<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Colin McNamara - CCIE 18233 , VCP, EMCIE, NCDA, GEEK &#187; threat</title>
	<atom:link href="http://www.colinmcnamara.com/technology-tags/threat/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.colinmcnamara.com</link>
	<description>Technical reviews and articles from a CCIE with extensive experience in designing and implementing converged enterprise networks.</description>
	<lastBuildDate>Fri, 13 Jan 2012 19:00:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Measuring and mitigating risk involved with sharing virtual infrastructure between DMZ and Internal environments</title>
		<link>http://www.colinmcnamara.com/measuring-and-mitigating-risk-involved-with-sharing-virtual-infrastructure-between-dmz-and-internal-environments/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=measuring-and-mitigating-risk-involved-with-sharing-virtual-infrastructure-between-dmz-and-internal-environments</link>
		<comments>http://www.colinmcnamara.com/measuring-and-mitigating-risk-involved-with-sharing-virtual-infrastructure-between-dmz-and-internal-environments/#comments</comments>
		<pubDate>Tue, 09 Sep 2008 20:36:57 +0000</pubDate>
		<dc:creator>colinmcnamara</dc:creator>
				<category><![CDATA[hyper-v]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[vmware]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[business context]]></category>
		<category><![CDATA[C]]></category>
		<category><![CDATA[CISCO]]></category>
		<category><![CDATA[Colin]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[Data Center]]></category>
		<category><![CDATA[DESIGN]]></category>
		<category><![CDATA[device contexts]]></category>
		<category><![CDATA[enhancements]]></category>
		<category><![CDATA[FCOE]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[Instances]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[NDA]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[network infrastructure]]></category>
		<category><![CDATA[Nexus 5020]]></category>
		<category><![CDATA[passed]]></category>
		<category><![CDATA[Pic]]></category>
		<category><![CDATA[risk risk]]></category>
		<category><![CDATA[san]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[storage]]></category>
		<category><![CDATA[switch]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[TrustSec]]></category>
		<category><![CDATA[virtual device]]></category>
		<category><![CDATA[vlan]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.colinmcnamara.com/?p=177</guid>
		<description><![CDATA[Ivan Pepelnjak over at IOS Hints and Tricks wrote a post about DMZ VLAN leaking that got me thinking. He writes about &#8220;the VLAN leaking myth&#8221; and how it encourages clients to utilize physically separate network infrastructure in the DMZ&#8217;s. Now first things first, I wouldn&#8217;t call VLAN leaking a myth. At one time it [...]<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/measuring-and-mitigating-risk-involved-with-sharing-virtual-infrastructure-between-dmz-and-internal-environments/">Measuring and mitigating risk involved with sharing virtual infrastructure between DMZ and Internal environments</a></p>
]]></description>
			<content:encoded><![CDATA[<p>Ivan Pepelnjak over at <a href="http://blog.ioshints.info/2008/09/are-vlans-safe-in-dmz-environment.html" target="_blank">IOS Hints and Tricks </a>wrote a post about DMZ VLAN leaking that got me thinking.</p>
<p>He writes about &#8220;the VLAN leaking myth&#8221; and how it encourages clients to utilize physically separate network infrastructure in the DMZ&#8217;s. Now first things first, I wouldn&#8217;t call VLAN leaking a myth. At one time it was a very real and serious vulnerability that was exploited by overflowing the capacity of the switch you were attacking, and causing it to &#8220;downgrade&#8221; from switch to a hub. Once this happened you now had access to previously protected devices, as well as having the ability to sniff data as it passed through the shared hub backplane.</p>
<p>As he mentions though, this is 8 years ago. Most switches have evolved to the point where backplanes far exceed the traffic that could ever be injected into their switchports. Even beyond backplane enhancements there are many ways to further firm up your security stance &#8211; Virtual Device Contexts, not using Layer 3 SVI&#8217;s on a DMZ VLAN, utilizing PVLANs, using port security, virtual routing instances, and many more. Of course, there are still many other attack vectors that still remain, but can be mitigated by utilizing features built into the majority of enterprise switches available today.</p>
<p>I think the real question is not &#8220;are VLANs safe in a DMZ&#8221;. The important question is have you mitigated the probability of compromise (the actual threat) to levels that are acceptable to your business. This question remains whether you have a standalone switch or not. So many times we hear about risk risk and more risk. But risk alone is meaningless in a business context. What is important is combining risk with likelihood. For that I like to use a simple table to come up with the true threat.</p>
<p><a class="thickbox" href="http://www.colinmcnamara.com/wp-content/gallery/breach/risk_grid.gif"><img class="ngg-singlepic ngg-center" src="http://www.colinmcnamara.com/wp-content/gallery/breach/thumbs/thumbs_risk_grid.gif" alt="risk_grid.gif" /></a></p>
<p>For example, as I drive to Fry&#8217;s there is the risk of me dying due to a car crash. The impact of me dying is very high (risk) however the likelihood of an accident is low, and furthermore I reduce (mitigate) the latent risk (threat) by wearing my seat belt. So all in all the threat of me dying on my way to Fry&#8217;s is pretty darn low.</p>
