Tuesday, 16 June 2009

Cisco Nonstop Forwarding for EIGRP

OVERVIEW

Cisco Nonstop Forwarding (NSF) with Stateful Switchover (SSO) is a Cisco innovation for routers with dual route processors. Cisco NSF with SSO allows a router, which has experienced a hardware or software failure of an active route processor, to maintain data link layer connections and continue forwarding packets during the switchover to the Standby route processor. This forwarding can continue despite the loss of routing protocol peering arrangements with other routers. Routing information is recovered dynamically, in the background, while packet forwarding proceeds uninterrupted.

Service Provider environments can benefit from the initial release of Cisco NSF with SSO in Cisco IOS® Software Release 12.0(22)S. It includes support for the Border Gateway Protocol (BGP), Open Shortest Path First (OSPF) and Intermediate System-Intermediate System (IS-IS) routing protocols. However, as Cisco NSF with SSO is ported to more traditional Enterprise platforms, such as the Cisco Catalyst 6500 Series Switch, there is a corresponding requirement to support the Enhanced Interior Gateway Routing Protocol (EIGRP).

There are two components of Cisco NSF for EIGRP:




  • NSF-capability: re-startable EIGRP component that is run by a router and supports dual route processors. Cisco NSF for EIGRP is available in Cisco IOS Software Release 12.2(18)S for the Cisco 7500 Series Router and in Release12.2(18)SXD for the Cisco Catalyst® 6500 Series Switch. This functionality may also be available in other platform-specific software releases for other Cisco dual route processor devices.


  • NSF-awareness: compatible components that run on the neighbors of the restarting router and help the restarting router reacquire its routing information. Available in Cisco IOS Software Release 12.2(15)T.


TECHNICAL DETAILS
Internally, a Cisco router equipped with dual route processors can maintain Layer 2 data link connections and up-to-date "next-hop" information to continue forwarding packets in the event of a route processor switchover.



However, all of these innovations would be for naught if routers that are neighbors with the router performing the switchover (hereafter, the neighbor routers) did not continue to forward packets to that router. In order for a neighbor router to continue packet forwarding, several conditions must be met:





  • Restarting routers and their neighbor routers must each support the appropriate EIGRP extensions.


  • Neighbor routers must not prematurely declare the restarting router as unavailable.


  • Neighbor routers must not communicate any state change in the restarting router to any of its own neighbors. This avoids the significant detrimental effect on network performance associated with the failure of a router.


  • Restarting router must signal its neighbors that it has restarted.


  • Neighbor routers must send EIGRP topology updates to help the restarting NSF router reacquire its EIGRP Topology Database.


  • Neighbor routers must signal the completion of the initial routing update by sending the End-of-Table marker.


  • In the interim (before the restarting router has reacquired the routing information), the neighbor routers must mark any routes associated with the restarting router as "stale", but continue to use those routes for packet forwarding.


To accomplish these conditions, some enhancements were made to EIGRP. A new bit-the Restart bit-was introduced in the EIGRP UPDATE and HELLO packets. In addition, an End-of-Table (EOT) signal was introduced, so that neighbor routers could tell a restarting router when it had completed sending its updates. The EOT allows the restarting router to begin topology and route calculation as quickly as possible, and speeds convergence. Figure 1 illustrates the process that occurs when an EIGRP/NSF capable router restarts.

Figure 1. Restart of an EIGRP/NSF Capable Router



As quickly as possible after switching over to its redundant route processor, the restarting router will send out an empty update packet with both the INIT and RESTART (RS) bits set. This notifies neighbors of the restarting router that a restart has occurred, and that their assistance will be required to refresh the routing database of the restarting router.

During this process, the restarting router may also send HELLO packets, in order to maintain neighbor adjacency. These HELLO packets will also have the RS bit set.

Upon receiving the INIT and RS, the neighbors of the restarting router will acknowledge the update while realizing that the restarting router has restarted. As such, the restarting router will have no routing information, and will need to reacquire it. Each neighbor of the restarting router will begin sending updates containing routing information. In its last update, each neighbor will set an EOT signal so the restarting router knows that it has all available information and may begin the process of calculating routes.

At this point, the restarting router exits "receive-only mode" and performs a Diffusing Update Algorithm (DUAL) calculation to select the best loop-free routes for each destination in the topology database. Once the DUAL calculation is complete, the restarting router will send updates to each of its neighbors regarding routing destinations accessible through it. Once all updates have been sent and acknowledged, convergence is complete.

Once convergence is complete, the restarting router will clear the RS bit in its HELLO packets, and network operation will continue as normal.

Note that the restarting router and all of its neighbors have continued to forward packets throughout this entire operation.

DEPLOYMENT CONSIDERATIONS
The primary deployment scenario for EIGRP/NSF is in single-point-of-failure routers. A good example of a single-point-of-failure router is an Enterprise WAN edge router that has no redundant multi-homed path to particular destinations.

EIGRP/NSF can also be deployed in multi-homed environments or on the Enterprise Distribution or Core layers. Note one important caveat for this type of deployment: Cisco NSF maintains the capability of forwarding packets by "freezing" the Cisco Express Forwarding table at the point where the RP switchover occurs. Forwarding occurs to the last-known-good next-hop for any particular IP destination. Therefore, if a routing topology change occurs prior to the restarting router reacquiring the most recent routing information, then transient routing loops, asymmetrical routing, or routing "black holes" may occur.

