoL2TPv3 EoMPLS ESX server NIC teaming etherchannel etherchannel mismatch Ethernet over MPLS event analysis event logs Exchange Expect Export extended VLAN failure domains Fast Rerouting FDCC fiber cuts fiber farm file transfer FIPS 140 Firefox firewall firmware upgrade full mesh fusion fusion router H.323 Hairpin Hairpin calls high availability iBGP IGP IIS Resource impact of packet loss Import Infrastructure Integrated Messaging interface groups IOS 12.4 IOS SSL ip multicast IP Phone Services IPCCX iPhone iPhone SIP Clients IPS IPv6 IPv6 addressing IPv6 addressing plan IPv6 Summit ISAKMP Java JRE jumbo L2 MPLS VPN L2 over L3 Lab large VLAN Layer 2 Layer 2 over Layer 3 Layer 2 Switching Layer 2 tunnel Layer 3 OOB layer 3 switching LDAP load balancer load balancing local preference Local Route Groups logparser mac address flapping malware MARS Mathis equation Mathis formula Meeting Center Message Store Configuration Wizard MGCP Microsoft Migration moving server virtually between zones MPLS MPLS QoS mpls routing MPLS VPN MPLS VPN customer routing MPLS VPN WAN MPLS WAN MSS MTTR Multi-VRF multicast multicast best practices multicast in a vrf multicast vrf lite Music On Hold MWI NAC NAC API NAC Appliance NAC design NAC roles NAC Server NAT NAT Traversal NCCM NCM net-snmp NetCraftsmen recruiting netflow NetMRI NetMRI trial Network Address Translation network analysis Network Compliance Manager network discovery network health network hygiene network management network monitoring network outages Nexus Nexus 2000 Nexus 5000 Nexus 7000 NMS Non Stop Forwarding Non-Stop Forwarding NSF OMB openSSH OSI layer OTV Out-of-band Outlook P2V packet captures packet loss PAT Patching PCA PCI PCI audit performance routing PERL netflow interpreter PERL script Personal Communications Assistant PfR Phone Customization physical to virtual conversion PIN security ping-pong PIX podcast port-based EoMPLS port-channel port-security sticky pre-site survey prefix-list Presence presentation problem management protocol analysis pseudo-wire pseudowire PWE Q.SIG QoS QoS in 6500 QoS with VSL radio considerations radio frequency redistribution redundancy REGEX REGEX practice regular expression Replication Restore Return Receipt RF RisPort ROI route reflectors router Routing convergence routing loop RSS feeds RTT rural fiber network script Security security patches server configuration server etherchannel SFTP shared services show ip cache flow SIP SIP Clients for iPhone SIP VoIP Phone for iPhone SLA slow slow application behavior smime snmp SNMP ifIndex snmp polling snmp traps SOAP spanning tree Spanning Tree loop SQL SRST SSL Certificate SSL VPN SSO standard network architecture standardization Stateful Switchover static routes Sup720-10G syslog TAC TCL TCP TCP performance TCP Ports TCP throughput test Testing throughput tools top of rack topology trace trojan troubleshooting Troubleshooting 802.11 TTL exceeded UC UC 7x UC Operations UC500 UC520 UCCX UDP Ports UM Unified Communications Unified Messaging Unity Unity Connection Unity troubleshooting Upgrade Using 10G ports Sup720 Using XML UTIM virtual desktop virtual machine virtual pod Virtual Switch Link virtualization vlan vlan-based EoMPLS VMWare VMware products VMware vSphere 4.0 glossary vmworld Voice voicecon Voicemail Voicemail Relay VoIP VoIP Metrics VoIP over 3G voip troubleshooting VPN VRF VRF into GRE vrf lite VRF-Lite VSL vSphere VSS WAN WAP vendor web logging WebEx WebEx Meeting Center WebEx Meeting Center for iPhone WeePhone weight WiFi WiFi Basics WiFi channels WiFi course WiFi vendors WinPCAP wireless wireless course wireless LAN wireless project management Wireless Project Plan Wireless Project Planning wireless requirement gathering WLAN WLAN course WLAN project management WLAN Traffic Flows WSUS X-Lite xconnect zeus
NetCraftsmen