<?xml version="1.0" encoding="UTF-8"?>
<!--Generated by Squarespace Site Server v5.9.2 (http://www.squarespace.com/) on Wed, 10 Mar 2010 10:17:54 GMT--><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><title>showcrypto</title><link>http://www.showcrypto.com/showcrypto/</link><description></description><lastBuildDate>Fri, 19 Feb 2010 20:38:10 +0000</lastBuildDate><copyright></copyright><language>en-US</language><generator>Squarespace Site Server v5.9.2 (http://www.squarespace.com/)</generator><item><title>INE SECURITY WORKBOOK - 1.6 IP Access-Lists</title><category>INE</category><category>LAB</category><category>WORKBOOK</category><dc:creator>Admin</dc:creator><pubDate>Fri, 19 Feb 2010 20:18:09 +0000</pubDate><link>http://www.showcrypto.com/showcrypto/2010/2/19/ine-security-workbook-16-ip-access-lists.html</link><guid isPermaLink="false">331243:3485891:6759624</guid><description><![CDATA[<p>This section was pretty straight forward. &nbsp;Everything worked as advertised. &nbsp;I did make an initial mistake in my ACL for allowing NTP traffic. &nbsp;I made the mistake and setup the ACL using TCP instead of UDP, which confused me when it would not accept "eq ntp" on the end. This was easily corrected.</p>
<p>&nbsp;</p>]]></description><wfw:commentRss>http://www.showcrypto.com/showcrypto/rss-comments-entry-6759624.xml</wfw:commentRss></item><item><title>INE SECURITY WORKBOOK - 1.5 Advanced Routing</title><category>INE</category><category>LAB</category><category>WORKBOOK</category><dc:creator>Admin</dc:creator><pubDate>Mon, 15 Feb 2010 21:29:52 +0000</pubDate><link>http://www.showcrypto.com/showcrypto/2010/2/15/ine-security-workbook-15-advanced-routing.html</link><guid isPermaLink="false">331243:3485891:6702259</guid><description><![CDATA[<p>This section introduced a command I have never used, "track". &nbsp;It is basically a way to setup a "smart" static route. &nbsp;This is a very handy command.</p>
<p>"a static route tracking feature is used to track the availability of a static route and, if that route fails, remove it from the routing table and replace it with a backup route."</p>
<p>ASA/PIX 7.x: Redundant or Backup ISP Links Configuration Example</p>
<p>http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml</p>]]></description><wfw:commentRss>http://www.showcrypto.com/showcrypto/rss-comments-entry-6702259.xml</wfw:commentRss></item><item><title>Quoted in February 2010 issue of Information Security Magazine</title><dc:creator>Admin</dc:creator><pubDate>Mon, 15 Feb 2010 20:52:18 +0000</pubDate><link>http://www.showcrypto.com/showcrypto/2010/2/15/quoted-in-february-2010-issue-of-information-security-magazi.html</link><guid isPermaLink="false">331243:3485891:6701891</guid><description><![CDATA[<p>Disaster recovery plans and DLP solutions top 2010 priorities</p>
<p>http://searchsecurity.techtarget.com/magazineFeature/0,296894,sid14_gci1380343_mem1,00.html</p>]]></description><wfw:commentRss>http://www.showcrypto.com/showcrypto/rss-comments-entry-6701891.xml</wfw:commentRss></item><item><title>Published Article on SearchSecurity.com</title><dc:creator>Admin</dc:creator><pubDate>Mon, 15 Feb 2010 20:38:02 +0000</pubDate><link>http://www.showcrypto.com/showcrypto/2010/2/15/published-article-on-searchsecuritycom.html</link><guid isPermaLink="false">331243:3485891:6701825</guid><description><![CDATA[<p>Here is a link to an article I wrote on implementing firewall egress filtering for SearchSecurity.com</p>
<p>&nbsp;</p>
<div id="_mcePaste">NETWORK SECURITY TACTICS</div>
<div id="_mcePaste">How to properly implement firewall egress filtering</div>
<p>Deploying egress firewall traffic filtering is sometimes easier said than done. Deployment may seem simple: Implement an access control list (ACL) on a firewall to block all outbound traffic, then only allow traffic that is approved by the company's security policy.</p>
<p>&nbsp;</p>
