Wednesday, May 1, 2013

NetworkEducator.com - Networking Articles, Tips, Resources, Configuration

NetworkEducator.com - Networking Articles, Tips, Resources, Configuration


Which VPN solution should we choose ?

Posted: 01 May 2013 03:30 AM PDT

Which VPN Solution should we choose ?

 Before choosing correct VPN solution for our network, we need to ask below question to us.

  • What do I need to protect?
  • What kind of protection is required?
  • How much protection is needed?

vpn solution

First need to determine what is to be protected. Do I need to protect traffic for specific applications, such as e-mail, database access, file transfers, and others? Do I need to protect traffic for specific hosts? Do I need to protect traffic for specific network segments? If I only need to protect traffic for specific applications, I would probably first examine SSL VPN to see if there is a solution available for the particular application or applications that need to be protected. Otherwise, I would look at other VPN solution

Second, what kind of protection is necessary? Does the traffic need to be encrypted? Do I need to perform packet integrity checking? How important is it to verify a device’s identity? Once I’ve answered these questions, I can narrow in on a more specific VPN solution. For instance, if I need encryption, I can immediately rule out GRE.

vpn solutionAnd third, how much protection is needed? For example, if I require encryption to provide data confidentiality, how strong does the encryption process need to be? Can I use DES or must I use a much stronger encryption algorithm, like 3DES? For device authentication, can I use pre-shared keys or should I use digital certificates? Again, I use these questions to narrow my pick to the most appropriate VPN solution.

There are many services being offered by the ISP providers. These include Site-to-site VPN, VPN on dial up networks, VPN on broadband networks, Voice with VPN and VPN on ISDN services

The post Which VPN solution should we choose ? appeared first on Network Educator.

Tuesday, April 30, 2013

NetworkEducator.com - Networking Articles, Tips, Resources, Configuration

NetworkEducator.com - Networking Articles, Tips, Resources, Configuration


Best practices for Network Infrastructure Management

Posted: 30 Apr 2013 05:30 AM PDT

Managing network infrastructure is a vital part of delivering IT services to the end-users. Networks play a critical part in the service delivery and at the same time as network infrastructure are becoming more complex day by day, it is essential that the processes for the Network Infrastructure exist and function efficiently.

network infrastructureIn this thesis I will create and present processes for Network Infrastructure Management for a company having thousands of users globally spread in unstructured way. The resolution is based on IT Infrastructure Library (ITIL) Change and Configuration Management best practice guidance. Integral part of this resolution is also to launch a structure to Configuration Management Database (CMDB), which holds the information and relationships of the network infrastructure. Our focus will be on network management support processes .We will not be focusing on the technology to implementing the same.

ITIL and specifically Change and Configuration Management are presented in the thesis for background information. Several other ITIL process areas go beyond the subject but they will be discussed only in brief. We can take ITIL as the basis for creating Network Infrastructure Management processes for the case study corporation, but it will only gives us some approach for the implementation. More specific approach had to be customized as per the company's requirement. When processes are in use the network staff can become an internal provider for network support and development for the end users.

After processes are acknowledged it is easier to educate IT staff for network support and network specialists who can focus more on the improvement side of network management and proactive management rather than just exclusively react on incidents. In other words they will be able to work in pro-active mode instead of reactive mode.

Thesis also discusses the challenges which comes during the implementing the new support processes. Processes describe the required procedures of people executing Network Infrastructure Management. Key problem in implementation new processes in Network Infrastructure Management is the resistance to change from local individual ways of managing the network infrastructure to global.

Author : Antti Mattila
Source : Helsinki University of Technology
 

The post Best practices for Network Infrastructure Management appeared first on Network Educator.

What is FAQ, RFC & FYI ?

Posted: 30 Apr 2013 03:30 AM PDT

FAQ stands for Frequently Asked Questions. These are periodic postings to Usenet newsgroups that contain a wealth of information related to the topic of the newsgroup. Many FAQs are quite extensive. FAQs are available by subscribing to individual Usenet newsgroups. A Web-based collection of FAQ resources has been collected by The Internet FAQ Consortium and is available at http://www.faqs.org/.

RFC stands for Request for Comments. These are documents created by and distributed to the Internet community to help define the nuts and bolts of the Internet. They contain both technical specifications and general information.