The following points mitigate this caveat:

  • NSF must be compared to its alternative: the complete reset of a router, which can also result in routing loops, asymmetrical routing, or routing "black holes".
  • In most network designs, asymmetrical routing is the most common occurrence. While this is usually undesirable, it does not prohibit packets from reaching their ultimate destination.
  • Depending on what topology change occurs, only a small portion of the traffic may be subject to routing loops or black holes. Other traffic continues to flow to its appropriate destinations.
  • NSF is a self-correcting protocol. Routing loops or black holes disappear after convergence. In addition, EIGRP converges very quickly, so any routing problems will be shortly resolved.

CONCLUSION
Cisco Nonstop Forwarding for EIGRP can significantly reduce downtime on Enterprise networks during a failure on a route processor. Provided that careful attention is dedicated to the potential deployment scenarios, and that due diligence is accorded the potential caveats when incorporating NSF into the overall network design, users can achieve unprecedented levels of network availability.

Virtualization

Virtualization has rapidly become the hottest technology in IT, driven largely by trends such as server consolidation, green computing and the desire to cut desktop costs and manage IT complexity. While these issues are important, the rise of virtualization as a mainstream technology is having a far more profound impact on IT beyond just saving a few dollars in the data centre. The benefits and impact of virtualization on the business will be directly correlated to the strength of an organization’s application delivery infrastructure. Application delivery is the key to unlocking the power of virtualization, and organizations that embrace virtualization wrapped around application delivery will thrive and prosper, while those that do not will flounder. As virtualization takes centre stage, shifting roles in IT will require a new breed of professionals with broader skill sets to bridge IT silos and optimize business processes around the delivery of applications.
Going mainstream
We are moving into a new era where virtualization will permeate every aspect of computing. Every processor, server, application and desktop will have virtualization capabilities built into its core. This will give IT a far more flexible infrastructure where the components of computing become dynamic building blocks that can be connected and reassembled on the fl y in response to changing business needs. In fact, three years from now, we will no longer be talking about virtualization as the next frontier in enterprise technology. It will simply be assumed. For example, today we normally assume that our friends, family and neighbours have high-speed Internet access from their homes. This was not the case a few years ago, when many were using sluggish dialup lines to access the Internet or had no access at all. High-speed Internet is now in mainstream, as it will be for virtualization. Virtualization will be expected; it will be a given within the enterprise. As this occurs, the conversation within IT circles will shift from the question of how to virtualize everything to the question of what business problems can be solved now that everything is virtualized.
Virtualization and application delivery
The most profound impact of virtualization will be in the way organizations deliver applications and desktops to end users. In many ways, applications represent the closest intersection between IT and the business. Your organization’s business is increasingly represented by the quality of its user facing applications. Whether large ERP solutions, custom web applications, e-mail, e-commerce, client-server applications or SOA, your success in IT today depends on ensuring that these applications meet the business goals. Unfortunately, trends such as mobility, globalization, offshoring, and e-commerce are moving users further away from headquarters, while issues like data centre consolidation, security and regulatory compliance are making applications less accessible to users.
These opposing forces are pushing the topic of application delivery into the limelight. It is forcing IT executives to consider how their infrastructures get mission-critical, data centre-based applications out to users to lower costs, reduce risk and improve IT agility. Virtualization is now the key to application delivery. Today’s leading companies are employing virtualization technology to connect users and applications to propel their businesses forward.
Virtualization in the enterprise
The seeds of virtualization were first planted over a decade ago, as enterprises began applying mainframe virtualization techniques to deliver Windows applications more efficiently with products such as Citrix® Presentation Server™. These solutions enabled IT to consolidate corporate applications and data centrally, while allowing users the freedom to operate from any location and on any network or device, where only screen displays, keyboard entry and mouse movement traversed the network. Today, products like Citrix® XenApp™ (the successor to Presentation Server) allow companies to create single master stores of all Windows application clients in the data centre and virtualize them either on the server or at the point of the end user. Application streaming technology within Citrix XenApp allows Windows-based applications to be cached locally in an isolation environment, rather than to be installed on the device. This approach improves security and saves companies millions of dollars when compared to traditional application installation and management methods.
Virtualization is also impacting the back end data and logic tier of applications with data centre products such as Citrix® XenServer™ and VMware ESX that virtualize application workloads on data centre servers. While these products are largely being deployed to reduce the number of physical servers in the data centres, the more strategic impact will be found in their ability to dynamically provision and shift application workloads on the fl y to meet end user requirements. The third major area concerning the impact of virtualization will be the corporate desktop, enabled by products such as Citrix® XenDesktop™. The benefits of such solutions include cost savings, but they also enable organizations to simplify how desktops are delivered to end users in a way that dramatically improves security and the end user experience (compared to traditional PC desktops). From virtualized servers in the data centres to virtualized end users desktops, the biggest impact of virtualization in the enterprise will be found within an organization’s application delivery infrastructure
Seeing the big picture
The mass adoption of virtualization technology will certainly require new skills, roles and areas of expertise within organizations and IT departments. Yet the real impact of virtualization will not hinge on the proper acquisition of new technical skills. Rather, by making the most of the virtualization opportunity, organizations will have to focus on breaking down traditional IT silos and adopt end-to-end virtualization strategies. Most IT departments today are organized primarily around technology silos. In many organizations, we find highly technical employees who operate on separate IT “islands,” such as servers, networks, security and desktops. Each group focuses on the health and well-being of its island, making sure that it runs with efficiency and precision. Unfortunately, this stand-alone approach is debilitating IT responsiveness, causing pundits like bestselling author Nicholas Carr to ask whether IT even matters to business anymore. To break this destructive cycle, IT employees must take responsibility for understanding and owning business processes that are focused horizontally (from the point of origin in the data centre all the way to the end users they are serving), building bridges from island to island. IT roles will increasingly require a wider, more comprehensive portfolio of expertise around servers, networking, security and systems management. IT personnel will need to have a broad understanding of all these technologies and how they work together as the focus on IT specialization gives way to a more holistic IT mindset.
Seeking experts in delivery
The new IT roles will require an expertise in delivery. IT will need to know how to use a company’s delivery infrastructure to quickly respond to new requirements coming from business owners and end users alike. IT specialization will not completely disappear, but it will not look anything like the silo entrenchment and technical specialization we see today. From this point forward, IT professionals will increasingly be organized around business process optimization to serve end users and line of business owners, rather than around independent technologies sitting in relative isolation. Across the board, the primary organizing principle in IT will shift from grouping people around technology silos to organizing them around common delivery processes. The companies that make this transition successfully will thrive, while those that do not will struggle to compete in an increasingly demanding and dynamic business world. IT organizations of the future will need to develop professionals who can see the parts as a whole and continually assess the overall health of the delivery system, responding quickly to changing business requirements. Employee work groups will continue to form around common processes, but the focus will be less about highly specialized knowledge and more about the efficiency of frequently repeated processes. IT professionals who understand the deep technical intricacies of IP network design, for example, will be in less demand than those who understand best practices in application delivery.