<p>http://searchsecurity.techtarget.com/tip/0,289483,sid14_gci1378492,00.html</p>]]></description><wfw:commentRss>http://www.showcrypto.com/showcrypto/rss-comments-entry-6701825.xml</wfw:commentRss></item><item><title>INE SECURITY WORKBOOK - 1.4 EIGRP</title><category>INE</category><category>LAB</category><category>WORKBOOK</category><dc:creator>Admin</dc:creator><pubDate>Mon, 15 Feb 2010 20:13:44 +0000</pubDate><link>http://www.showcrypto.com/showcrypto/2010/2/15/ine-security-workbook-14-eigrp.html</link><guid isPermaLink="false">331243:3485891:6701642</guid><description><![CDATA[<p>The only question I had regarding this lab was disabling OSPF on the connection to R4. &nbsp;The command in the solution guide appears to be incomplete. This may be due to my lab running PIX instead of ASA. &nbsp;To disable OSPF on my PIX the command is:</p>
<p>&nbsp;<em>Rack1ASA1(config)#router osfp 1</em></p>
<div id="_mcePaste"><em>&nbsp;Rack1ASA1(config-router)# no network 136.1.124.0 255.255.255.0 <strong>area 1</strong></em></div>
<p>&nbsp;</p>
<p>The solution guide does not include the "area 1". &nbsp;I will test this on an ASA to see if it behaves the same.</p>
<p>&nbsp;****Update 02.19.2010****</p>
<p>The "area 1" is also required on the ASA</p>]]></description><wfw:commentRss>http://www.showcrypto.com/showcrypto/rss-comments-entry-6701642.xml</wfw:commentRss></item><item><title>INE SECURITY WORKBOOK - 1.2 RIP v2, 1.3 OSPF</title><category>INE</category><category>LAB</category><category>WORKBOOK</category><dc:creator>Admin</dc:creator><pubDate>Mon, 15 Feb 2010 20:11:29 +0000</pubDate><link>http://www.showcrypto.com/showcrypto/2010/2/15/ine-security-workbook-12-rip-v2-13-ospf.html</link><guid isPermaLink="false">331243:3485891:6701594</guid><description><![CDATA[<p>Nothing to report here. &nbsp;These labs went as expected.</p>]]></description><wfw:commentRss>http://www.showcrypto.com/showcrypto/rss-comments-entry-6701594.xml</wfw:commentRss></item><item><title>INE Security Workbook - 1.1 VLANS and IP addressing</title><category>INE</category><category>LAB</category><category>WORKBOOK</category><dc:creator>Admin</dc:creator><pubDate>Wed, 13 Jan 2010 22:20:54 +0000</pubDate><link>http://www.showcrypto.com/showcrypto/2010/1/13/ine-security-workbook-11-vlans-and-ip-addressing.html</link><guid isPermaLink="false">331243:3485891:6316386</guid><description><![CDATA[<p>Comments and observations from CCIE Security Lab Workbook Volume I Version 5.0</p>
<p>ASA Firewall&nbsp;1.1 VLANS and IP addressing</p>
<p>This section was pretty straight forward; however I did get some inconsistencies from my lab equipment compared to the solution guide. &nbsp;These verification inconsistencies did not take away from the overall objectives of this section.</p>
<p>My verification result (from Switch1):</p>
<p><em style="font-size: 90%;"><span style="font-size: 90%;">Rack1SW1#show interface trunk</span></em></p>
<p><em style="font-size: 90%;"><span style="font-size: 90%;">Port&nbsp; &nbsp; &nbsp; &nbsp; Vlans in spanning tree forwarding state and not pruned</span></em></p>
<p><em style="font-size: 90%;"><span style="font-size: 90%;">Fa0/21&nbsp; &nbsp; &nbsp; 1,100,120-121,124</span></em></p>
<p><em style="font-size: 90%;"><span style="font-size: 90%;">Fa0/22&nbsp; &nbsp; &nbsp; </span></em><em><span style="font-size: 90%;">none</span></em></p>
<p><em style="font-size: 90%;"><span style="font-size: 90%;">Fa0/23&nbsp; &nbsp; &nbsp; </span></em><em><span style="font-size: 90%;">none</span></em></p>
<p>&nbsp;****The solution guide says ports Fa0/22 - 23 should display the same results as Fa0/21. Why would Fa0/22 and Fa0/23 show "none"? I haven't figured this out.&nbsp;</p>
<p>&nbsp;</p>
<p>My verification result (from Switch2):</p>
<p><em style="font-size: 90%;"><span style="font-size: 90%;">Rack1SW2#show interfaces trunk</span></em></p>
<p><em style="font-size: 90%;"><span style="font-size: 90%;">Port&nbsp; &nbsp; &nbsp; &nbsp; Mode &nbsp; &nbsp; &nbsp; &nbsp; Encapsulation&nbsp; Status&nbsp; &nbsp; &nbsp; &nbsp; Native vlan</span></em></p>
<p><em style="font-size: 90%;"><span style="font-size: 90%;">Fa0/13&nbsp; &nbsp; &nbsp; on &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 802.1q &nbsp; &nbsp; &nbsp; &nbsp; trunking&nbsp; &nbsp; &nbsp; 1</span></em></p>