<p>In a business context this may be that I have public facing web servers and network devices in my DMZ. The impact of them being compromised is that my public image may be tarnished for a short time, and my end users may lose productivity if they are not able to VPN into work, or access the Internet while on premise. I mitigate this risk by using firewalls and both host and network based Intrusion Prevention Systems as well as implementing best security practices on my network and systems devices. The latent risk (threat) remaining is at a level that is acceptable to the business leaders, so the system is allowed.</p>
<p>One question that I have seen coming up more often as we move towards fully virtualized data centers is centered around commingling of virtual infrastructure. There are some hard questions which challenge some practices that we have held true over the years.</p>
<ul>
<li>Should you allow sharing of physical memory on a host virtual machine between an internal and DMZ server?</li>
<li>Should you allow virtual infrastructure from multiple security zones to share a storage array or cluster of arrays?</li>
<li>Should you allow multiple virtual switches in different security zones commingling on the same ESX or Hyper-V cluster?</li>
<li>Should you allow virtual firewall and load balancing instances protecting internal and external zones to reside on the same hardware?</li>
<li>Should you allow virtual routing instances from multiple zones to share a physical infrastructure?</li>
</ul>
<p>In the past world of standalone systems, the additional cost of providing a wholly separate infrastructure for DMZ environments was relatively low. Each system generally had internal disk, or at most direct attached storage. Network devices themselves were scaled down to support one chassis one function. This fit quite neatly into the Enterprise Composite Network model that was quite common from 1999-2003.</p>
<p>Now, many data centers have moved to the Service Oriented Network Architecture (SONA). In this model the cost of a virtualized data center is primarily focused on foundation elements such as the virtual storage and virtual fabrics, virtualized network, and virtual systems elements. The cost of providing additional virtualized services off these elements is low, however the cost of duplicating the physical infrastructure is quite high on both the capital and operational levels. This is forcing the technical and executive leadership at many companies to take a long hard look at the true threats they are facing in previously physically separate security zones such as DMZ&#8217;s, Financial and other secure zones. In the end, they are having to decide whether the threat remaining after their security controls is worth duplicating hundreds of thousands of dollars worth of infrastructure or not.</p>
<p>These are hard questions, with really no single good answer. My gut feel is that over the next few years we will continue the move towards the fully virtualized data center where components such as memory, PCI-X buses, storage and network devices are even further decentralized. This will make the cost of duplicating the infrastructure more and more significant, causing consolidated data center (or compute) fabrics to be the norm. At this point the discussion will move away from securing zones by creating separate infrastructure, to providing end to end security, starting integrated application level security, maybe with TrustSec or a dirivative, all the way down to securing the data at rest on disk. For the time being however, the best we can do is sit down and do an honest appraisel of our security stances, mitigate what we can, and do our best to design data center architectures that provide the flexibility of implementing whatever choice the technical and business leaders agree on.<strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.colinmcnamara.com/moving-towards-a-green-data-center-truth-behind-the-hype/" rel="bookmark" title="February 22, 2008">Moving towards a Green Data Center &#8211; Truth behind the hype</a></li>
<li><a href="http://www.colinmcnamara.com/ciscos-cloud-computing-offering/" rel="bookmark" title="April 7, 2009">Cisco&#8217;s Cloud Computing Offering</a></li>
<li><a href="http://www.colinmcnamara.com/about/" rel="bookmark" title="January 5, 2008">About Colin McNamara</a></li>
<li><a href="http://www.colinmcnamara.com/vote-for-my-vmworld-presentation-shameless-pandering/" rel="bookmark" title="May 12, 2011">Vote for my VMworld presentation &#8211; #3221 Built to fail (shameless pandering)</a></li>
<li><a href="http://www.colinmcnamara.com/remote-site-security-cisco-analog-video-gateway-video-management-storage-system-network-modules-on-the-integrated-services-router-isr/" rel="bookmark" title="June 10, 2008">Simplifying remote site security with Cisco&#8217;s new video surveillance modules on the ISR</a></li>
<li><a href="http://www.colinmcnamara.com/interesting-techwise-tv-episode-on-virtualization/" rel="bookmark" title="October 23, 2008">Interesting TechWise TV episode on  virtualization</a></li>
</ul>
<p><!-- Similar Posts took 44.058 ms --></p>
<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/measuring-and-mitigating-risk-involved-with-sharing-virtual-infrastructure-between-dmz-and-internal-environments/">Measuring and mitigating risk involved with sharing virtual infrastructure between DMZ and Internal environments</a></p>