Guidelines for Staying in and Ahead of the Game
If you are not testing the waters of virtualization, you may already be behind. Experiment with virtualization now. Acquire applications and consider how to deliver them as part of your IT strategy. Three key recommendations are: n Change the mindset of your IT organization to focus on delivery of applications rather than installing or deploying them. Think about “delivery centres” rather than data centres. Most IT organizations today continue to deploy and install applications, although industry analysts advise that traditional application deployment is too complex, too static and costs too much to maintain, let alone to try to keep up with changes in the business. Delivering on the vision of an IT organization that is aligned with business goals requires an end-to-end strategy of efficiently delivering business applications to users.
  • Place a premium on knowledge of applications and business processes when hiring and training IT employees. IT will always be about technology, but do not perpetuate today’s “island” problem by continuing to hire and train around deep technical expertise in a given silo. If that happens, IT will continue to foster biased mindsets that perceive the world through a technologically biased silo lens, the opposite of what is needed today. IT leaders will increasingly need to be people who understand business processes. Like today’s automotive technicians, they will have to be able to view and optimize the overall health of the system, not the underlying gears and valves - or bits and bytes.
  • Select strategic infrastructure vendors who specialize in application delivery. Industry experts agree that the time is right to make the move from static application deployment to dynamic application delivery. IT will continue to use vendors that specialize in technical solutions that fit into various areas, such as networking, security, management and even virtualization. What is important, however, is forming a strategic relationship with a vendor that focuses not on technology silos, but on application delivery solutions. The vendor should be able to supply integrated solutions to incorporate virtualization, optimization and delivery systems that inherently work with one another, as well as the rest of your IT environment.

Virtualization is Changing the way IT Delivers Applications

Virtualization has rapidly become the hottest technology in IT, driven largely by trends such as server consolidation, green computing and the desire to cut desktop costs and manage IT complexity. While these issues are important, the rise of virtualization as a mainstream technology is having a far more profound impact on IT beyond just saving a few dollars in the data centre. The benefits and impact of virtualization on the business will be directly correlated to the strength of an organization’s application delivery infrastructure. Application delivery is the key to unlocking the power of virtualization, and organizations that embrace virtualization wrapped around application delivery will thrive and prosper, while those that do not will flounder. As virtualization takes centre stage, shifting roles in IT will require a new breed of professionals with broader skill sets to bridge IT silos and optimize business processes around the delivery of applications.

Going Mainstream
We are moving into a new era where virtualization will permeate every aspect of computing. Every processor, server, application and desktop will have virtualization capabilities built into its core. This will give IT a far more flexible infrastructure where the components of computing become dynamic building blocks that can be connected and reassembled on the fl y in response to changing business needs. In fact, three years from now, we will no longer be talking about virtualization as the next frontier in enterprise technology. It will simply be assumed. For example, today we normally assume that our friends, family and neighbours have high-speed Internet access from their homes. This was not the case a few years ago, when many were using sluggish dialup lines to access the Internet or had no access at all. High-speed Internet is now in mainstream, as it will be for virtualization. Virtualization will be expected; it will be a given within the enterprise. As this occurs, the conversation within IT circles will shift from the question of how to virtualize everything to the question of what business problems can be solved now that everything is virtualized.