<p><em style="font-size: 90%;"><span style="font-size: 90%;">Fa0/21&nbsp; &nbsp; &nbsp; </span></em><strong><em style="font-size: 90%;"><span style="font-size: 90%;">on</span></em></strong><em style="font-size: 90%;"><span style="font-size: 90%;"> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 802.1q &nbsp; &nbsp; &nbsp; &nbsp; trunking&nbsp; &nbsp; &nbsp; 1</span></em></p>
<p><em style="font-size: 90%;"><span style="font-size: 90%;">Fa0/22&nbsp; &nbsp; &nbsp; </span></em><strong><em style="font-size: 90%;"><span style="font-size: 90%;">on</span></em></strong><em style="font-size: 90%;"><span style="font-size: 90%;"> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 802.1q &nbsp; &nbsp; &nbsp; &nbsp; trunking&nbsp; &nbsp; &nbsp; 1</span></em></p>
<p><em style="font-size: 90%;"><span style="font-size: 90%;">Fa0/23&nbsp; &nbsp; &nbsp; </span></em><strong><em style="font-size: 90%;"><span style="font-size: 90%;">on</span></em></strong><em style="font-size: 90%;"><span style="font-size: 90%;"> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 802.1q &nbsp; &nbsp; &nbsp; &nbsp; trunking&nbsp; &nbsp; &nbsp; 1</span></em></p>
<p>***The solution guide says ports Fa0/21 - 23 should be "auto".&nbsp;I can make my results look like the solution guide by changing the provided intial config for SW2 ports Fa0/21, Fa0/22, Fa0/23</p>
<p>from:&nbsp;<em><strong>switchport mode trunk</strong></em></p>
<p>to:&nbsp;<strong><em>switchport mode dynamic auto</em></strong></p>]]></description><wfw:commentRss>http://www.showcrypto.com/showcrypto/rss-comments-entry-6316386.xml</wfw:commentRss></item><item><title>Squarespace iPhone App</title><dc:creator>Admin</dc:creator><pubDate>Thu, 03 Dec 2009 03:53:17 +0000</pubDate><link>http://www.showcrypto.com/showcrypto/2009/12/3/squarespace-iphone-app.html</link><guid isPermaLink="false">331243:3485891:5975032</guid><description><![CDATA[<p>This is my first post using the Squarespace iPhone app.</p>]]></description><wfw:commentRss>http://www.showcrypto.com/showcrypto/rss-comments-entry-5975032.xml</wfw:commentRss></item><item><title>Cisco Terminal Server</title><category>LAB</category><dc:creator>Admin</dc:creator><pubDate>Mon, 23 Nov 2009 18:53:39 +0000</pubDate><link>http://www.showcrypto.com/showcrypto/2009/11/23/cisco-terminal-server.html</link><guid isPermaLink="false">331243:3485891:5891692</guid><description><![CDATA[<p>I needed a very inexpensive terminal server to provide console access to my security lab. I purchased an 8 Port USB To RS232 Adapter from StarTech.&nbsp;</p>
<p>http://www.startech.com/item/ICUSB2328-8-Port-USB-To-RS232-Adapter.aspx</p>
<p>I found this on Amazon for $144. &nbsp;I attached this to the Dell Latitude D600, which is running XP. &nbsp;This solution works great. &nbsp;I RDP into the laptop and have CON access to 8 devices.</p>]]></description><wfw:commentRss>http://www.showcrypto.com/showcrypto/rss-comments-entry-5891692.xml</wfw:commentRss></item><item><title>Building A Security Lab - Part 2</title><category>INE</category><category>LAB</category><dc:creator>Admin</dc:creator><pubDate>Mon, 23 Nov 2009 17:19:30 +0000</pubDate><link>http://www.showcrypto.com/showcrypto/2009/11/23/building-a-security-lab-part-2.html</link><guid isPermaLink="false">331243:3485891:5890885</guid><description><![CDATA[<p>I have scrapped the previous security lab I was working on. &nbsp;I have been able to acquire the following physical equipment:</p>
<p>2 - 3550-24 12.2 IP Services&nbsp;</p>
<p>4 - 2610XM 12.4(15)T11 ADV. Security</p>
<p>2 - PIX 525 8.0(4)&nbsp;</p>
<p>1 - Dell 1750 Running Windows 2003 with VMware Server</p>
<p>1 - Dell Latitude D600</p>
<p>All of this equipment is cabled according to the INE Lab Physical Interface Connections document.&nbsp;</p>
<p>This should get me through the majority of the VOL1 Workbook. &nbsp;I thought I had access to an ASA 5510, but I will have to get by using a 5505 for ASA only features.</p>
<p>&nbsp;</p>]]></description><wfw:commentRss>http://www.showcrypto.com/showcrypto/rss-comments-entry-5890885.xml</wfw:commentRss></item></channel></rss>