Showing posts with label Network Articles. Show all posts
Showing posts with label Network Articles. Show all posts

Friday, 31 May 2013

How to Install and Configure MRTG on Ubuntu Server 12.04


This post will describe how to install and configure Tobi Oetiker’s MRTG (Multi Router Traffic Grapher) on your Ubuntu home server. Once configured, you’ll be able to use it to monitor the traffic in and out of your home network using the SNMP capability in your network’s gateway\router. MRTG generates static HTML pages containing PNG images which provide a visual representation of this traffic. MRTG typically produces daily, weekly, monthly, and yearly graphs. MRTG is written in perl and works on Unix/Linux as well as Windows. MRTG is free software licensed under the GNU GPL.

Software versions used in this post were as follows:
  • Ubuntu Server v12.04 x64 LTS)
  • mrtg_2.17.3-2ubuntu1_amd64.deb

  • Download and Install

    First, download and install MRTG:
    sudo apt-get install mrtg
    If this is the first time installing MRTG on your server you’ll likely be presented with the following message. Answering “Yes” means that the default configuration file will be installed with permissions set at 640. Answering “No” means that the permissions are set at 644. In this example we’re going to accept the default Yes. No worries though, if you select No the steps in this tutorial will still work.

    Sunday, 26 May 2013

    How to Setup Chroot SFTP in Linux (Allow Only SFTP, not SSH)



    If you want to setup an account on your system that will be used only to transfer files (and not to ssh to the system), you should setup SFTP Chroot Jail as explained in this article.
    In a typical sftp scenario (when chroot sftp is not setup), if you use sftp, you can see root’s file as shown below.
    If you want to give sftp access on your system to outside vendors to transfer files, you should not use standard sftp. Instead, you should setup Chroot SFTP Jail as explained below.
    Non-Chroot SFTP Environment
    In the following example (a typical sftp environment), abc can sftp to the system, and view /etc folder and download the files from there.
    # sftp abc@xcessl0gycs.com
    abc@xcessl0gycs's password:
    sftp> pwd
    Remote working directory: /home/abc
    

    Thursday, 23 May 2013

    What’s the Difference Between 127.0.0.0 and 127.0.0.1?



    Sometimes the most elementary of questions yield teachable moments; read on as we delve into how a single digit change between 127.0.0.0 to 127.0.0.1 offers a chance to look at network topology.
    The Question
    What’s the Difference Between 127.0.0.0 and 127.0.0.1?
    I know that both are loopback IPs, but they have another ip mask.
    What’s the difference between them? Can they be used interchangeably?
    ===========================================================================
    
    IPv4 routes
    ===========================================================================
    Active routes:
    Destination               Mask          Gateway        Interface Metric
          0.0.0.0          0.0.0.0      192.168.1.1      192.168.1.6     26
    [...]
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
    What kind of information can we tease out from this table?

    Thursday, 24 January 2013

    ADOBE ACROBAT X PRO 10.1.3 MULTILANGUAGE + KEYGEN


    Adobe® Acrobat® X Pro software lets you deliver highly professional PDF communications. Create and edit PDF files with rich media included, share information more securely, and gather team feedback more efficiently.

    Benefits of Acrobat X Pro

    Increase your productivity : Get more work done — faster. From streamlining routine PDF tasks to quickly comparing two files, Acrobat X Pro software makes your job easier.

    Protect sensitive information : Share files with confidence by easily adding PDF passwords or digital signatures. Remove sensitive information with redaction tools.

    Easily create fillable forms : Turn your paper forms into fillable PDF forms in just a few steps. Distribute and collect forms electronically, track status, and analyze results.

    Sunday, 13 January 2013

    Passive-interface command behavior in RIP, EIGRP & OSPF


    Passive-interface command is used in all routing protocols to disable sending updates out from a specific interface. However the command behavior varies from o­ne protocol to another.

    In RIP this command will disable sending multicast updates via a specific interface but will allow listening to incoming updates from other RIP speaking neighbors.

    This simply means that the router will still be able to receive updates o­n that passive interface and use them in the routing table.

    In EIGRP the passive-interface command stops sending outgoing hello packets, hence the router can not form any neighbor relationship via the passive interface. This behavior stops both outgoing and incoming routing updates.

    In OSPF the passive-interface has a similar behavior to EIGRP. The command suppresses hello packets and hence neighbor relationships.

    Wednesday, 7 November 2012

    Explain Intrusion detection system (IDS)?? Types OF IDS...


