Monday, March 19, 2012

new/updated ASG

Interface Virtual MAC Address (Spoofing) ,Ethernet interfaces in ASG can have their hardware MAC address rewritten by ASG to a desired value. This MAC ,"editing" is for example used when the MAC of your external interface must match one registered with your ,ISP, and you want to use a new/updated ASG without having to go through the process again.  ,You can set a Virtual MAC address from the Interfaces Section of WebAdmin by editing the desired interface on ,the "Advanced" tab. ,Web Application Security: Drop Invalid Cookies  ,In Web Application Security, if Cookie Signing is activated, requests containing unsigned or invalidly signed ,cookies will be rejected. You have now the option to instead let the Web Application Firewall only remove the ,invalid Cookie from the request before letting it pass. For example, this is useful if you switch an existing web ,application to cookie signing and don't want to reject the requests from existing users that already have an ,(unsigned) cookie. This can be configured in the Firewall Profiles (Web Application SecurityWeb Application ,Firewall Firewall Profiles). ,Web Application Security: Rule Skipping ,In Web Application Security, for Firewall Profiles there is now a list in the advanced profile settings where you ,can add WAF rules to skip. You need to add specific WAF rule numbers which are found in the logs or reports.  ,(This is something you don't need to make use of unless you have a very specific problem or have been ,directed by Astaro Support to do so.) ,Web Application Security: SAN Certificate Support ,Web Application Security now supports the use of SAN certificates. These allow you to protect multiple ,hostnames with a single SSL cert, also known as "Domain certificates". They are commonly used in Outlook ,Web Access, and fall somewhere in the middle between a true "Wildcard" certificate (*.yourcompany.com) and ,a single-server one (domain.yourcompany.com). SAN Certificates can support a list of domains which can be ,mixed between external and internal server names. ,Editing User-Defined Mail White/Blacklists in WebAdmin ,Admins can now review the UserPortal whitelist and blacklist entries for mail senders that users have made for ,themselves. In WebAdmin, navigate to the user (Definitions & UsersUsers & Groups) you wish to work with to ,see this information and make edits where required.,

How many incoming VPN


Sunday, March 18, 2012

admitted into theVPN

For the purpose of dynamic bandwidth control, a VPG-based VPN can be compared to anATM network in which the link size can be varied. Therefore, controllers in the customerdomain operate on two views of the network (Figure 4). The view on the left side of Figure 4shows a network of end-to-end VPs which connect a set of CPNs. The view on the right showsa VPG network, which connects the same set of CPNs. The relationship between VPs andVPGs defines the mapping between both views.The VP admission controller, which participates in call setup and release in the enterprise network, operates on the left view. The controller decides whether a call can be admitted into theVPN, based on the VP capacity, its current utilization and the admission control policy. TheVP admission controller always ensures that enough capacity is available, such that cell-levelQOS can be guaranteed for all calls that are accepted. The controller runs on the time scale ofthe call arrival and departure rates (seconds or below). There can be one VP admission controller per VP, or one for a set of VPs. The VPG controller operates on both views. Depending onthe state of the VPs (in particular, traffic statistics and VP size) and the control objectives, itdynamically changes the amount of VPG bandwidth allocated to associated VPs. This controller enables customers to exploit variations in utilization among VPs that traverse the sameVPG, allowing bandwidth between VPs of different source-destination pairs to be shared without interacting with the provider. In order to guarantee QOS, the sum of the VP capacities mustbe less than or equal to the capacity of the VPG link. The controller runs on a time-scale ofseconds to minutes. The VPN controller operates on the right view. It is the only controllerwhich interacts with the provider, and it runs on the slowest time scale of all the controllers(minutes or above). The VPN controller dynamically negotiates the bandwidth of the VPGlinks with the provider, based on traffic statistics and control objectives (e.g., minimizing theVPN cost), while observing the customer's QOS requirements.

Saturday, March 17, 2012

VPN width as GPIO

transfer eciency by implementing dual one-way data buses to reduce datacongestion and arbitration with dedicated DMA arrays, namely the C/WDMA(config/write direct memory access) and RDMA (read direct memory access),implemented to establish two separate one-way data paths to transfer pending databetween the internal/external memories and the cryptographic engines under theguidance of the descriptors. The CD is the most important control module in chargeof the heterogeneous resource allocation and the task management given in thedescriptors. In addition to descriptor generation, C*Core 310 also manages systemwork flows and executes various network security related applications. This systemadopts a PCI-X compliant interface with a 133 MHz 64 bit data width as GPIO. Theapplication command is delivered by the external NP which processes the input andoutput packets to and from the PHY modules and executes data compression,header modification, packet classification and packet framing

