Orange County Computer Consultant

My photo
Orange County Computer Consultant helps small businesses with networking, installations and small business software.

Wednesday, December 14, 2005

More info on Cisco PIX 501

Cisco Firewall PIX 501

This firewall is designed for homes and small businesses.This firewall can support up to ten users on a basic license from Cisco. It has a 133 MHz processor and comes with 16MB's of RAM. In addition it has 8MB of Flash RAM.

The Firewall also comes with 1 uplink port and a four port switch. It does not support Layer 2 transparent fire walling. It also does not support the routing protocol OSFP which stands for Open Shortest Path First. There is no VLAN-Virtual Local Area Network.

The PIX 501 allows you to setup a VPN-Virtual Private Network easily with the Cisco Easy VPN Server.

The firewall supports speeds up to 60Mbps bidirectional.

When you implement cryptography such as 3DES or DES it slows down the traffic.The PIX 501 can support anywhere from 50-unlimited users depending on your license

Cisco PIX Technology

Cisco PIX Security Appliance.

Cisco PIX Security applications can enforce policies on users and applications.

Cisco PIX can protect you from many different network and Internet based attacks.

Cisco PIX offers secure connectivity, using methods such as SSHv2 Secure Shell Two and VPN virtual private networks.

This is fairly easy to setup.

Cisco PIX can provide you with secure VOIP voice over internet protocol.

IPSec or Internet Protocol Security IPSec can be setup for VPN's.

Cisco PIX Security appliances provide multiple layers of security.

This hardware/software based solutions is designed to look for anomolies aka weird traffic thats not normal on your network, which could be an indication of a attack.

There is over thirty different engines looking for different attack signatures.

The current version is Cisco PIX appliance version 7.0

Here are some of the feautures:

You can rollback previous configurations in IOS.

QOS- Quality of Service

You can update software on the fly with bringing down the hardware. No rebooting.

VPN client security

Layer 2 transparent firewall.

This is really interesting 3G mobile security services.

You can configure the firewall to block instant messaging, point to point networking P2P.

You have the ability to block applications trying to tunnel thru your network with encrypted
traffic.

Cisco PIX provide rich statefull packet inspection PIX can protect your voice, data, and video
traffic.

Version 7.0 also supports IKE or Internet Key Exchange.

Everything can be managed from Cisco Adaptive Device Manger which can be console and web based.

Benjamin Hargis CEO Phuture Networks
http://www.phuturenetworks.com
http://www.computersecurityadvice.com/
Here are some other sites for you viewing pleasure:http://www.checkmategame.blogspot.com
http://www.realestatelead.blogspot.com/

Sales Tips

-Here are some tips for people in sales, hope this helps.

Anticipate objections and be ready with rebuttals.

Get down to the real objection.

Follow up with all leads.

Do it the best its ever been done.

Its all numbers, dial more.

Provide value for customers.

Control the conversation, listen even more.

Follow ethical practices.

Planning, goal setting, decision making, delegation and communication work on improving these areas.

Toss out ideas at meetings.

Keep abreast of the market

Look for multiple sources of income.

Assume responsibility for your actions.

Build relationships.

Network like crazy.

Be resourcefull, ready, remebered and relentless.

Help customers discover the best solutions.

Persist and dont give up!

I've been in sales for 15 years this can be valuable to new sales people and veterans.

Building Internet Firewalls

Building Internet Firewalls by Oreilly

This book covers the basics of firewall technology to the nitty gritty details. I highly recommend it. It is well written and covers such interesting topics as protocols, databases, security strategies and examles of firewall setups.

Building Internet Firewalls covers packet Filtering, Proxy Services, NAT- network address translation and VPN's virtual private networks. Firewall architecture such as single box, screened host, bastion host, multiple screened hosts, modems and internal firewalls for your intranets.

The different ways to filter traffic are also discussed in depth. You can filter based upon address, protocol, source and destination addresses amongst many other variables. It discusses both Micorsoft Windows and *nix based solutions.

It goes over Internet Services such as RPC, DCOM, DOM, CIFS, SMB, SSL, RAS, PPTP and so many others.

This book is a awesome reference to add to your security analyst book collection.

Microsoft Security Update

Microsoft has released several security alerts for Microsoft Internet Explorer. Here are four of them:

HTTPS Proxy Vulnerability (CAN-2005-2830)

File Download Dialog Box Manipulation Vulnerability (CAN-2005-2829)

COM Object Instantiation Memory Corruption Vulnerability (CAN-2005-2831)

Mismatched Document Object Model Objects Memory Corruption Vulnerability (CAN-2005-1790)

This can cause problems ranging from attackers reading web addresses sent to a proxy server to running malicious code on your hosts to gain admin access.

MS05-055Vulnerability in Windows Kernel Allows Elevation of Privilege (908523)http://www.microsoft.com/technet/security/bulletin/MS05-055.mspx

This one allows attackers to escalate or gain higher privleges than allowed an example would be a user with no rights gaining administrative control of the machine. It is possible to change kernel memory with this vulnerability. This can lead to remote code execution as well.