Virtualization and Application Delivery
The most profound impact of virtualization will be in the way organizations deliver applications and desktops to end users. In many ways, applications represent the closest intersection between IT and the business. Your organization’s business is increasingly represented by the quality of its user facing applications. Whether large ERP solutions, custom web applications, e-mail, e-commerce, client-server applications or SOA, your success in IT today depends on ensuring that these applications meet the business goals. Unfortunately, trends such as mobility, globalization, offshoring, and e-commerce are moving users further away from headquarters, while issues like data centre consolidation, security and regulatory compliance are making applications less accessible to users.
These opposing forces are pushing the topic of application delivery into the limelight. It is forcing IT executives to consider how their infrastructures get mission-critical, data centre-based applications out to users to lower costs, reduce risk and improve IT agility. Virtualization is now the key to application delivery. Today’s leading companies are employing virtualization technology to connect users and applications to propel their businesses forward.

Virtualization in the Enterprise
The seeds of virtualization were first planted over a decade ago, as enterprises began applying mainframe virtualization techniques to deliver Windows applications more efficiently with products such as Citrix® Presentation Server™. These solutions enabled IT to consolidate corporate applications and data centrally, while allowing users the freedom to operate from any location and on any network or device, where only screen displays, keyboard entry and mouse movement traversed the network. Today, products like Citrix® XenApp™ (the successor to Presentation Server) allow companies to create single master stores of all Windows application clients in the data centre and virtualize them either on the server or at the point of the end user. Application streaming technology within Citrix XenApp allows Windows-based applications to be cached locally in an isolation environment, rather than to be installed on the device. This approach improves security and saves companies millions of dollars when compared to traditional application installation and management methods.
Virtualization is also impacting the back end data and logic tier of applications with data centre products such as Citrix® XenServer™ and VMware ESX that virtualize application workloads on data centre servers. While these products are largely being deployed to reduce the number of physical servers in the data centres, the more strategic impact will be found in their ability to dynamically provision and shift application workloads on the fl y to meet end user requirements. The third major area concerning the impact of virtualization will be the corporate desktop, enabled by products such as Citrix® XenDesktop™. The benefits of such solutions include cost savings, but they also enable organizations to simplify how desktops are delivered to end users in a way that dramatically improves security and the end user experience (compared to traditional PC desktops). From virtualized servers in the data centres to virtualized end users desktops, the biggest impact of virtualization in the enterprise will be found within an organization’s application delivery infrastructure

Seeing the Big Picture
The mass adoption of virtualization technology will certainly require new skills, roles and areas of expertise within organizations and IT departments. Yet the real impact of virtualization will not hinge on the proper acquisition of new technical skills. Rather, by making the most of the virtualization opportunity, organizations will have to focus on breaking down traditional IT silos and adopt end-to-end virtualization strategies. Most IT departments today are organized primarily around technology silos. In many organizations, we find highly technical employees who operate on separate IT “islands,” such as servers, networks, security and desktops. Each group focuses on the health and well-being of its island, making sure that it runs with efficiency and precision. Unfortunately, this stand-alone approach is debilitating IT responsiveness, causing pundits like bestselling author Nicholas Carr to ask whether IT even matters to business anymore. To break this destructive cycle, IT employees must take responsibility for understanding and owning business processes that are focused horizontally (from the point of origin in the data centre all the way to the end users they are serving), building bridges from island to island. IT roles will increasingly require a wider, more comprehensive portfolio of expertise around servers, networking, security and systems management. IT personnel will need to have a broad understanding of all these technologies and how they work together as the focus on IT specialization gives way to a more holistic IT mindset.

Seeking Experts in Delivery
The new IT roles will require an expertise in delivery. IT will need to know how to use a company’s delivery infrastructure to quickly respond to new requirements coming from business owners and end users alike. IT specialization will not completely disappear, but it will not look anything like the silo entrenchment and technical specialization we see today. From this point forward, IT professionals will increasingly be organized around business process optimization to serve end users and line of business owners, rather than around independent technologies sitting in relative isolation. Across the board, the primary organizing principle in IT will shift from grouping people around technology silos to organizing them around common delivery processes. The companies that make this transition successfully will thrive, while those that do not will struggle to compete in an increasingly demanding and dynamic business world. IT organizations of the future will need to develop professionals who can see the parts as a whole and continually assess the overall health of the delivery system, responding quickly to changing business requirements. Employee work groups will continue to form around common processes, but the focus will be less about highly specialized knowledge and more about the efficiency of frequently repeated processes. IT professionals who understand the deep technical intricacies of IP network design, for example, will be in less demand than those who understand best practices in application delivery.

Guidelines for Staying in and Ahead of the Game
If you are not testing the waters of virtualization, you may already be behind. Experiment with virtualization now. Acquire applications and consider how to deliver them as part of your IT strategy. Three key recommendations are: n Change the mindset of your IT organization to focus on delivery of applications rather than installing or deploying them. Think about “delivery centres” rather than data centres. Most IT organizations today continue to deploy and install applications, although industry analysts advise that traditional application deployment is too complex, too static and costs too much to maintain, let alone to try to keep up with changes in the business. Delivering on the vision of an IT organization that is aligned with business goals requires an end-to-end strategy of efficiently delivering business applications to users.
  • Place a premium on knowledge of applications and business processes when hiring and training IT employees. IT will always be about technology, but do not perpetuate today’s “island” problem by continuing to hire and train around deep technical expertise in a given silo. If that happens, IT will continue to foster biased mindsets that perceive the world through a technologically biased silo lens, the opposite of what is needed today. IT leaders will increasingly need to be people who understand business processes. Like today’s automotive technicians, they will have to be able to view and optimize the overall health of the system, not the underlying gears and valves - or bits and bytes.
  • Select strategic infrastructure vendors who specialize in application delivery. Industry experts agree that the time is right to make the move from static application deployment to dynamic application delivery. IT will continue to use vendors that specialize in technical solutions that fit into various areas, such as networking, security, management and even virtualization. What is important, however, is forming a strategic relationship with a vendor that focuses not on technology silos, but on application delivery solutions. The vendor should be able to supply integrated solutions to incorporate virtualization, optimization and delivery systems that inherently work with one another, as well as the rest of your IT environment.

Monday, 15 June 2009

Why Firewall?

Firewalls are usually seen as a requirement if you are going to attach your network to other networks, especially the Internet. Unfortunately, some network administrators and managers do not understand the strengths a firewall can offer, resulting in poor product choice, deployment, configuration and management. Like any security technology, firewalls are only effective if the implementation is done properly and there is proper maintenance and response to security events.

Additionally, with the proper deployment of firewalls other security strategies are often much easier to integrate, such as VPNs and IDS systems. So what makes firewalls good, and what can you do to ensure they are used properly?

Perimeter
One of firewalls' weaknesses is also one of their strengths. Firewalls are typically deployed as a perimeter defence, usually intersecting network links that connect your network to others. If the firewall is properly deployed on all paths into your network, you can control what enters and leaves your network.

Of course, as with any form of perimeter defence, if an attack is launched from inside, firewalls are not too effective. However, this deployment on your network perimeter allows you to prevent certain kinds of data from entering your network, such as scans and probes, or even malicious attacks against services you run.

Conversely, it allows you to restrict outbound information. It would be nearly impossible to configure every workstation to disallow IRC, but blocking ports 6667-7000 (the most common IRC ports) is relatively easy on your perimeter firewalls.

While you can employ access control lists on servers internally, this still allows attackers to scan them, and possibly talk to the network portion of the OS on the server — making a number of attacks possible. This perimeter also allows you to deploy IDS systems much more easily, since "chokepoints" will have already been created, and you can monitor all data coming in or leaving.

VPN deployment also becomes easy. Instead of loading up VPN software on every desktop that might need it, you can simply employ VPN servers at those network access points, either as separate servers or directly on your firewall, which is becoming increasingly popular.

Concentrated Security
Controlling one, or even multiple firewalls is a much easier job than maintaining access control lists on numerous separate internal servers that are probably not all running the same operating system or services. With firewalls you can simply block all inbound mail access except for the official mail server. If someone forgets to disable email server software on a newly installed server, you do not need to worry about an external attacker connecting to it and exploiting any flaws.

Most modern firewall products are administered from a central console. You get an overall view of your network and can block or allow services as needed very quickly and efficiently.

With VPN-capable firewalls you can easily specify that access to certain networks must be done via encrypted tunnels, or otherwise blocked. With VPN software on each client, you would have more to worry about with misconfiguration or user interference. This results in sensitive data being accidentally sent out unencrypted. If your firewall is set up to block all but a few specific outbound services, then no matter what a user does - even to bring in their own laptop - they will probably not be able to access the blocked services. Enforcing this without firewalls and instead on each client machine is nearly impossible.

Enforcement of Security Policies
You may have a set of corporate guidelines for network usage that include such items as:

  1. Chat clients such as IRC, AIM, and Yahoo IM are strictly forbidden, as they can transfer files.
  2. Accessing external mail servers is forbidden (antivirus policy); only use the internal server to send or receive.
  3. Network games, such as Doom or Quake, are forbidden, except between 8 a.m. and 6 p.m. all weekdays for members of management.
  4. Websites such as playboy.com are forbidden for legal reasons.

Enforcing the first policy without a firewall would be possible, but difficult. In theory, if you managed to secure every single desktop machine and prevent users from installing software, it would be possible. Then you would need to prevent people from attaching "rogue" laptops and so forth to the internal LAN with software preinstalled. While possible, this is a Herculean task compared to configuring a dozen rules (or even a hundred rules) on your firewalls to prevent access to the ports and servers that IRC, AIM and the rest use.

The second policy would be very difficult to enforce without a firewall. You would need to do the above steps to prevent people from installing their own email software or using rogue machines such as laptops with it preinstalled. Moreover, any email software you do use (such as Outlook or Eudora) would need to be configured so that users could not modify any preferences, add new accounts and so on. This is not possible in almost all email clients.

The third policy is virtually impossible to enforce without a firewall. You would need to take the above steps to prevent any user except for management installing the software. One possibility would be to place the software on a network share and only make it available from 6 p.m. to 8 a.m., and on weekends to users of the management group. However, many network games would not function properly, and you would have to prevent the software from being copied off, etc.