	Tags: <a href="http://www.colinmcnamara.com/technology-tags/blog/" title="blog" rel="tag">blog</a>, <a href="http://www.colinmcnamara.com/technology-tags/breach/" title="breach" rel="tag">breach</a>, <a href="http://www.colinmcnamara.com/technology-tags/business-context/" title="business context" rel="tag">business context</a>, <a href="http://www.colinmcnamara.com/technology-tags/c/" title="C" rel="tag">C</a>, <a href="http://www.colinmcnamara.com/technology-tags/cisco/" title="CISCO" rel="tag">CISCO</a>, <a href="http://www.colinmcnamara.com/technology-tags/colin/" title="Colin" rel="tag">Colin</a>, <a href="http://www.colinmcnamara.com/technology-tags/compromise/" title="compromise" rel="tag">compromise</a>, <a href="http://www.colinmcnamara.com/technology-tags/data-center/" title="Data Center" rel="tag">Data Center</a>, <a href="http://www.colinmcnamara.com/technology-tags/design/" title="DESIGN" rel="tag">DESIGN</a>, <a href="http://www.colinmcnamara.com/technology-tags/device-contexts/" title="device contexts" rel="tag">device contexts</a>, <a href="http://www.colinmcnamara.com/technology-tags/enhancements/" title="enhancements" rel="tag">enhancements</a>, <a href="http://www.colinmcnamara.com/technology-tags/fcoe/" title="FCOE" rel="tag">FCOE</a>, <a href="http://www.colinmcnamara.com/technology-tags/hp/" title="HP" rel="tag">HP</a>, <a href="http://www.colinmcnamara.com/technology-tags/hyper-v/" title="hyper-v" rel="tag">hyper-v</a>, <a href="http://www.colinmcnamara.com/technology-tags/instances/" title="Instances" rel="tag">Instances</a>, <a href="http://www.colinmcnamara.com/technology-tags/linux/" title="linux" rel="tag">linux</a>, <a href="http://www.colinmcnamara.com/technology-tags/nda/" title="NDA" rel="tag">NDA</a>, <a href="http://www.colinmcnamara.com/technology-tags/network/" title="Network" rel="tag">Network</a>, <a href="http://www.colinmcnamara.com/technology-tags/network-infrastructure/" title="network infrastructure" rel="tag">network infrastructure</a>, <a href="http://www.colinmcnamara.com/technology-tags/nexus-5020/" title="Nexus 5020" rel="tag">Nexus 5020</a>, <a href="http://www.colinmcnamara.com/technology-tags/passed/" title="passed" rel="tag">passed</a>, <a href="http://www.colinmcnamara.com/technology-tags/pic/" title="Pic" rel="tag">Pic</a>, <a href="http://www.colinmcnamara.com/technology-tags/risk-risk/" title="risk risk" rel="tag">risk risk</a>, <a href="http://www.colinmcnamara.com/technology-tags/san/" title="san" rel="tag">san</a>, <a href="http://www.colinmcnamara.com/technology-tags/security/" title="security" rel="tag">security</a>, <a href="http://www.colinmcnamara.com/technology-tags/storage/" title="storage" rel="tag">storage</a>, <a href="http://www.colinmcnamara.com/technology-tags/switch/" title="switch" rel="tag">switch</a>, <a href="http://www.colinmcnamara.com/technology-tags/threat/" title="threat" rel="tag">threat</a>, <a href="http://www.colinmcnamara.com/technology-tags/trustsec/" title="TrustSec" rel="tag">TrustSec</a>, <a href="http://www.colinmcnamara.com/technology-tags/virtual-device/" title="virtual device" rel="tag">virtual device</a>, <a href="http://www.colinmcnamara.com/technology-tags/virtualization/" title="virtualization" rel="tag">virtualization</a>, <a href="http://www.colinmcnamara.com/technology-tags/vlan/" title="vlan" rel="tag">vlan</a>, <a href="http://www.colinmcnamara.com/technology-tags/vmware/" title="vmware" rel="tag">vmware</a>, <a href="http://www.colinmcnamara.com/technology-tags/vulnerability/" title="vulnerability" rel="tag">vulnerability</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.colinmcnamara.com/measuring-and-mitigating-risk-involved-with-sharing-virtual-infrastructure-between-dmz-and-internal-environments/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Simplifying remote site security with Cisco&#8217;s new video surveillance modules on the ISR</title>
		<link>http://www.colinmcnamara.com/remote-site-security-cisco-analog-video-gateway-video-management-storage-system-network-modules-on-the-integrated-services-router-isr/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=remote-site-security-cisco-analog-video-gateway-video-management-storage-system-network-modules-on-the-integrated-services-router-isr</link>
		<comments>http://www.colinmcnamara.com/remote-site-security-cisco-analog-video-gateway-video-management-storage-system-network-modules-on-the-integrated-services-router-isr/#comments</comments>
		<pubDate>Wed, 11 Jun 2008 00:31:13 +0000</pubDate>
		<dc:creator>colinmcnamara</dc:creator>
				<category><![CDATA[4s ranch rancho bernardo san diego witch fire evacuated]]></category>
		<category><![CDATA[CCIE]]></category>
		<category><![CDATA[CISCO]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sun]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[archived footage]]></category>
		<category><![CDATA[C]]></category>
		<category><![CDATA[camera control]]></category>
		<category><![CDATA[center infrastructure]]></category>
		<category><![CDATA[cisco secure]]></category>
		<category><![CDATA[Colin]]></category>
		<category><![CDATA[Data Center]]></category>
		<category><![CDATA[dust mites]]></category>
		<category><![CDATA[encoders]]></category>
		<category><![CDATA[Gadget]]></category>
		<category><![CDATA[hardware replacement]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[ip cameras]]></category>
		<category><![CDATA[isr]]></category>
		<category><![CDATA[legal]]></category>
		<category><![CDATA[life on mars]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[management infrastructure]]></category>
		<category><![CDATA[mars]]></category>
		<category><![CDATA[mitiigation]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[network storage]]></category>
		<category><![CDATA[Pic]]></category>
		<category><![CDATA[Power]]></category>
		<category><![CDATA[Router]]></category>
		<category><![CDATA[security environments]]></category>
		<category><![CDATA[security infrastructure]]></category>
		<category><![CDATA[storage]]></category>
		<category><![CDATA[storage system]]></category>
		<category><![CDATA[support contract]]></category>
		<category><![CDATA[surveillance systems]]></category>
		<category><![CDATA[switch]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[two choices]]></category>
		<category><![CDATA[video encoding]]></category>
		<category><![CDATA[video management]]></category>
		<category><![CDATA[video streams]]></category>
		<category><![CDATA[video surveillance]]></category>

		<guid isPermaLink="false">http://www.colinmcnamara.com/?p=130</guid>
