Monday, November 22, 2010
Aruba Networks and Force 10 Networks Offers Reliable Real Time High Speed WLAN for Campus
Friday, November 5, 2010
Polycom, Aruba now lead the Cloud Video Conferencing technology
Aruba said the joint solution will reduce the time, cost and network engineering needed to deliver the unified communications products to remote users working at home, in branch offices or on the road. Aruba said the cost involved in joint Aruba-Polycom remote access points can be as low as USD 99 per site. Aruba noted that its Virtual Intranet Client can deliver remote access points for virtually no cost to PC users while delivering security service economically to branches.
Sunday, October 24, 2010
Aruba Networks offers the best solution for Video over WLAN
Monday, November 23, 2009
How Oracle, Cisco to Challenge IBM, HP in Enterprise Data Centers ?
News Analysis: Oracle and Cisco Systems are working on entirely separate, but similar tracks in long-term efforts to become full-service systems providers on par with IBM and Hewlett-Packard. Oracle, a 32-year-old vendor of database and enterprise application software, will get a lot closer to that goal if it gets final regulatory clearance to close its $7.4 billion acquisition of server and storage manufacturer Sun Microsystems. Meanwhile, networking equipment vendor Cisco Systems, at 25, is focusing on its Unified Computing System initiative to expand its presence and influence in corporate data centers.
Botnets: who's behind them and why?
Sunday, February 1, 2009
How to Configure NetFlow on Cisco Routers
Configure our routers to do a few things:
1. Install Software that analyze NetFlow
2. Enable NetFlow on the router
3. Configure the router to send the logs to a netflow analyzer server (needs to be configure before)
Once you got the server or PC up and running with a netflow software (there are a lot of free application, I used Manage Engine NetFlow Analyzer 6 which allows you to monitor 2 router for free) , We need to tell the router to send the NetFlow logs to the server, To do that here is the commands we need to type:
Router(config)# ip flow-export destination {hostname|ip_address} 9996
Router(config)# ip flow-export source {interface} {interface_number}
Router(config)#ip flow-export version 5
Router(config)# ip flow-export version 5
Router(config)# ip flow-cache timeout inactive 15
Router(config)# snmp-server ifindex persist
To monitor and Check that we configured the Router to send the logs type:
Router# show ip flow export
Router# show ip cache flow
Router# show ip cache verbose flow
Configuration Sample:
router#configure terminal
router(config)#interface FastEthernet 0/1
router(config-if)#ip route-cache flow
router(config-if)#exit
router(config)#ip flow-export destination 10.60.1.254 9996
router(config)#ip flow-export source FastEthernet 0/1
router(config)#ip flow-export version 5
router(config)#ip flow-cache timeout active 1
router(config)#ip flow-cache timeout inactive 15
router(config)#snmp-server ifindex persist
router(config)#^Z
router# copy run start
router#show ip flow export
router#show ip cache flow
Thursday, October 16, 2008
How to Configure Windows 2008 DHCP Server to Perform Dynamic DNS Updates
To Configure Your DHCP Server to Perform Dynamic DNS Updates
1. In Server Manager, expand Roles, and then expand DHCP Server.
2. Expand the server name, right-click IPv4, and then click Properties.
3. Click the DNS tab. Select Enable DNS Dynamic Updates According To The Settings Below.
4. To allow the DHCP server to remove resource records after a DHCP lease expires, select the Discard A And PTR Records When A Lease Is Deleted check box.
5. To perform dynamic DNS updates for client computers that are not capable of performing their own updates, select the Dynamically Update DNS A And PTR Records For DHCP Clients That Do Not Request Updates check box. Windows 2000 and all later versions of Windows can perform their own dynamic DNS updates. Click OK.
Wednesday, April 9, 2008
Cisco, Juniper face-off on software
Network World, 06/12/00
SANTA CLARA - Speeds and feeds are not all that matters when building reliable routers for the Internet core.
Indeed, the software component of these high-speed devices may play an even larger role in ensuring that packets and sessions are not dropped. That's why Cisco is building more resiliency and redundancy into its next generation IOS software. That's also why Juniper Networks plays up the reliability of its Junos operating system.