Even with all this, the software may still continue to function after 8 a.m. if it is running on the client machine (or it might crash horribly). In any event, this is much easier to enforce with a firewall such as FW-1: enable user authentication, then define a policy that allows users of the management group access to the ports used by these games at the appropriate times.

Enforcing policy number four is basically impossible as well without a firewall. While some Web clients do allow you to list sites that are off limits, keeping the browsers on multiple workstations up to date would be a virtually impossible task. Compare that with configuring the firewall to force WWW access through an application-level.

A Secure Network Is a Healthy Network
Generally speaking, any security implementation done in a network will help with its overall health. Cataloguing systems and software versions to decide what needs upgrading first, implementing automated software upgrade procedures, and so on all helps with the overall health of your network and its systems.

A network configuration that creates chokepoints for firewall deployment also means you can easily implement a DMZ, a zone with servers to handle inbound and outbound information with the public. These servers can typically run a hardened and stripped down OS and application software. A proxy email server, for example, only needs to be able to accept and send email. There is no need for user accounts, POP or IMAP services, or GroupWare software integration.

Usually the simpler a system is, the easier it is to secure, and hence the harder it is for an attacker to break into. Securing a messy network is almost impossible. You must find out what you have, which versions, where the servers are deployed, what network links exist, and so on.

Kurt Seifried.
Security Analyst & the author of the Linux Administrators Security Guide.

Tuesday, 9 June 2009

Technology Consulting

Keeping current with new technology is a task in itself. organisations are undergoing enormous challenges in creating and evolving an IT framework that would help leverage IT to serve customers better. When and where to invest in technology and staffing issues, security are just a drop in the ocean of challenges. Experience is crucial to understand these challenges that an organisation is experiencing.

Eon Networks consulting services cover a spectrum of IT infrastructure related services from systems audit to call centers. We have demonstrated capability to provide effective solutions to key customers in many verticals. With over a decade of experience, Eon Networks is armed with the necessary expertise and know-how to capture your business's unique needs and help adapting your organisation to the rapid technological advancements.

Pre-sales consultancy is crucial as it helps in selecting the right products and technologies before investing. It plays important role in infrastructure building.Our experts have a range of solutions meeting the clients' requirements and budget.

Monday, 8 June 2009

Eon Network achieves its 100th Enterprise/SMB customer

Eon Networks Pvt Ltd, a leading provider of IT Infrastructure solutions and services to domestic customers, today announced its milestone in achieving its 100th Enterprise/SMB customer in a short span of 1 Year since the inception of Eon Networks. In the face of fierce competition Eon Networks has shown a tremendous growth rate and exceeded the objectives set for its first year. Eon Networks has achieved the feat due to the level of commitment, service, efficient technical team, good hands on exposure on latest technologies, well defined support & delivery mechanism and its competitive pricing policy.

We boast of our Alliance portfolio with the top-tier technology providers like Cisco, D-Link, 3Com, IBM, HP, Microsoft, Symantec, Trend, McAfee, Checkpoint, Cyberoam & SonicWall. Our unique solution-based methodology has enabled us to effectively address the business needs of our clients, optimize the returns on their IT investments, mitigate risk, and focus on growth and profitability.

The vast range of technology solutions which we have provided to our clients in such a short span of time ranges from providing Network Security, Storage, Routing & Switching, and Wireless Network across various verticals like Enterprise & SMBs in the IT, ITES, Construction, Educational, Financial & Consultancy industries.

Here is a list of our selected clientele across various verticals:
ITES:
Data world and Rapid process solution.
Government: Delhi Electricity Regulatory Commission and Employees Saving and Insurance Corporation.
Insurance: Bajaj Capital.
Educational Institutions: BRCM college of Engineering and Technology and International College of Financial Planning.
Manufacturing: Hindustan Glass and Orient Tiles.
Telecom: Airtel.

Eon Networks specializes in delivering complex network solutions that leverage our technical expertise, extensive experience and broad services offering. Our consultative approach includes a comprehensive delivery methodology and relentless focus on complete customer satisfaction. Our clients trust us to plan, build, and operate their secure converged networks providing them with considerable competitive advantage.

We deliver business driven technology solutions that enable our clients to gain competitive advantage, make their business more responsive to market opportunities and threats, improve productivity and reduce information technology costs.

Eon Networks also takes this opportunity to announce inclusion of some more services in its portfolio like Backup and Data Management so as to be a single interface for its customer for all their IT related .

Friday, 5 June 2009

Cyberoam CR100ia - Comprehensive Network Security for Small and Remote

Cyberoam UTM

Cyberoam CR100ia is an identity-based security appliance that delivers real-time network protection against evolving Internet threats to small and medium enterprises (SMEs) through unique user based policies. CR100ia delivers comprehensive protection from malware, virus, spam, phishing, pharming and more. Its unique identity-based security protects users from internal threats that lead to data leakage. Cyberoam features include Stateful Inspection Firewall, VPN (SSL VPN & IPSec), Gateway Anti-Virus and Anti-Spyware, Gateway Anti-Spam, IPS, Content Filtering, Bandwidth Management, Multiple Link Management and can be centrally managed with Cyberoam Central Console.

Identity-based Security inUTM
Cyberoam attaches the user identity to security, taking enterprises a step ahead of conventional solutions that bind security to IP-addresses. Cyberoam's identity-based security offers full business flexibility while ensuring complete security in any environment, including DHCP and Wi-Fi, by identifying individual users within the network-whether they are victims or attackers.

