Network technologies and trends:

Networking


August 26, 2016  6:17 AM

Shadow Brokers group and Cisco exploit

Yasir Irfan Yasir Irfan Profile: Yasir Irfan
ASA, Cisco, NSA, Security, SNMP, Software, vulnerability

The recent claims by Shadow Brokers group to have stolen hacking tools which might belong to the National Security Agency (NSA) has drawn interest of major Security vendors.  Cisco did acknowledge that there is a vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco Adaptive...

August 20, 2016  11:40 AM

Cisco ASA FirePOWER deployment options – Series 2

Yasir Irfan Yasir Irfan Profile: Yasir Irfan
ASA, Cisco, Decryption, Encryption, IPsec, Security, Security policies, Ssl vpn, traffic

Cisco ASA FirePOWER module can be configured in promiscuous monitor-only mode also known as passive mode. As the name suggests, in passive mode the Cisco ASA FirePOWER module does nothing to the traffic passes through it. Rather the ASA just forwards a copy of the packet to Cisco ASA FirePOWER...


August 19, 2016  5:55 PM

Cisco ASA FirePOWER deployment options – Series 1

Yasir Irfan Yasir Irfan Profile: Yasir Irfan
ASA, Cisco, Decryption, Encryption, Security policies

When it comes to deploying the Cisco ASA FirePOWER module, it can be configured in one of the following modes

  • Inline Mode
  • Promiscuous monitor-only (passive) mode
Inline Mode In an inline mode, the traffic passes through the configured ASA...


August 14, 2016  7:48 AM

An Introduction Cisco ASA FirePOWER Services

Yasir Irfan Yasir Irfan Profile: Yasir Irfan
CCIE, Cisco, Decryption, IPS, SSL

As we all know Cisco jumped into Next Generation Firewall segment, though they are late yet they are trying sell their next-generation firewall services, including Next-Generation Intrusion Prevention System (NGIPS), Application Visibility and Control (AVC), URL filtering, and Advanced Malware...


August 2, 2016  5:35 AM

A review for “Cisco Next-Generation Security Solutions: All-in-one Cisco ASA Firepower Services, NGIPS, and AMP”

Yasir Irfan Yasir Irfan Profile: Yasir Irfan
CCIE, Cisco, Cisco ASA, Cisco Press, Exam, firewall, Security, threat

The newly released Cisco Press title “Cisco Next-Generation Security Solutions” seems to be a great resource which deals with Cisco ASA FirePOWER Services, NGIPS and AMP. Thanks to...


February 29, 2016  12:45 PM

Things to consider before introducing Palo Alto Firewall into routing domain- Series 2

Yasir Irfan Yasir Irfan Profile: Yasir Irfan
ASA, BGP, Cisco, firewall, Network design, OSPF, Routing

In my previous post , I did mentioned Palo Alto Networks Firewall having issues in...


February 29, 2016  12:07 PM

How does Palo Alto Firewall identify an App?

Yasir Irfan Yasir Irfan Profile: Yasir Irfan
app, application, ASA, BGP, Cisco, firewall, HTTP, IP address, Network design, OSPF, Routing, Signatures, Technology

When it comes to identifying an application  Palo Alto Firewall is quite accurate and yield great results in either allowing or dropping the traffic based on security policy applied.  I believe App-ID is the strongest point of Palo Alto Firewalls and it makes them leaders in the Next Generation...


February 28, 2016  6:15 AM

Things to consider before introducing Palo Alto Firewall into routing domain- Series 1

Yasir Irfan Yasir Irfan Profile: Yasir Irfan
ASA, BGP, Cisco, firewall, Gartner, Gartner Magic Quadrant, Network design, OSPF, Routing

When it comes to routing, most of us are quite comfortable in using dedicated routers in Enterprise networks.  Some time the Business need or the existing network design forces an Organisation to use a traditional firewall not only as a firewall but also as a router. Well this works well, if some...


February 26, 2016  4:28 PM

Palo Alto Firewall with PAN-OS 7.02 have issues with OSPF

Yasir Irfan Yasir Irfan Profile: Yasir Irfan
firewall, OSPF, Palo Alto Networks, router

When it comes to Palo Alto Networks Firewall, we all know PAN-OS 6.x is a quite stable version, Palo Alto announced PAN-OS version 7 almost 8 months back,  but I see very few people are using this version of PAN-OS. Those who are considering  a migration from PAN-OS 6.x to PAN-OS 7.x  they...


February 24, 2016  12:55 PM

Using ECMP with Palo Alto Firewalls? Make sure you’re running PAN-OS 7

Yasir Irfan Yasir Irfan Profile: Yasir Irfan
BGP, firewall, OSPF, Routing

When it comes to using Equal Cost Multipath in Palo Alto Firewalls, one needs to be very careful as this feature is not available in all PAN-OS versions by default.  Most of the Network Engineers assume ECMP is supported by default,  and they are shocked to discover ECMP is not working when they...


Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to: