Interop: Firewalls, Booth Babes and Unicorn Poop

Now that I've returned from the whirlwind that was Interop Las Vegas, I thought I'd share some thoughts about my experience … [Read more...]

Machine Fragile

Yesterday, a “breaking news” tweet at 1:07 PM EDT from the Associated Press reported that two explosions had occurred at … [Read more...]

Firewalls: Expensive, Broken Routers

In a previous post on IPS, I made a fairly negative comment on the value that you get from enterprise firewalls in the modern … [Read more...]

Surprised by Spam

I attended my first in person meeting of the ISOC Advisory Council this last week — I'm a newly minted co-chair, and … [Read more...]

NetCitadel and Software Defined Security

OneControl uses a common policy definition language to define security policies

It's been an exciting couple of weeks in the security realm, with a number of innovative startups appearing. That's … [Read more...]

Cisco ASA: High CPU in Dispatch Unit

1848-132420

I ran into an issue of unexpectedly high CPU utilization on a Cisco ASA firewall running 8.4.x family code; the CPU was … [Read more...]

How to Build an IPSec VPN With Cisco ASAs & Overlapping Address Space

blog1

There are times your company will partner with another to provide a resource to them. Often, this interaction is … [Read more...]

Network Visibility for Flexible Security Architectures

Deploying aggregation switches for better network visibility

Inline security appliances are a fact of modern network security architectures. There are a number of compliance drivers to … [Read more...]

Using SSL Intercept With ADCs + Firewalls to Inspect & Clean Encrypted Traffic

SSL Intercept

The Problem Let’s take a typical enterprise. We have our internet connection going to our router (or ISP’s router), then … [Read more...]

Security Superstition

A scientist is never certain. We all know that. We know that all our statements are approximate statements with different … [Read more...]

Interacting With the Cisco ASA CLI Using the HTTPS Interface

Most people are familiar with interacting with the ASA over HTTPS to get captures off the box, but every CLI mode is … [Read more...]

12 Tips for Effective IPS Deployment (Goats Optional)

Fresh from a conversation so frustrating that I could have cheerfully punched a goat today, I thought I'd jot down my … [Read more...]

Ode to a Network Engineer (in the Style of Bukowski)*

You are not a technical sink. You are not an infant made to passively suck up the pabulum from a vendor. Do your … [Read more...]

The Scorched Earth LAN & A Better Enterprise Security Model

The enterprise LAN is a blasted wasteland of dead and dying technologies. I call for a strategic retreat. It seems to me … [Read more...]

Cisco ASA 9.0 Clustering: Technical Highlights

asa-9.0-cluster-eclb-control-link

Cisco has released OS version 9.0.1 for the popular and ubiquitous ASA firewall. One of the new features Cisco is touting is … [Read more...]