Features

DescriptionBenefits
Stateful Inspection Firewall
(ICSA Labs Certified
)
  • Powerful stateful and deep packet inspection
  • Fusion technology blends all the components of Cyberoam into a single firewall policy
  • Prevents DoS & flooding attacks from internal & external sources
  • Identity-based access control for applications like P2P, IM
  • Application layer protection
  • Provides the right balance of security, connectivity and productivity
  • Flexibility to set policies by user identity
  • High scalability
Virtual Private Network
  • Threat Free Tunneling
  • Industry standard: IPSec, L2TP, PPTP VPN
  • VPN High Availability for IPSec and L2TP connections
  • Dual VPNC Certifications - Basic and AES Interop
  • Safe and clean VPN traffic
  • Secure connectivity to branch offices and remote users
  • Low cost remote connectivity over the Internet
  • Effective failover management with defined connectionpriorities
Gateway Anti-Virus
& Anti-Spyware
  • Scans HTTP, FTP, IMAP, POP3 and SMTP traffic
  • Detects and removes viruses, worms and Trojans
  • Access to quarantined mails to key executives
  • Instant user identification in case of HTTP threats
  • Complete protection of traffic over all protocols
  • High business flexibility
  • Protection of confidential information
  • Real-time security
Gateway Anti-Spam
  • Scans SMTP, POP3 and IMAP traffic for spam
  • Detects, tags and quarantines spam mail
  • Enforces black and white lists
  • Virus Outbreak Protection
  • Content-agnostic spam protection including Image-spam using Recurrent Pattern Detection (RPD ) Technology
  • Enhances productivity
  • High business flexibility
  • Protection from emerging threats
  • High scalability
  • Zero hour protection incase of virus outbreaks
  • Multi-language and Multi-format spam detection
Intrusion Prevention
System - IPS
  • Database of over 3000 signatures
  • Multi-policy capability with policies based on default & custom signatures, source and destination
  • Prevents intrusion attempts, DoS attacks, malicious code, backdoor activity and network-based blended threats
  • Blocks anonymous proxies with HTTP proxy signatures
  • Blocks “phone home” activities
  • Low false positives
  • Real-time Security in dynamic environments like DHCP and Wi-Fi
  • Offers instant user-identification in case of internal threats
  • Apply IPS policies on users
Content &
Application Filtering
  • Automated web categorization engine blocks non-work sites
    based on millions of sites in over 82+ categories
  • URL Filtering for HTTP & HTTPS protocols
  • Hierarchy, department, group, user-based filtering policies
  • Time-based access to pre-defined sites
  • Prevents downloads of streaming media, gaming, tickers, ads
  • Supports CIPA compliance for schools and libraries
  • Prevents exposure of network to external threats
  • Blocks access to restricted websites
  • Ensures regulatory compliance
  • Saves bandwidth and enhances productivity
  • Protects against legal liability
  • Ensures the safety and security of minors online
  • Enables schools to qualify for E-rate funding
Bandwidth Management
  • Committed and burstable bandwidth by hierarchy,
    departments, groups & users
  • Prevents bandwidth congestion
  • Prioritizes bandwidth for critical applications
Multiple Link Management
  • Security over multiple ISP links using a single appliance
  • Load balances traffic based on weighted round robin distribution
  • Link Failover automatically shifts traffic from a failed link to a working link
  • Easy to manage security over multiple links
  • Controls bandwidth congestion
  • Optimal use of low-cost links
  • Ensures business continuity
On-Appliance Reporting
  • Complete Reporting Suite available on the Appliance
  • Traffic discovery offers real-time reports
  • Reporting by username
  • Reduced TCO as no additional purchase required
  • Instant and complete visibility into patterns of usage
  • Instant identification of victims and attackers in internal network
Specification
Interfaces
10/100 Ethernet Ports-
10/100/1000 GBE Ports6
Configurable Internal/DMZ/WAN PortsYes
Console Ports (RJ45)-
SFP (Mini GBIC) Ports-
USB ports2
System Performance*
Firewall throughput (Mbps)1,000
New sessions/second10,000
Concurrent sessions400,000
168-bit Triple-DES/AES throughput (Mbps)80/100
Antivirus throughput (Mbps)200
IPS throughput (Mbps)300
UTM throughput (Mbps)160
Stateful Inspection Firewall
Multiple Zones security with separate levels of access rule enforcement for each zoneYes
Rules based on the combination of User, Source &
Destination Zone and IP address and Service
Yes
Actions include policy based control for IPS, Content
Filtering, Anti virus, Anti spam and Bandwidth Management
Yes
Access SchedulingYes
Policy based Source & Destination NATYes
H.323 NAT TraversalYes
802.1q VLAN SupportYes
DoS & DDoS Attack preventionYes
Gateway Anti-Virus & Anti-Spyware
Virus, Worm, Trojan Detection & RemovalYes
Spyware, Malware, Phishing protectionYes
Automatic virus signature database updateYes
Scans HTTP, FTP, SMTP, POP3, IMAP, VPN TunnelsYes
Customize individual user scanningYes
Self Service Quarantine areaYes
Scan and deliver by file sizeYes
Block by file typesYes
Gateway Anti-Spam
Real-time Blacklist (RBL), MIME header checkYes
Filter based on message header, size, sender, recipientYes
Subject line taggingYes
IP address Black list/White listYes
Redirect spam mails to dedicated email addressYes
Image-based spam filtering using RPD TechnologyYes
Zero hour Virus Outbreak ProtectionYes
Self Service Quarantine areaYes
Intrusion Prevention System
Signatures: Default (3000+), Custom Yes
IPS Policies: Multiple, Custom Yes
User-based policy creation Yes
Automatic real-time updates from CRProtect networksYes
Protocol Anomaly DetectionYes
Block
- P2P applications e.g. Skype
- Anonymous proxies e.g. UItra surf
- “Phone home” activities
- Keylogger

