Now that I've returned from the whirlwind that was Interop Las Vegas, I thought I'd share some thoughts about my experience … [Read more...]
Machine Fragile
Yesterday, a “breaking news” tweet at 1:07 PM EDT from the Associated Press reported that two explosions had occurred at … [Read more...]
Firewalls: Expensive, Broken Routers
In a previous post on IPS, I made a fairly negative comment on the value that you get from enterprise firewalls in the modern … [Read more...]
Surprised by Spam
I attended my first in person meeting of the ISOC Advisory Council this last week — I'm a newly minted co-chair, and … [Read more...]
NetCitadel and Software Defined Security

It's been an exciting couple of weeks in the security realm, with a number of innovative startups appearing. That's … [Read more...]
Cisco ASA: High CPU in Dispatch Unit

I ran into an issue of unexpectedly high CPU utilization on a Cisco ASA firewall running 8.4.x family code; the CPU was … [Read more...]
How to Build an IPSec VPN With Cisco ASAs & Overlapping Address Space

There are times your company will partner with another to provide a resource to them. Often, this interaction is … [Read more...]
Network Visibility for Flexible Security Architectures

Inline security appliances are a fact of modern network security architectures. There are a number of compliance drivers to … [Read more...]
Using SSL Intercept With ADCs + Firewalls to Inspect & Clean Encrypted Traffic

The Problem Let’s take a typical enterprise. We have our internet connection going to our router (or ISP’s router), then … [Read more...]
Security Superstition
A scientist is never certain. We all know that. We know that all our statements are approximate statements with different … [Read more...]
Interacting With the Cisco ASA CLI Using the HTTPS Interface
Most people are familiar with interacting with the ASA over HTTPS to get captures off the box, but every CLI mode is … [Read more...]
12 Tips for Effective IPS Deployment (Goats Optional)
Fresh from a conversation so frustrating that I could have cheerfully punched a goat today, I thought I'd jot down my … [Read more...]
Ode to a Network Engineer (in the Style of Bukowski)*
You are not a technical sink. You are not an infant made to passively suck up the pabulum from a vendor. Do your … [Read more...]
The Scorched Earth LAN & A Better Enterprise Security Model
The enterprise LAN is a blasted wasteland of dead and dying technologies. I call for a strategic retreat. It seems to me … [Read more...]
Cisco ASA 9.0 Clustering: Technical Highlights

Cisco has released OS version 9.0.1 for the popular and ubiquitous ASA firewall. One of the new features Cisco is touting is … [Read more...]
Recent Comments