		<description><![CDATA[One giant pain I have always faced when working with high security environments is dealing with surveillance systems. They are a necessary and required part of your security infrastructure. However they just never seem to integrate as well as your network, storage, or server devices. When I work with data center infrastructure I expect the [...]<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/remote-site-security-cisco-analog-video-gateway-video-management-storage-system-network-modules-on-the-integrated-services-router-isr/">Simplifying remote site security with Cisco&#8217;s new video surveillance modules on the ISR</a></p>
]]></description>
			<content:encoded><![CDATA[<p>One giant pain I have always faced when working with high security environments is dealing with surveillance systems. They are a necessary and required part of your security infrastructure. However they just never seem to integrate as well as your network, storage, or server devices.</p>
<p>When I work with data center infrastructure I expect the following &#8211; clean, remotely manageable, secure devices that runs on the same power and similar cabling, and everything can have a 24x7x4 support contract for hardware replacement. For the most part, you get this when dealing with Cisco, HP, Sun and similar manufacturers.</p>
<p>More often then not (with a few very cool exceptions), when I run into video surveillance infrastructure the video management infrastructure runs on some random third tier manufactured server. It never fails that the video management software is on Windows (normally XP or win2k). I have even seen some systems where the vendor requires you to have a session open to run the software.</p>
<p>And then when you get to the encoders themselves, it never fails. You have two choices.</p>
<ol>
<li>The Uber package that can run a Casino, Identify and track dust mites , and if you point it at space, determine if there is life on mars.</li>
<li>Individual dinky encoders that run one or two camera&#8217;s each. They have limited encoding choices, limited camera control, no remote management, and normally run on 110 volt system that require different power distribution then the 220 that is common in systems today.</li>
</ol>
<p><strong>Cisco&#8217;s answer to this mess</strong></p>
<p>Cisco has released both a video management solution, as well as a video encoding solution in a network module form factor for the Integrated Services Router (ISR).</p>
<p><a class="thickbox" href="http://www.colinmcnamara.com/wp-content/gallery/cisco-surveillance/cisco-vmss-network-module-internal-view.jpg"><img class="ngg-singlepic ngg-none" src="http://www.colinmcnamara.com/wp-content/gallery/cisco-surveillance/thumbs/thumbs_cisco-vmss-network-module-internal-view.jpg" alt="cisco-vmss-network-module-internal-view.jpg" /></a></p>
<p>The first part of this system, the Video Management and Storage System (VMSS) module fills the following roles -</p>
<ul>
<li>Management of multiple video streams from one interface, including IP cameras, 3rd party encoders, and streams from Cisco&#8217;s video encoding module</li>
<li>Streaming of live and archived footage through a web browser interface</li>
<li>This one is pretty cool &#8211; The module can mount external storage via iSCSI. So, in addition to its 160 gig internal drive, you can mount a filer and utilize external storage to scale the system.</li>
<li>&#8220;fast forward&#8221; to events, as well as notify security and other personnel through SMS and email</li>
</ul>
<p style="text-align: left;">
<p style="text-align: left;"><a class="thickbox" href="http://www.colinmcnamara.com/wp-content/gallery/cisco-surveillance/ip-surveillance-both.jpg"><img class="ngg-singlepic ngg-none" src="http://www.colinmcnamara.com/wp-content/gallery/cisco-surveillance/thumbs/thumbs_ip-surveillance-both.jpg" alt="ip-surveillance-both.jpg" /></a></p>
<p style="text-align: left;">The second part of the system (the module on the left in the picture above) is the Analog Video Gateway Network Module (EV-IPVS-16A). It has a couple functions -</p>
<ul>
<li>It can take up to 16 analogue video inputs and encode them with MJPEG or MPEG4 codecs</li>
<li>You can use the first two ports to output video to a external monitors</li>
<li>If you are using MPEG4, it can be used as a motion detector (handy for fast forwarding to important events, or triggering alerts)</li>
<li>It can control pan and tilt cameras. This is good for pointing the camera at the janitor unplugging your servers each night to vacuum <img src='http://www.colinmcnamara.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </li>
<li>You can configure analogue contacts as an alarm. This can be bound to a door switch, or even temperature and water level monitors in a remote data center. This one will be very handy.</li>
</ul>
<p><a class="thickbox" href="http://www.colinmcnamara.com/wp-content/gallery/cisco-surveillance/cisco-video-surveillance-manager.jpg"><img class="ngg-singlepic ngg-none" src="http://www.colinmcnamara.com/wp-content/gallery/cisco-surveillance/thumbs/thumbs_cisco-video-surveillance-manager.jpg" alt="cisco-video-surveillance-manager.jpg" /></a></p>
<p>The third part of this solution is Cisco&#8217;s Video Surveillance Operations Manager. It manages, archives, displays and distributes the content that was created and collected on the two previous modules. You would use this if you had many branches to aggregate, or needed to staff a video wall (e.g. casino gaming commission operations). Now, you can run each of these components individually. Buy run together as a whole, Cisco has an enterprise class security solution.</p>
<p><strong>Want to learn more ?</strong></p>
<p>Branch office security page on cisco.com <a href="http://www.cisco.com/en/US/products/ps9671/prod_module_series_home.html" target="_blank">http://www.cisco.com/en/US/products/ps9671/prod_module_series_home.html</a></p>