Yes
Yes
Yes
Yes

Content & Application Filtering
Inbuilt Web Category DatabaseYes
URL, keyword, File type blockYes
Categories: Default(82+), CustomYes
Protocols supported: HTTP, HTTPSYes
Block Malware, Phishing, Pharming URLsYes
Custom block messages per category Yes
Block Java Applets, Cookies, Active XYes
CIPA CompliantYes
Data leakage control via HTTP uploadYes
Virtual Private Network - VPN
IPSec, L2TP, PPTP Yes
Encryption - 3DES, DES, AES, Twofish, Blowfish, Serpent Yes
Hash Algorithms - MD5, SHA-1 Yes
Authentication - Preshared key, Digital certificates Yes
IPSec NAT Traversal Yes
Dead peer detection and PFS support Yes
Diffie Hellman Groups - 1,2,5,14,15,16 Yes
External Certificate Authority support Yes
Export Road Warrior connection configuration Yes
Domain name support for tunnel end points Yes
VPN connection redundancy Yes
Overlapping Network support Yes
Hub & Spoke VPN support Yes
SSL VPN
TCP & UDP TunnelingYes
Authentication - Active Directory, LDAP, RADIUS, CyberoamYes
Multi-layered Client Authentication - Certificate, Username/PasswordYes
Network access - Split and Full tunnelingYes
Browser-based (Portal) Access - Clientless accessYes
Lightweight SSL VPN Tunneling ClientYes
Granular access control to all the Enterprise Network resourcesYes
Administrative controls - Session timeout, Dead Peer Detection, Portal customizationYes
User & Group policy enforcementYes
Bandwidth Management
Application and User Identity based Bandwidth ManagementYes
Guaranteed & Burstable bandwidth policyYes
Application & User Identity based Traffic Discovery
Multi WAN bandwidth reporting
User Identity and Group Based Controls
Access time restrictionYes
Time and Data Quota restrictionYes
Schedule based Committed and Burstable BandwidthYes
Schedule based P2P and IM Controls Yes
Networking
Multiple Link Auto FailoverYes
WRR based Load balancingYes
Policy routing based on Application and UserYes
DDNS/PPPoE ClientYes
Support for HTTP ProxyYes
Dynamic Routing: RIP v1& v2, OSPF, BGP, Multicast ForwardingYes
Parent Proxy support with FQDNYes
High Availability
Active-Active Yes
Active-Passive with state synchronizationYes
Stateful FailoverYes
Alert on Appliance Status changeYes
Administration & System Management
Web-based configuration wizardYes
Role-based administrationYes
Multiple administrators and user levelsYes
Upgrades & changes via Web UIYes
Multi-lingual support: Chinese, HindiYes
Web UI (HTTPS)Yes
Command line interface (Serial, SSH, Telnet)Yes
SNMP (v1, v2c, v3)Yes
Cyberoam Central ConsoleYes
Version RollbackYes
NTP Server SupportYes
User Authentication
Local databaseYes
Windows Domain Control & Active Directory IntegrationYes
Automatic Windows Single Sign OnYes
External LDAP/RADIUS database IntegrationYes
User/MAC BindingYes
Logging/Monitoring
Internal HDDYes
Graphical real-time and historical monitoringYes
Email notification of reports, viruses and attacksYes
Syslog support Yes
On-Appliance Reporting
Intrusion events reportsYes
Policy violations reportsYes
Web Category reports (user, content type)Yes
Search Engine Keywords reportingYes
Data transfer reporting (By Host, Group & IP Address)Yes
Virus reporting by User and IP AddressYes
Compliance Reports45+
VPN Client
IPSec compliantYes
Inter-operability with major IPSec VPN GatewaysYes
Supported platforms: Windows 98, Me, NT4, 2000, XP, VistaYes
Import Connection configurationYes
Certification
ICSA Firewall - CorporateYes
VPNC - Basic and AES interoperabilityYes
Checkmark UTM Level 5 CertificationYes
Compliance
CE Yes
FCCYes
Dimensions
H x W x D (inches)16.8 x 10.3 x 1.7
H x W x D (cms)42.8 x 25.5 x 4.4
Weight 5.3 kg,11.68 lbs
Power
Input Voltage115-230 VAC
Consumption90W
Total Heat Dissipation (BTU)200
Environmental
Operating Temperature0 to 40 °C
Storage Temperature-20 to 80 °C
Relative Humidity (Non condensing)0 to 90%
Cooling System -Fans2