And perhaps that's why these two rivals try to point out the deficiencies of each others' software offerings. Although Cisco has been around a lot longer than Juniper, both companies are courting the same customers in the service provider market, where Cisco is a relative newcomer.
"Juniper continues to eat away at Cisco's leading market share - which is still in the 70% range - and this trend should continue," market researcher Current Analysis stated in a recent report.
"Our broader strength is our six major releases in 18 months," says Scott Kriens, Juniper CEO, commenting on Junos. "We can deliver innovation faster than anyone else. It's that accumulated breadth that is our competitive advantage."
Eighteen months pales in comparison to 15 years, which is how long Cisco has been developing and selling IOS.
"We are the market share leader from a control plane perspective," says Martin McNealis, marketing manager in Cisco's IOS Technologies division, referring to the Multi-protocol Label Switching, VPN, voice and multicast features of the Cisco software. "We're not hearing service providers hammer the table saying we need to have [certain features] because [Juniper] has it."
It's neither Juniper nor Junos that's prompting Cisco to build more resiliency, availability and redundancy into the next major release of IOS. IOS will feature "more intelligent" handling of outages and service upgrades, McNealis says.
"We're now looking to deliver a bulletproof architecture," McNealis says. "Now that we're a systems company, we have to accept that there will be hardware and software failures."
Cisco is building stateful redundancy into IOS whereby information on the state of routes, sessions or packets can be replicated within a router chassis. Currently, Cisco offers redundancy between two distinct routers via the Hot Standby Routing Protocol in IOS.
Juniper refers to this version of IOS as IOS NG, with NG standing for "Next Generation." IOS NG is Cisco's attempt to be more competitive with Junos by having a more modular architecture and being tailored specifically for service providers, Kriens says.
Juniper's definition of modular means separate processes - such as routing protocols, management and security - each run in protected memory. Currently, IOS is "monolithic," Kriens says, meaning all processes run together and are interdependent.
"It's kind of comparing Windows with DOS," Kriens says, noting the modular nature of Windows vs. the monolithic nature of DOS.
Perhaps it's best to compare an operating system that was built from the ground up to perform routing vs. one that has its roots in a general purpose operating system such as Berkeley Sockets - the precursor to Unix - but has been modified to do routing, says Cisco's McNealis. IOS is the former while Junos is the latter.
"IOS was always tailored for infrastructure," McNealis says. "It's very network-centric. It's control plane and data plane optimization vs. a general-purpose operating system. You do make some compromises when it has to be that portable."
Juniper selected Berkeley Sockets as the source code for Junos because it was readily available in the public domain, Kriens says. But JUNOS represents 4 years and 300 to 400 man years of development on top of that Berkeley Sockets source code, he says.
"Any resemblance [to Berkeley Sockets] would be so remote as to be irrelevant," Kriens says.
Cisco, Juniper face-off on software
Network World, 06/12/00
SANTA CLARA - Speeds and feeds are not all that matters when building reliable routers for the Internet core.
Indeed, the software component of these high-speed devices may play an even larger role in ensuring that packets and sessions are not dropped. That's why Cisco is building more resiliency and redundancy into its next generation IOS software. That's also why Juniper Networks plays up the reliability of its Junos operating system.
Sunday, February 17, 2008
Cisco Nexus 7000 Series Switches
A More Scalable and Flexible Data Center
Build a flexible, scalable framework for your new data center network with Cisco Nexus Switches.
The Cisco Nexus 7000 Series is a modular data center-class switching system designed for 10 Gigabit Ethernet networks. The Cisco Nexus architecture scales beyond 15 terabits per second, with future availability of 40Gb and 100 Gb Ethernet and unified fabric I/O modules. This new platform is designed for exceptional scalability, continuous systems operation, and transport flexibility.
The Cisco Nexus 7000 Platform is powered by Cisco NX-OS, a state-of-the-art operating system. The Cisco Nexus 7000 Series is purpose-built for the data center and has many unique features and capabilities designed specifically for the most mission-critical place in the network, the data center.