<p>Cisco&#8217;s product page for the Video Managment Module &#8211; <a href="http://www.cisco.com/en/US/prod/collateral/modules/ps9671/data_sheet_c78_462225.html" target="_blank">http://www.cisco.com/en/US/prod/collateral/modules/ps9671/data_sheet_c78_462225.html</a><strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.colinmcnamara.com/interesting-techwise-tv-episode-on-virtualization/" rel="bookmark" title="October 23, 2008">Interesting TechWise TV episode on  virtualization</a></li>
<li><a href="http://www.colinmcnamara.com/about/" rel="bookmark" title="January 5, 2008">About Colin McNamara</a></li>
<li><a href="http://www.colinmcnamara.com/measuring-and-mitigating-risk-involved-with-sharing-virtual-infrastructure-between-dmz-and-internal-environments/" rel="bookmark" title="September 9, 2008">Measuring and mitigating risk involved with sharing virtual infrastructure between DMZ and Internal environments</a></li>
<li><a href="http://www.colinmcnamara.com/nexus-5020-consolidated-10-gig-ethernet-and-4-gig-fibre-channel/" rel="bookmark" title="April 9, 2008">Nexus 5020 &#8211; Consolidated 10 Gig Ethernet and 4 Gig Fibre Channel</a></li>
<li><a href="http://www.colinmcnamara.com/cisco-nexus-5020-and-5010-fcoe-video-ordering-guide/" rel="bookmark" title="December 15, 2008">Cisco Nexus 5020 and 5010 FCOE video ordering guide</a></li>
<li><a href="http://www.colinmcnamara.com/cisco-nx-os-40-next-generation-internet-operating-system/" rel="bookmark" title="January 29, 2008">Cisco NX-OS 4.0 | Next Generation Internet Operating System</a></li>
</ul>
<p><!-- Similar Posts took 52.844 ms --></p>
<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/remote-site-security-cisco-analog-video-gateway-video-management-storage-system-network-modules-on-the-integrated-services-router-isr/">Simplifying remote site security with Cisco&#8217;s new video surveillance modules on the ISR</a></p>

	Tags: <a href="http://www.colinmcnamara.com/technology-tags/archived-footage/" title="archived footage" rel="tag">archived footage</a>, <a href="http://www.colinmcnamara.com/technology-tags/c/" title="C" rel="tag">C</a>, <a href="http://www.colinmcnamara.com/technology-tags/camera-control/" title="camera control" rel="tag">camera control</a>, <a href="http://www.colinmcnamara.com/technology-tags/ccie/" title="CCIE" rel="tag">CCIE</a>, <a href="http://www.colinmcnamara.com/technology-tags/center-infrastructure/" title="center infrastructure" rel="tag">center infrastructure</a>, <a href="http://www.colinmcnamara.com/technology-tags/cisco/" title="CISCO" rel="tag">CISCO</a>, <a href="http://www.colinmcnamara.com/technology-tags/cisco-secure/" title="cisco secure" rel="tag">cisco secure</a>, <a href="http://www.colinmcnamara.com/technology-tags/colin/" title="Colin" rel="tag">Colin</a>, <a href="http://www.colinmcnamara.com/technology-tags/data-center/" title="Data Center" rel="tag">Data Center</a>, <a href="http://www.colinmcnamara.com/technology-tags/dust-mites/" title="dust mites" rel="tag">dust mites</a>, <a href="http://www.colinmcnamara.com/technology-tags/encoders/" title="encoders" rel="tag">encoders</a>, <a href="http://www.colinmcnamara.com/technology-tags/gadget/" title="Gadget" rel="tag">Gadget</a>, <a href="http://www.colinmcnamara.com/technology-tags/hardware-replacement/" title="hardware replacement" rel="tag">hardware replacement</a>, <a href="http://www.colinmcnamara.com/technology-tags/hp/" title="HP" rel="tag">HP</a>, <a href="http://www.colinmcnamara.com/technology-tags/ip-cameras/" title="ip cameras" rel="tag">ip cameras</a>, <a href="http://www.colinmcnamara.com/technology-tags/isr/" title="isr" rel="tag">isr</a>, <a href="http://www.colinmcnamara.com/technology-tags/legal/" title="legal" rel="tag">legal</a>, <a href="http://www.colinmcnamara.com/technology-tags/life-on-mars/" title="life on mars" rel="tag">life on mars</a>, <a href="http://www.colinmcnamara.com/technology-tags/linux/" title="linux" rel="tag">linux</a>, <a href="http://www.colinmcnamara.com/technology-tags/management-infrastructure/" title="management infrastructure" rel="tag">management infrastructure</a>, <a href="http://www.colinmcnamara.com/technology-tags/mars/" title="mars" rel="tag">mars</a>, <a href="http://www.colinmcnamara.com/technology-tags/mitiigation/" title="mitiigation" rel="tag">mitiigation</a>, <a href="http://www.colinmcnamara.com/technology-tags/network/" title="Network" rel="tag">Network</a>, <a href="http://www.colinmcnamara.com/technology-tags/network-storage/" title="network storage" rel="tag">network storage</a>, <a href="http://www.colinmcnamara.com/technology-tags/pic/" title="Pic" rel="tag">Pic</a>, <a href="http://www.colinmcnamara.com/technology-tags/power/" title="Power" rel="tag">Power</a>, <a href="http://www.colinmcnamara.com/technology-tags/router/" title="Router" rel="tag">Router</a>, <a href="http://www.colinmcnamara.com/technology-tags/security/" title="security" rel="tag">security</a>, <a href="http://www.colinmcnamara.com/technology-tags/security-environments/" title="security environments" rel="tag">security environments</a>, <a href="http://www.colinmcnamara.com/technology-tags/security-infrastructure/" title="security infrastructure" rel="tag">security infrastructure</a>, <a href="http://www.colinmcnamara.com/technology-tags/storage/" title="storage" rel="tag">storage</a>, <a href="http://www.colinmcnamara.com/technology-tags/storage-system/" title="storage system" rel="tag">storage system</a>, <a href="http://www.colinmcnamara.com/technology-tags/support-contract/" title="support contract" rel="tag">support contract</a>, <a href="http://www.colinmcnamara.com/technology-tags/surveillance-systems/" title="surveillance systems" rel="tag">surveillance systems</a>, <a href="http://www.colinmcnamara.com/technology-tags/switch/" title="switch" rel="tag">switch</a>, <a href="http://www.colinmcnamara.com/technology-tags/technology/" title="Technology" rel="tag">Technology</a>, <a href="http://www.colinmcnamara.com/technology-tags/threat/" title="threat" rel="tag">threat</a>, <a