Thursday, March 15, 2012

VPN IP address of your own internet provider

Several information resources of the Erasmus MC Medical Library and of the Erasmus University Library are protected, that means, have restricted access. The provider of the information keeps in check if the licence applies to the code (IP address) that is sent by the information asking computer.IP addressOn logging in to a network, the computer receives an address code (IP address) to recognize that computer from outside that network. An IP address consists of four groups of maximally three digits. For computers that are logged onto the network of the Erasmus MC, IP addresses always start with 156.83, for the EUR that is 130,115. But from home you have the IP address of your own internet provider, e.g. 87.208.xxx.xxx(Tele2). With that you will not have access to the shielded information.Shielded informationMany bibliographic databases only have licenced access. That applies to EMbase.com, PsycINFO via OvidSP, Web-of-Knowledge/Web-of-Science, Journal Citation Reports (Impact Factors), Cinahl. Many journals have access by subscription (Elsevier Science Direct, Wiley, Springer), just like the electronic books.PubMed is freely accessible, but linking to shielded journal articles, requires special access. That also applies to the MedLib Catalogue (OPAC): freely accessible, but linking to the e-books only is possible in shielded surround. There also are freely accessible journals (often free for a restricted periode, e.g. forinformation older that one year. Of course, employees and students of Erasmus MC and EUR from their working places and study rooms have direct access to the shielded information: those computers are default logged onto the network of Erasmus MC or EUR.Within the buildings of Erasmus MC there are two distinct wireless networks:1. the shielded one (IP address 156.83.*.*);2. the free, not shielded 'Hotspot' (IP address 70.172.*.*?).Using the 'Hotspot' is just like working from home (or elsewere): no access to shielded information. But there is something to do on it!VPN portal ('Virtual Personal Networking')By a special connection your personal computer at home seems to be part of the network of Erasmus MC or of EUR.Erasmus MC employees can log on to the network of Erasmus MC from elsewhere. Employees with a teaching task also have access to the MyEUR/ERNA-VPN portal of the EUR.EUR students (including medical students and other Erasmus MC students) use the MyEUR/ERNA portal.Access for EUR onlySome databases and journals are specifically meant for certain faculties of the EUR (legal, economic); thoseare only accessible from the EUR domain (130,115 .*.*), and not for employees of Erasmus MC, even from their workplaces.

Internet technology VPN

Internet technology has been the fastest growing areaof information technology in recent years (Keeney1999). Its rapid development, implementation and useby the individual and organizations have created bothopportunities and challenges for the management of thistechnology. The rapidly emerging Internet technologiesare in¯ uencing not just the management of product andservices but also the rethinking of business processes,®rm structure and even industry boundaries. EŒectiveuse of this technology is increasingly considered as amajor determinant of competitive advantage, productivity, and even individual competency.Internet usage by the individual is a pivotal conceptthat in¯ uences our understanding of the social andeconomic impacts of information technology. MISresearchers have proposed usage as a central conceptin taxonomies of success (DeLone and McLean 1992,Doll and Torkzadeh, 1998). Usage is also proposed as aMIS success measure in several frameworks for research(Ein-Dor and Segev 1978, Hamilton and Chervany1981, Ives et al. 1980). Jonscher (1983) suggests thatimprovements in the way that information technology is

Wednesday, March 14, 2012

Network Access Control VPN

Network Access Control
In addition to NIDS, access control, generally through the use of a firewall, should be performed before and after the VPN
device. When done on the interior of a VPN device as traffic heads toward the campus, the access control can ensure only
that the proper address ranges and protocols are allowed. As was mentioned earlier, most policies for VPN access tend to
allow the remote users to use almost any protocol they could on the local LAN. As such, it may be easier to define the
protocols you don't want your remote-user communities to be able to access, rather than define the ones that you do want
to allow.
In larger deployments, it is helpful to segment the various types of VPNs off of discrete access control points of the network.
This can be done through providing a dedicated firewall interface for each VPN type, as was done in the large VPN design.
This setup allows different levels of trust for different VPN applications. For example, an organization might decide it trusts
site-to-site VPNs a little more than remote-access VPNs. This better trust is a result of the fact that with site-to-site you know
the IP address of the remote peer and are potentially using digital certificates, whereas with remote-access VPNs you generally
do not know the address of your remote peer and are relying on group preshared keys combined with secondary
authentication to allow your users into the network. When deployed in this manner, VPN traffic can be filtered differently
based on what interface it arrives on at the access-control device.
Filtering outbound from the VPN device (toward the public network) is also important. This filtering can help ensure that
the VPN devices see only IPSec traffic coming into and out of their public interfaces. This filtering can generally be done on
a router with a standard ACL instead of a firewall, freeing the firewall to sit behind the VPN device as was specified earlier.
This setup is in contrast to many deployments today that place the firewall in front of the VPN device. When placed in front,
no visibility into the specific types of user traffic is possible because the traffic is still encrypted. Most of the benefits thatCisco Systems
 
stateful firewalls could provide in front of a VPN device are lost regardless, because IPSec traffic cannot be intelligently
filtered by most firewalls. The administrator would need to open a hole through the firewall to allow the traffic (that is, UDP
500 for IKE and IP 50 for ESP) and at that point, it is behaving in much the same way as a standard packet filter on a router.
Filtering inbound on the VPN device itself is recommended to allow only IKE and ESP. If the NAT transparency mechanism
is enabled, you should allow only the specific UDP or TCP port to the VPN device.
Often this access-control function can exist on the same hardware platform as the IPSec function. It can if your VPN device
also has a stateful firewall, or when a remote user connects using a laptop that has both VPN client software and a personal
firewall.