    An intrusion detection system (IDS) is a device or software application that monitors network or system activities for malicious activities or policy violations and produces reports to a Management Station. Some systems may attempt to stop an intrusion attempt but this is neither required nor expected of a monitoring system. Intrusion detection and prevention systems (IDPS) are primarily focused on identifying possible incidents, logging information about them, and reporting attempts. In addition, organizations use IDPSes for other purposes, such as identifying problems with security policies, documenting existing threats and deterring individuals from violating security policies. IDPSes have become a necessary addition to the security infrastructure of nearly every organization.
    IDPSes typically record information related to observed events, notify security administrators of important observed events, and produce reports. Many IDPSes can also respond to a detected threat by attempting to prevent it from succeeding. They use several response techniques, which involve the IDPS stopping the attack itself, changing the security environment (e.g. reconfiguring a firewall), or changing the attack's content.

    Thursday, 4 October 2012

    EBOOK - Installation And Configuration of R.S.A enVision

                                    



    "The Right Choice for Compliance and Security Success!". The RSA enVision platform provides collection, alerting and analysis of log data that enables organizations to simplify compliance and quickly respond to high-risk security events. The RSA enVision 3-in-1 platform offers an effective Security and Information Event Management (SIEM) and log management solution, capable of collecting and analyzing large amounts of data in real-time, from any event source and in computing environments of any size. RSA enVision is easily scalable - eliminating the need for filtering and to deploy agents.

    Tuesday, 2 October 2012

    Information System Auditing


    1. What is informaton system?
    Information system is any combination of information technology and human operation managemen and dececion making.

    2. What is information system auditing?
    Ron Weber opinion (1999,p.10), “EDP auditing is the process of collecting and evaluating evidence to determine whether a computer systems safeguard assets, and consumes resources effiently ”.Understanding in general is the process of collecting and evaluating evidence to determine whether a computerized application system has been set and implement the system, adequate internal controls, all assets are protected well / not abused, and ensuring data integrity, reliability and the effectiveness and efficiency of the system computer-based information.

    Sunday, 2 September 2012

    Syness-The IT Regulatory and Standards Compliance Handbook: How to Survive Information Systems Audit and Assessments | For ISO 27001(BS7979), PCI-DSS, HIPPA, FISCAM, COBIT


    The IT Regulatory and Standards Compliance Handbook: How to Survive Information Systems Audit and Assessments

    Publisher: Syngress 2008 | 750 Pages | ISBN: 1597492663 | PDF | 11 MB

    This book provides comprehensive methodology, enabling the staff charged with an IT security audit to create a sound framework, allowing them to meet the challenges of compliance in a way that aligns with both business and technical needs. This “roadmap” provides a way of interpreting complex, often confusing, compliance requirements within the larger scope of an organization’s overall needs.

    Saturday, 14 July 2012

    Configuring the Cisco IDS Router / Switch Modules for Cisco 6500 Switch / 7200 Router

    IDSM-2
    The IDSM-2 Module is a Cisco IDS blade for the Cisco 6500 switch.
    Once you install the module into the switch the module uses following logical ports :
    Port 1Used for TCP Resets (In Promiscuous Mode)
    Port 2Command and Control
    Port 7Sensing Port
    Port 8Sensing Port
    Below details the steps required for configuring your switch / module for an inline setup. This includes obtaining the module number for the cisco ids running the setup wizard and then assigning the required ports for on the switch for ids sensing within an inline configuration. The clear trunk commands are required as by default the switch assigns the ports as trunk ports to every vlan.

    Tuesday, 26 June 2012

    How to configure a Cisco Layer 3 switch-InterVLAN Routing



    Cisco Catalysts switches equipped with the Enhanced Multilayer Image (EMI) can work as Layer 3 devices with full routing capabilities. Example switch models that support layer 3 routing are the 3550, 3750, 3560 etc.

    On a Layer3-capable switch, the port interfaces work as Layer 2 access ports by default, but you can also configure them as Routed Ports which act as normal router interfaces. That is, you can assign an IP address directly on the routed port. Moreover, you can configure also a Switch Vlan Interface (SVI) with the “interface vlan” command which acts as a virtual layer 3 interface on the Layer3 switch.

    On this post I will describe a scenario with a Layer3 switch acting as “Inter Vlan Routing” device together with two Layer2 switches acting as closet access switches.

    Friday, 22 June 2012

    Check Point : SecurePlatform (SPLAT) Backup Options Available.



    One aspect of the Check Point SecurePlatform OS that I struggle to get my head around is backups. There are a few different options, and during the course of researching an upgrade I came across the best explanation I’ve seen yet.  I’ve decided to grab a copy of the relevant text and post it in my blog for future reference here.