href="http://www.colinmcnamara.com/technology-tags/two-choices/" title="two choices" rel="tag">two choices</a>, <a href="http://www.colinmcnamara.com/technology-tags/video-encoding/" title="video encoding" rel="tag">video encoding</a>, <a href="http://www.colinmcnamara.com/technology-tags/video-management/" title="video management" rel="tag">video management</a>, <a href="http://www.colinmcnamara.com/technology-tags/video-streams/" title="video streams" rel="tag">video streams</a>, <a href="http://www.colinmcnamara.com/technology-tags/video-surveillance/" title="video surveillance" rel="tag">video surveillance</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.colinmcnamara.com/remote-site-security-cisco-analog-video-gateway-video-management-storage-system-network-modules-on-the-integrated-services-router-isr/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Zone based IOS firewalls</title>
		<link>http://www.colinmcnamara.com/zone-based-ios-firewalls/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=zone-based-ios-firewalls</link>
		<comments>http://www.colinmcnamara.com/zone-based-ios-firewalls/#comments</comments>
		<pubDate>Tue, 16 Oct 2007 01:19:00 +0000</pubDate>
		<dc:creator>colinmcnamara</dc:creator>
				<category><![CDATA[CCIE]]></category>
		<category><![CDATA[CISCO]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[C]]></category>
		<category><![CDATA[Colin]]></category>
		<category><![CDATA[DESIGN]]></category>
		<category><![CDATA[error]]></category>
		<category><![CDATA[NDA]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[packet]]></category>
		<category><![CDATA[Router]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[virtualization]]></category>

		<guid isPermaLink="false">http://www.colinmcnamara.com/2007/10/15/zone-based-ios-firewalls/</guid>
		<description><![CDATA[Zone based IOS firewalls Cisco has finally included zone based firewalling in the IOS firewall feature set. The configuration guide can be found here - Zone Based Firewall Design and Configuration Guide The things that really got me interested are - 1. It is VRF aware (works well with network virtualization strategies) 2. No more [...]<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/zone-based-ios-firewalls/">Zone based IOS firewalls</a></p>
]]></description>
			<content:encoded><![CDATA[<p>Zone based IOS firewalls</p>
<p>Cisco has finally included zone based firewalling in the IOS firewall feature set. The configuration guide can be found here -</p>
<p><a href="http://www.cisco.com/en/US/products/ps6350/products_feature_guide09186a008072c6e3.html#wp1061094">Zone Based Firewall Design and Configuration Guide</a></p>
<p>The things that really got me interested are -</p>
<p>1. It is VRF aware (works well with network virtualization strategies)<br />
2. No more CBAC&#8217;s<br />
3. Policing built into firewalling classes<br />
4. Content inspection including HTTP,P2P, and Instant Messenger</p>
<p>I think the biggest plus for this release is that IOS firewalls are finally following the general trend of zone based firewalling. By moving this way, configuration errors resulting in lax controls are likely to be minimized.</p>
<p>Excerpts from the documentation -</p>
<p>Cisco IOS Software Release 12.4(6)T introduced a new configuration model for the Cisco IOS Firewall feature set. This new configuration model offers intuitive policies for multiple-interface routers, increased granularity of firewall policy application, and a default deny-all policy that prohibits traffic between firewall zones until an explicit policy is applied to allow desirable traffic.</p>
<p>Nearly all firewall features implemented prior to Cisco IOS Software Release 12.4(6)T are supported in the new zone-based policy inspection interface; supported features are as follows:</p>
<p>•Stateful packet inspection</p>
<p>•Application inspection</p>
<p>–HTTP</p>
<p>–Post Office Protocol (POP3), Internet Mail Access Protocol (IMAP), Simple Mail Transfer Protocol/Enhanced Simple Mail Transfer Protocol (SMTP/ESMTP)</p>
<p>–Sun RPC</p>
<p>•VRF-aware Cisco IOS Firewall</p>
<p>•URL filtering</p>
<p>•Denial-of-service (DoS) mitigation</p>
<p>Zone-based policy firewall generally improves Cisco IOS performance for most firewall inspection activities.</p>
<p>The only Cisco IOS Firewall features that are not supported in zone-based policy firewall in Cisco IOS Software Release 12.4(6)T are as follows:</p>
<p>•Authentication proxy</p>
<p>•Stateful firewall failover</p>
<p>•Unified firewall MIB</p>
<p>Zone-based policy firewall completely changes the way you configure a Cisco IOS Firewall.</p>
<p>The first major change to the firewall configuration is the introduction of zone-based configuration. Cisco IOS Firewall is the first Cisco IOS Software threat defense feature to implement a zone configuration model. Other features might adopt the zone model over time. The classical Cisco IOS Firewall stateful inspection/context-based access control (CBAC) interface-based configuration model employing the ip inspect command set will be maintained for a period of time, but few, if any, new features will be configurable with the classical command-line interface (CLI). Zone-policy firewall does not use the stateful inspection/CBAC commands. The two configuration models can be used concurrently on routers but not combined on interfaces; an interface cannot be configured as a security zone member as well as being configured for ip inspect simultaneously.</p>
<p>Zones establish the security borders of your network. A zone defines a boundary where traffic is subjected to policy restrictions as it crosses to another region of your network. Zone-Policy Firewall&#8217;s default policy between zones is to deny all. If no policy is explicitly configured, all traffic moving between zones is blocked. This is a significant departure from stateful inspection&#8217;s model, in which traffic was implicitly allowed unless it was explicitly blocked with an access control list (ACL).</p>