FYI stands for For Your Information. These notes are a subset of RFCs and contain information of interest to new Internet users.

Links to indexes of all three of these information resources are available on the University Libraries Web site at below url.

http://library.albany.edu/reference/faqs.html

The post What is FAQ, RFC & FYI ? appeared first on Network Educator.

Firewall Best Practices

Posted: 30 Apr 2013 02:55 AM PDT

 

  • There should physical security for the firewall.
  • Deny all the traffic and allow only those ports, protocols and services which are required. 
  • Services & software which are not specifically required should be uninstalled or disabled.
  • Limit the number of applications that run on the firewall to let firewall perform at it best. Should avoid using services which can be configured on other dedicated machines instead of firewall. 
  • Syslog Server should be implemented in separate zone (Management zone) so that logs cannot be manipulated by malicious user.
  • Log should be monitored regularly and should be kept for long period. 
  • Alrerting should be configured. 
  • Login Password should be of minimum 8 characters using a combination of alphabets, numeric & special characters such as $  &  # This should be changed frequently. 
  • Access-list should be as much specific as it can be. 
  • Should have backup configuration in soft copy on TFTP Server as well as hard copy. There should be process for restoring the configuration directly from TFTP Server. 
  • Should have the backup of ios files of firewall and and should have process for restoring the ios . 
  • Should create different security zones for additional security. 
  • Instead of configuring telnet for remote management Secure Shell or SSH should be configured. 
  • Different privilege level should be configured for different users for limited access.
  • Should be used stateful inspection should be enabled. 
  • Application proxy should be configured for added security.  
  • Should perform security tests regularly on your firewall to find out loop holes & flaws. These should be done from every interface of the firewall. 

 

The post Firewall Best Practices appeared first on Network Educator.

Thursday, April 11, 2013

NetworkEducator.com - Networking Articles, Tips, Resources, Configuration

NetworkEducator.com - Networking Articles, Tips, Resources, Configuration


How NMS increases network security and capacity planning

Posted: 11 Apr 2013 03:30 AM PDT

This case study describes how NMS increases network Security and capacity Planning. Cisco IT is using Cisco IOS Net flow technology internally with their Cisco Global network, a leading-edge enterprise environment that is one of the largest and most complex in the world. Cisco customers can draw on Cisco IT’s real world experience in this area to help support [...]

The post How NMS increases network security and capacity planning appeared first on Network Educator.

Thursday, February 21, 2013

Networking Articles and Tips

Networking Articles and Tips


Configuring Console Security

Posted: 21 Feb 2013 04:00 AM PST

console port is used to connect a terminal directly into the router. By default, there is no security configured or implemented to the console port and even the setup utility also does not prompt to configure security for console port. Cisco routers have many different modes of operation, one of which is user mode. User [...]

Tuesday, December 25, 2012

Networking Articles and Tips

Networking Articles and Tips


TFTP (Trivial File Transfer Protocol)

Posted: 25 Dec 2012 04:52 AM PST

TFTP or Trivial File Transfer Protocol is a very simple lightweight protocol which is used to copy files to and from devices which supports TCP/IP.  It is is one of the more important protocols, specially while working with Cisco devices ( routers and switches) as it is the primary method of transferring configuration file and IOS images. [...]

Monday, November 5, 2012

Networking Articles and Tips

Networking Articles and Tips


Demilitarized Zone (DMZ)

Posted: 16 Sep 2012 07:45 PM PDT


Demilitarized Zone (DMZ) In computer networks, a DMZ or Demilitarized Zone is a physical or logical subnetwork that contains an organization’s external services, largely to untrusted network, such as Internet.  It prevents outside users from getting direct access to a server that has company data. In other words “demilitarised zone” or DMZ refers to this [...]

Sunday, October 28, 2012

Networking Articles and Tips

Networking Articles and Tips


Temporary Post Used For Theme Detection (4dbe3fdd-15eb-4218-90b1-09f9ad3e7214 – 3bfe001a-32de-4114-a6b4-4005b770f6d7)

Posted: 28 Oct 2012 01:24 AM PDT


This is a temporary post that was not deleted. Please delete this manually. (0a77e3b0-c6c5-4534-99c1-3444423cedd2 – 3bfe001a-32de-4114-a6b4-4005b770f6d7)