    Oversimplified Executive Summary

    • upgrade_export contains just Check Point configuration
    • A backup is an upgrade_export plus SPLAT OS configuration
    • A snapshot is a backup plus binary files, both Check Point and SPLAT OS
    • As a general rule of thumb, if your restoring on the same hardware a snapshot would be the easiest to use since it contains the most info and an upgrade_export would be the worst, since you’d have to manually restore the most stuff.

    Checkpoint : Mount USB Memory Stick / Pen Drive to Splat

    Ever wanted to use an USB stick on OpenServer using SPLAT or an appliance?

    Just connect the device to an USB port of your choice.

    1. Load the appropriate kernel module for handling the USB device.
    * modprobe usb-storage

    2. Check which new device was bound, for example "/dev/sda1".
    * fdisk -l

    3. Create a mount point.
    * mkdir /mnt/usbdisk

    4. Mount USB device.
    * mount /dev/sdb1 /mnt/usbdisk

    5. Use the device to transfer data as you like.   "[DATA Transafer]"

    6. Unmount USB device.
    * umount /mnt/usbdisk


    Thursday, 21 June 2012

    How Traceroute Command Works ??

                                       Traceroute

    What is Traceroute?
    It is an application layer implementation to find the hops when a packet traverses to a destination.

    What are the Protocols Used in Traceroute?
    Traceroute works with combination of both ICMP and UDP. It mainly relies on ICMP Time-to-Live Exceeded (Type 11).

    Wednesday, 20 June 2012

    DDNS - Dynamic Domain Name System | What is DDNS , DNS

    DDNS - Dynamic Domain Name System
    We Know All before sending anything to his mail server, he will read the database from the public server for the latest ip address of mail server and put it as destination address.. But twas a small problem, at times after fetching the latest public ip of mail server, ISP DHCP renews the IP lease of mail server, hence the message lost.

    Again after some time I started thinking about a vpn connectivity from an office which doesn't have public address, so the idea of DDNS came,

    Before explaining DDNS, I hope you all have a good idea about DNS, For those who dont know, DNS is the one to one mapping between name to ip address. But in DNS its will not get updated dynamically and it may take even more than 24 hrs to get updated in the root DNS servers. Here come DDNS.

    Tuesday, 19 June 2012

    Top Ten Tips for Managing Your CheckPoint Firewall


    This article discusses the Top ten tips that you can implement to best manage and fine tune your firewall. The purpose of this article is to get the best performance out of your firewall and increased security to your network.

    1. Use the latest version of the OS software available for your particular firewall. Install the latest patches and if possible/applicable, the latest software version available.

    2. Use a stealth Rule at the top of the rule base.

    What is a stealth rule? A stealth rule is a rule which disallows any communication to the firewall itself from unauthorized networks/hosts. It is a rule to protect the firewall itself from attacks.

    Monday, 18 June 2012

    Different Types of Firewalls


    Companies such as Cisco and other major vendors have introduced a multitude of firewall products that are capable of monitoring traffic using different techniques. Some of today's firewalls can inspect data packets up to Layer 4 (TCP layer). Others can inspect all layers (including the higher layers) and are referred to as deep packet firewalls. This section defines and explains these firewalls. 

    The three types of inspection methodologies are as follows:
    • Packet Filtering and Stateless Filtering.
    • Stateful Filtering.
    • Deep Packet Layer Inspection.

    Blue Coat ProxySG - CLI Commands


    Here is a list of Blue Coat ProxySG CLI commands, that I have compiled from my studies, Blue Coat documents, and places around the web. This is by no means an exhaustive or comprehensive list, but is rather meant to be a command line KB of sorts - mainly for my quick reference. The list is split into standard and privileged mode commands. If the list proves useful to you, please feel free to share the link with others. Also, if you see any typo's with anything, feel free to let me know!

    What Is SIC (Secure Internal Communication) in Checkpoint Firewall

    SIC - Encryption, Authentication and Secure Channel

    The following security measures are taken to ensure the safety of SIC:

    Certificates for authentication.

    Standards-based SSL for the creation of the secure channel.

    3DES for encryption.


    ******************************************************************************************************
    ****************************************************************************************************** 

    Saturday, 16 June 2012

    How to Configure DHCP on Cisco Router 871 or 18xx or 21xx or 26xx .(Series)


    DHCP stands for Dynamic Host Configuration Protocol. Basically it’s a mechanism which assigns IP addresses to computers dynamically. Usually DHCP is a service running on a server machine in the network in order to assign dynamic IP addresses to hosts. All Cisco 800 series models have the ability to work as DHCP servers, thus assigning addresses to the internal LAN hosts. Without a DHCP server in the network, you would have to assign IP addresses manually to each host. These manually assigned addresses are also called “static IP addresses”.