Virtualisation gets a leg up
OPEN-SOURCE solutions provider Red Hat recently announced its Integrated Virtualisation Inside campaign that aims to encourage the use of virtualisation technology among open-source software users.
The company said virtualisation will become more mainstream as enterprises look for ways to boost productivity and performance of its IT infrastructures.
“The problem with most applications is that they run on specific operating systems and are hardcoded into the hardware making it difficult to deploy,” said Red Hat Asia Pacific Pte Ltd general manager for Asean, Teong Eng Guan.
“Virtualisation will allow enterprises to run their applications on multiple operating systems while enabling them to run on virtual servers.
“So instead of running one application per server, enterprises can save on electricity and real estate by running them on one server,” he said.
Red Hat’s virtualisation capability is integrated into its Red Hat Enterprise Linux 5 operating system.
Red Hat virtualisation will run on most desktop and server platforms including Intel Xeon and Itanium, AMD Opteron and IBM Power systems, Teong said
Source: The Star (Malaysia)
Malaysian Government should support an open source solution for future implementation.
Juniper offers new switches
Juniper believes the new series will allow it to compete more effectively in the crowded enterprise networking segment of the market.
“Enterprises are demanding more than what has been offered by traditional switching vendors,” said Juniper Networks Malaysia country manager Wan Ahmad Kamal. “They want performance, reliability and simplicity in a switching solution.”
He said the problem in a typical networking environment is that it is highly complex, thanks to different versions of software running on various brands of equipment.
This, he said, makes it difficult to manage and upgrade networks.
Juniper’s solution to the problem is its Junos software, which is included in the EX series. It is a single-source network operating system that simplifies operations and integrates business applications across the network, the company said.
“Aside from wanting simplicity in a network, enterprises are getting increasingly concerned about system security,” Wan Ahmad added. “The new switches will fully integrate with Juniper’s Unified Access Control solution, which allows administrators to enforce access control and security down to individual ports and users.”
The EX 3200 and EX 4200 switches will be available from next month while the EX 8200 will only be available in the second half of the year. No local pricing has been announced yet.
Tuesday, October 30, 2007
IPS gaining ground over IDS
With the growth of intrusion-prevention systems, established IPS vendors and start-ups are introducing an ever-widening array of products.
However, while IPSs appears to be usurping intrusion-detection systems (IDS) in more organizations, they come with the risk of blocking good traffic and bad.
"It's a calculated risk," says Chris Hoff, information security officer at Western Corporate Federal Credit Union (WesCorp) in San Dimas, Calif., about his company's decision to shift from IDS to IPS over the last six months.
WesCorp, which has $25 billion in assets and provides back-office management services to about 1,000 credit unions, deployed the Internet Security Systems (ISS) Proventia G-100 IPS appliance to start automatically blocking attack traffic. The main reason is that even one hit from the growing number of worms and hacker attempts would be too high a price to pay, Hoff says. However, the downside is that legitimate traffic occasionally is blocked along with attack traffic, he adds.
"Legitimate traffic can be blocked, and we spend an enormous amount of time tracking down false positives and false negatives," Hoff says. He adds that there needs to be improvement in IPS blocking to filter out the "harmful stuff" while allowing good traffic through.
In spite of the problems false positives cause - the same kind that plagued passive IDS sensors over the years - Hoff says he has no intention of giving up intrusion prevention. He adds that WesCorp isn't buying network-based IDS any more. Instead, the company is using vulnerability-assessment much more than it did in the past, and deploying products from Skybox Technologies and Qualys to determine which server and desktops require patching and updates.
Hoff says he's interested in host-based IPS, too, but is waiting for prices to drop. Costs typically run into the hundreds of dollars for the software for each server that needs protection.
According to IDC, the market for IDS and IPS together - collectively known as intrusion detection and prevention (IDP) - is about $730 million, with host-based software half of network-based software and hardware last year.