<p>The second major change is the introduction of a new configuration policy language known as CPL. Users familiar with the Cisco IOS Software Modular quality-of-service (QoS) CLI (MQC) might recognize the format being similar to QoS&#8217;s use of class maps to specify which traffic will be affected by the action applied in a policy map.</p>
<p>Colin McNamara<br />
<a href="http://www.colinmcnamara.com" title="Copyright ©2008 | Colin McNamara | CCIE 18233 | All Rights Reserved">Copyright ©2008 | Colin McNamara | CCIE 18233 | All Rights Reserved&#8221;</a><strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.colinmcnamara.com/cisco-is-using-linux-virtualization-and-40-core-cpus-for-its-next-generation-routers/" rel="bookmark" title="March 10, 2008">Cisco is using Linux virtualization and 40 core CPU&#8217;s for its next generation routers</a></li>
<li><a href="http://www.colinmcnamara.com/41/" rel="bookmark" title="August 10, 2007">Cool new features in 12.4(15)T</a></li>
<li><a href="http://www.colinmcnamara.com/identity-aware-networking-using-cisco-trustsec/" rel="bookmark" title="February 23, 2008">Identity aware networking using Cisco TrustSec</a></li>
<li><a href="http://www.colinmcnamara.com/routers-can-email-you-when-they-go-down/" rel="bookmark" title="October 28, 2007">Routers can email you when they go down</a></li>
<li><a href="http://www.colinmcnamara.com/measuring-and-mitigating-risk-involved-with-sharing-virtual-infrastructure-between-dmz-and-internal-environments/" rel="bookmark" title="September 9, 2008">Measuring and mitigating risk involved with sharing virtual infrastructure between DMZ and Internal environments</a></li>
<li><a href="http://www.colinmcnamara.com/cisco-nx-os-40-next-generation-internet-operating-system/" rel="bookmark" title="January 29, 2008">Cisco NX-OS 4.0 | Next Generation Internet Operating System</a></li>
</ul>
<p><!-- Similar Posts took 39.498 ms --></p>
<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/zone-based-ios-firewalls/">Zone based IOS firewalls</a></p>

	Tags: <a href="http://www.colinmcnamara.com/technology-tags/c/" title="C" rel="tag">C</a>, <a href="http://www.colinmcnamara.com/technology-tags/ccie/" title="CCIE" rel="tag">CCIE</a>, <a href="http://www.colinmcnamara.com/technology-tags/cisco/" title="CISCO" rel="tag">CISCO</a>, <a href="http://www.colinmcnamara.com/technology-tags/colin/" title="Colin" rel="tag">Colin</a>, <a href="http://www.colinmcnamara.com/technology-tags/design/" title="DESIGN" rel="tag">DESIGN</a>, <a href="http://www.colinmcnamara.com/technology-tags/error/" title="error" rel="tag">error</a>, <a href="http://www.colinmcnamara.com/technology-tags/nda/" title="NDA" rel="tag">NDA</a>, <a href="http://www.colinmcnamara.com/technology-tags/network/" title="Network" rel="tag">Network</a>, <a href="http://www.colinmcnamara.com/technology-tags/packet/" title="packet" rel="tag">packet</a>, <a href="http://www.colinmcnamara.com/technology-tags/router/" title="Router" rel="tag">Router</a>, <a href="http://www.colinmcnamara.com/technology-tags/security/" title="security" rel="tag">security</a>, <a href="http://www.colinmcnamara.com/technology-tags/threat/" title="threat" rel="tag">threat</a>, <a href="http://www.colinmcnamara.com/technology-tags/virtualization/" title="virtualization" rel="tag">virtualization</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.colinmcnamara.com/zone-based-ios-firewalls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Book Review &#8211; Security Threat Mitigation and Response: Understanding Cisco Security MARS</title>
		<link>http://www.colinmcnamara.com/book-review-security-threat-mitigation-and-response-understanding-cisco-security-mars/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=book-review-security-threat-mitigation-and-response-understanding-cisco-security-mars</link>
		<comments>http://www.colinmcnamara.com/book-review-security-threat-mitigation-and-response-understanding-cisco-security-mars/#comments</comments>
		<pubDate>Wed, 15 Nov 2006 01:35:00 +0000</pubDate>
		<dc:creator>colinmcnamara</dc:creator>
				<category><![CDATA[book review]]></category>
		<category><![CDATA[CISCO]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[C]]></category>
		<category><![CDATA[CCIE]]></category>
		<category><![CDATA[cisco secure]]></category>
		<category><![CDATA[Colin]]></category>
		<category><![CDATA[DESIGN]]></category>
		<category><![CDATA[mars]]></category>
		<category><![CDATA[mitiigation]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Pic]]></category>
		<category><![CDATA[threat]]></category>

		<guid isPermaLink="false">http://www.colinmcnamara.com/2006/11/14/book-review-security-threat-mitigation-and-response-understanding-cisco-security-mars/</guid>
		<description><![CDATA[Book Review &#8211; Security Threat Mitigation and Response: Understanding Cisco Security MARS Security Threat Mitigation and Response: Understanding Cisco Security MARS by Dale Tesch, Greg Abelar Publisher: Cisco Press Pub Date: September 28, 2006 Print ISBN-10: 1-58705-260-1 Print ISBN-13: 978-1-58705-260-6 Pages: 408 This book had so much potential to be a great. Sadly it turned [...]<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/book-review-security-threat-mitigation-and-response-understanding-cisco-security-mars/">Book Review &#8211; Security Threat Mitigation and Response: Understanding Cisco Security MARS</a></p>
]]></description>
			<content:encoded><![CDATA[<p>Book Review &#8211; Security Threat Mitigation and Response: Understanding Cisco Security MARS</p>
<p><a href="http://www.amazon.com/gp/product/1587052601?ie=UTF8&#038;tag=314159265-20&#038;linkCode=as2&#038;camp=1789&#038;creative=9325&#038;creativeASIN=1587052601"><img border="0" src="41YPCDND8QL._SL160_.jpg"></a><img src="http://www.assoc-amazon.com/e/ir?t=314159265-20&#038;l=as2&#038;o=1&#038;a=1587052601" width="1" height="1" border="0" alt="" style="border:none !important; margin:0px !important;" /></p>
<p>Security Threat Mitigation and Response: Understanding Cisco Security MARS<br />
by Dale Tesch, Greg Abelar<br />
Publisher: Cisco Press<br />
Pub Date: September 28, 2006<br />
Print ISBN-10: 1-58705-260-1<br />
Print ISBN-13: 978-1-58705-260-6<br />
Pages: 408</p>
<p>This book had so much potential to be a great. Sadly it turned out to be an overgrown technical manual. The author does try to lighten things up by interspersing real world technical details throughout the book, however he could have just written a &#8220;hacks&#8221; style book with that material and been much better off.</p>
<p>This book is organized into four major divisions. The first, Security threat identification and response challenge reviews basic security theory and response. A network engineer breaking into security may find this interesting. Anyone else can just skip over this chapter.</p>
<p>I actually found the second, CS-MARS theory and operation to be the most useful. The author laid out a pretty good flowchart of the designing process used to process alerts. He also hinted out the back end architecture supporting the device.</p>
<p>The third section, CS-MARS operation was just blatantly lifted from the users guide. The only difference is that the online users guide is organized a little more clearly. I recommend skipping this chapter and going straight to the on-line documentation, you will be much happier.</p>
<p>The fourth section, CS-MARS in action had great potential, however the author just stuck in some really salesy usage scenarios. I can&#8217;t reinforce this enough &#8211; This needs to be updated. I have been to customer talks where users presented how the MARS box has made their life easier in many ways. The stories presented here do a disservice to the product, and do not highlight the core differentiators that this product offers.</p>
<p>Would I recommend this book? Yes and No. I would recommend that entry level engineers with no security experience, and business users pick this up. Other then that, log onto CCO and just read through the docs. You will learn more in less time. And as a plus, you will have $50 sitting in your wallet still.</p>
<p>Colin McNamara<br />
<a title="Copyright ©2008 | Colin McNamara | CCIE 18233 | All Rights Reserved" href="http://www.colinmcnamara.com">Copyright ©2008 | Colin McNamara | CCIE 18233 | All Rights Reserved&#8221;</a></p>
<p class="blogger-post-footer">Colin McNamara<br />
CCIE #18233</p>
<p>http://www.2cups.com</p>
<p>&#8220;The difficult we do immediately, the impossible just takes a little longer.&#8221;</p>
<p><strong>Similar Posts:</strong>
<ul class="similar-posts">
<li><a href="http://www.colinmcnamara.com/rss-feeds-an-intranet-aggregation-solution/" rel="bookmark" title="June 26, 2005">RSS feeds &#8211; an intranet aggregation solution?</a></li>
<li><a href="http://www.colinmcnamara.com/measuring-and-mitigating-risk-involved-with-sharing-virtual-infrastructure-between-dmz-and-internal-environments/" rel="bookmark" title="September 9, 2008">Measuring and mitigating risk involved with sharing virtual infrastructure between DMZ and Internal environments</a></li>
<li><a href="http://www.colinmcnamara.com/remote-site-security-cisco-analog-video-gateway-video-management-storage-system-network-modules-on-the-integrated-services-router-isr/" rel="bookmark" title="June 10, 2008">Simplifying remote site security with Cisco&#8217;s new video surveillance modules on the ISR</a></li>
<li><a href="http://www.colinmcnamara.com/28/" rel="bookmark" title="November 22, 2006">What should I do this thanksgiving break?</a></li>
<li><a href="http://www.colinmcnamara.com/41/" rel="bookmark" title="August 10, 2007">Cool new features in 12.4(15)T</a></li>
<li><a href="http://www.colinmcnamara.com/altor-virtual-network-security-analyzer-vnsa-integrated-with-ciscos-nexus-1000v-for-vmware/" rel="bookmark" title="September 17, 2008">Altor Virtual Network Security Analyzer (VNSA) integrated with Cisco&#8217;s Nexus 1000v for VMware</a></li>
</ul>
<p><!-- Similar Posts took 37.810 ms --></p>
<p>--Colin McNamara
<br/><br/><a href="http://www.colinmcnamara.com/book-review-security-threat-mitigation-and-response-understanding-cisco-security-mars/">Book Review &#8211; Security Threat Mitigation and Response: Understanding Cisco Security MARS</a></p>

	Tags: <a href="http://www.colinmcnamara.com/technology-tags/blog/" title="blog" rel="tag">blog</a>, <a href="http://www.colinmcnamara.com/technology-tags/c/" title="C" rel="tag">C</a>, <a href="http://www.colinmcnamara.com/technology-tags/ccie/" title="CCIE" rel="tag">CCIE</a>, <a href="http://www.colinmcnamara.com/technology-tags/cisco/" title="CISCO" rel="tag">CISCO</a>, <a href="http://www.colinmcnamara.com/technology-tags/cisco-secure/" title="cisco secure" rel="tag">cisco secure</a>, <a href="http://www.colinmcnamara.com/technology-tags/colin/" title="Colin" rel="tag">Colin</a>, <a href="http://www.colinmcnamara.com/technology-tags/design/" title="DESIGN" rel="tag">DESIGN</a>, <a href="http://www.colinmcnamara.com/technology-tags/mars/" title="mars" rel="tag">mars</a>, <a href="http://www.colinmcnamara.com/technology-tags/mitiigation/" title="mitiigation" rel="tag">mitiigation</a>, <a href="http://www.colinmcnamara.com/technology-tags/network/" title="Network" rel="tag">Network</a>, <a href="http://www.colinmcnamara.com/technology-tags/pic/" title="Pic" rel="tag">Pic</a>, <a href="http://www.colinmcnamara.com/technology-tags/security/" title="security" rel="tag">security</a>, <a href="http://www.colinmcnamara.com/technology-tags/threat/" title="threat" rel="tag">threat</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.colinmcnamara.com/book-review-security-threat-mitigation-and-response-understanding-cisco-security-mars/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