Several analyst firms, including Infonetics Research and IDC, say it's admittedly hard to figure out the exact number of blocking-capable IPS products that were sold in any year vs. IDS. This is because some of the larger IDP vendors, including ISS and Symantec, are reluctant to break this out. The reason often given is that IPS typically includes passive IDS functionality, and sometimes customers use IPS for passive monitoring or in a "mixed mode" where they block some traffic but monitor other portions.
Nevertheless, there's strong reason to believe IPS is gaining ground among enterprise customers, says Charles Kolodgy, research director for security products at IDC. He predicts that within a matter of a few years "IPS will eventually be the predominant technology."
IPS is selling better than IDS, confirms Clarence Morey, senior manager for product strategy at ISS, adding IPS is often preferred for the most mission-critical networks. ISS, which focused on software-based intrusion detection until the launch of its Proventia appliance line in mid-2003, declines to offer more detail on numbers. But in its latest quarterly legal filing at the Securities and Exchange Commission, ISS indicated that the Proventia line of IPS appliances accounted for 61% of product and license sales in the third quarter of this year, and 53% of sales revenue for the nine months of the year. ISS stated its nine-month revenue as $88.9 million, as opposed to $76.1 million for the same period a year ago. According to this statement, IPS has overtaken sales of traditional IDS.
IDC also points out that several of the top vendors in the IDP market - McAfee, NetScreen Technologies (which Juniper bought last year) and Top Layer Networks - generate their revenue through IPS products alone. IDC also cites the explosion of new market entries in the last six months as an indicator of growing demand for IPS.
On the host-based IPS side, eEye Digital Security's Blink software and products from start-ups such as Bodacion and Determina were introduced this year.
On the network-based IPS side, the new-product barrage came from start-ups such as Barrier Group, Beadwindow and Captus Networks. A few, such as Sentryware, offer network- and host-based IPS.
McAfee recently unveiled two new versions of its IntruShield IPS, the multi-gigabit models 4010 and 3000 with expanded ports for large corporations and ISPs.
Amid this cornucopia of IPS offerings, there's no shortage of early adopters willing to try network-based IPS to protect their networks through blocking.
"I look at it as a disaster-prevention element," says Eben Berry, manager of IS at managed healthcare provider Network Health in Cambridge, Mass., which serves 60,000 Medicaid recipients. The healthcare organization uses V-Secure's 100M bit/sec V-100 appliance at the perimeter to block attacks on its Web site.
Berry says the V-100 appliance doesn't rely on signatures to pinpoint attacks but instead monitors patterns of activity. On its internal LAN, Network Health deployed a different IPS: Juniper's NetScreen IDP-100, because it can filter on a bidirectional basis, something V-Secure's appliance only recently added.
Todd Woyke, engineer at Diversico Industries, a tool manufacturer in Minneapolis, decided to use Barrier Group's IPS after being blitzed repeatedly by dozens of computer worms and hackers that broke into servers. "So far, all I can say is we aren't seeing any intrusions," Woyke says, and adds he's sold on intrusion prevention.
Unclassified but Sensitive Internet Protocol Router Network Security Policy
Secret Internet Protocol Router Network (SIPRNET)
The Secret Internet Protocol Router Network (SIPRNET) has matured to be the core of our warfighting command and control capability. Many expeditionary commanders ask for SIPRNET ahead of secure voice when deploying their forces. SIPRNET is fast becoming the defacto standard of preferred data services, even over NIPRNET. The SIPRNET is the new, worldwide router-based network replacing the older X.25-based packet switched network (the Defense Secure Network One (DSNET1) of the Defense Data Network (DDN)). The initial SIPRNET backbone router network went online 3 March 1994. Subscribers started coming on line shortly thereafter. The SIPRNET WAN (as of 31 May 1995) consisted of a collection of 31 backbone routers interconnected by high-speed serial links to serve the long-haul data transport needs of secret-level DoD subscribers. Additional SIPRNET backbone routers are being planned to meet increased customer requirements. SIPRNET supports the DoD standard Transmission Control Protocol/Internet Protocol (TCP/IP) protocol service. Subscribers within the DoD and other Government Agencies are able to use the SIPRNET for passing datagrams at the Secret-Not Releasable to Foreign Nationals (SECRET-NOFORN) classification level.
Tuesday, October 23, 2007
Security and VPN Management Solution
The Cisco Security Management Suite is a framework of products and technologies designed for scalable policy administration and enforcement for the Cisco Self-Defending Network. This integrated solution can simplify and automate the tasks associated with security management operations, including: configuration, monitoring, analysis, and response. The key components of this suite are the Cisco Security Manager and the Cisco Security Monitoring, Analysis, and Response System (Cisco Security MARS).
1. Cisco Security Manager is a powerful but easy-to-use solution for configuring firewall, VPN, and intrusion prevention system (IPS) policies on Cisco security appliances, firewalls, routers, and switch modules.
2. Cisco Security MARS, is an appliance-based, all-inclusive solution that allows network and security administrators to monitor, identify, isolate, and counter security threats.
Cisco Security Manager and Cisco Security MARS can be deployed separately to provide flexibility for any network environment. However, when used together, an administrator can achieve even greater value and productivity benefits. These applications are integrated to provide an outstanding ability to continuously monitor and improve the security of the network as threats arise. This allows organizations to realize the following business benefits:
1. Simplified management of an integrated security fabric
2. Higher network availability through faster threat mitigation
3. Reduced complexity across multiple security platforms
4. IT Investment preservation
With a powerful set of applications, an integrated architecture, and a comprehensive ecosystem partner strategy, the Cisco Security Management Suite is positioned as the ideal management solution for the Cisco Self-Defending Network
Monday, October 22, 2007
Cisco Cable High Speed Data (HSD) Solutions
Cable operators have enjoyed great success offering Internet access. Cisco has the real-world experience, proven products, and advanced technologies to help you supply cable high-speed data (HSD) services, based on DOCSIS standards, for homes and businesses.
Cisco HSD solutions (Figure 1) blend broadband cable RF technology with Cisco’s highly scalable, secure, and flexible IP core technology. The Cisco portfolio includes industry-leading, DOCSIS-compliant CMTSs, leading-edge business and home CPE, and advanced IP backbone and edge products. Along with residential HSD products, Cisco offers tested business service solutions, including VPNs, Metro Ethernet, and virtual LANs, that can generate higher margins and higher revenue.
Cisco works with you to integrate its broad array of products into a single, highly productive HSD solution tailored to your needs.
How the DOCSIS-Based Solution Works
Your high-speed data backbone can be used for interconnection between different regional networks, as well as to external networks. High-speed trunks using DWDM and SONET/SDH technologies support Ethernet interfaces used by both routers and switches. The statistically multiplexed links can, in turn, use Dynamic Packet Transport (DPT), Resilient Packet Rings (RPRs), or other Ethernet transport standards such as 10 Gigabit Ethernet links.
Next-generation technology incorporates Modular CMTS architectures (M-CMTS) based on DOCSIS 3.0 downstream channel-bonding techniques that more effectively use bandwidth. Your customers can receive 100 Mbps services and beyond via your existing cable plant. You can add this new technology on a node-by-node basis, responding to competition as it arises. Our solutions let you take advantage of DOCSIS 3.0 channel bonding without a major infrastructure upgrade and also allow you to support DOCSIS 1.x, 2.0, and 3.0 simultaneously.
Figure 1 Cisco Cable DOCSIS-Based High-Speed Data Solutions
Click on a product name for more information
Thursday, October 18, 2007
Best Practices for Software Performance Testing
This Podcast highlights the best practices necessary for effective software performance testing. In this Podcast, you will learn about:
The components of performance testing
Issues performance testing uncovers
Important factors affecting software performance
The impact of Web 2.0 and Ajax on software performance testing
CLICK HERE TO PLAY THE AUDIO
--------------------------
SPEAKERS:
Paul Gillin
Principal, Paul Gillin Communications
Paul Gillin is a veteran technology journalist with more than 23 years of editorial leadership, including positions as chief editor of TechTarget and Computerworld. He is now a content marketing consultant specializing in technology and new media. He advises business-to-business marketers on how to optimize online channels to reach buyers most cost-effectively. His forthcoming book about social media, The New Influencers, will be published by Quill Driver Books in Spring, 2007.
Siva Darivemula
Director of Product Marketing, Hewlett-Packard Company
Siva Darivemula is the Director of Product Marketing for the HP Performance Center software product line. In this role, he is responsible for the go-to-market strategy of performance testing solutions. He has many years of experience with enterprise software and solutions and product marketing. He has worked at IBM, Microsoft and Adobe Systems with industry-leading solutions such as WebSphere, Microsoft Office, and Flex.
Small Business Networking
HP's c3000 aims at medium and small businesses.
If you're drooling over the advances in the world of blade servers, wishing you could afford a rack or two of them, that day may arrive sooner than you think. Looking to replace the jumble of servers stacked in the storage closet, er, server room? Don't have a fancy raised floor and heavy duty air conditioner? No problem.
Of course, if you read about the heavy power requirements for a rack full of blades, such as three phase power modules, you figure blades will elude you forever. When you read about problems large companies have cooling a cabinet full of 64 blade servers, all with two processors and 32GBs of RAM generating heat like the August sun, you may be glad to avoid such headaches.
But the truth is blade servers create less heat, and require less power, than stand-alone servers with the same horsepower. They just need the power and cool air in one small spot. Second generation blade server chassis now do a better job dispersing the heat generated by blades than ever before, and cooling product vendors have adapted their tools to better handle the heat created by racks of blade servers. Still takes work, but it is getting easier.
Even better, HP now has a smaller blade enclosure system called the c3000, or Shorty. The company based the unit on the enterprise class c7000 blade enclosure used by the big data centers, so many parts from the high end system work in the c3000, such as the special cooling fans. Aiming at branch offices of large companies, HP actually made a great “introductory” blade server system for small and midsize businesses.
The best thing about the c3000 for small businesses is its ability to run in the same kind of environment your current servers do: the “nothing special” environment. It runs on power from a normal 120 volt wall socket. It runs in rooms cooled by standard office air conditioning. In other words, you can get a blade system and treat it as badly as you treat your current servers. There's no need to upgrade your storage closet/server room.
Blade system vendors say the price for blades evens out with stand-alone servers when buying five servers. You have to amortize the cost of the chassis over five servers to get the individual server cost down to match similar stand-alone server pricing. While it's more efficient to provide power and cooling fans in the chassis for multiple servers rather than in each case for stand-alone servers, that does drive up the cost of the chassis. Blade production volumes continue to increase, but traditional servers still get lower pricing from higher volume production runs.
Full height blade servers aren't much smaller than the rackable 1U pizza box style servers they replace. They moved the cooling and power supplies off the server motherboard into the chassis, but they didn't make a huge leap in server density. Blades reduced management overhead and did away with 9 of 10 cables used inside a normal rack, but the server density didn't jump way up.
HP's half height blades, however, pack two complete servers into the same space as one of their full height blade slots. Since the c3000 Shorty chassis can handle four full height blades, eight half height blades, or any combination that works mathematically, you can choose exactly what your blade server system includes.
These second generation blade servers, both full and half height, include more storage options onboard and storage blades, packed with hard disks rather than processors, provide additional capacity as well. The release of 3.5 inch hard drives with 1 terabyte of data space really allows you to pack plenty of storage into a small space. In this case, pack it into a small slot.
Blade technology dominates future plans in large data centers. For the first time, small and growing businesses can jump into blade territory without worrying about concentrated cooling and power demands faced by the enterprise data centers.
Keep an eye on Network World's review pages. Tom Henderson, a fellow member of the Test Alliance, has a c3000 on his testing bench for review right now.
Although vendors only promise you'll come out even price-wise if you buy five blade servers, you should plan ahead a little. If you need three servers now, or even two, check out the c3000, especially if you know your next server purchase will be within a few months.
Like the book from the '70s said, small is beautiful. Small and powerful, however, is gorgeous.