Showing posts with label Firewall. Show all posts
Showing posts with label Firewall. Show all posts

Friday, June 10, 2011

Circumventing the Chinese Firewall

When you are trying to access western websites from within China, you will find they are very slow loading and in some cases just don't load at all. The main reason for this slow speed and unreliability is that all your network traffic is being routed through government servers.

Overall, the Internet is slowed down because every bit of information has to pass through these servers that do the filtering. These servers look for flagged keywords and/or phrases such as "communism", "government" or "Tiananmen Square". They also check to see if you are attempting to access a blacklisted website, and if so, the connection is interrupted and your left with an error page.

This process can dramatically slow down access to websites that are outside of china. For the average foreign user in China, this can be pretty frustrating. But for a foreign enterprise operating in China, the effects can be much worse. If your company relies on the internet for communications like most do, then this can cause complications between you, your headquarters and clients. If the internet is an integral part of your business e.g. a web development company, then this could seriously impede your operations.

The solution, a proxy. You have heard of proxies, they are complicated to setup and not very convenient right? Wrong.

There are many proxy providers out there, some are free and some you must pay for to use their services. Many providers have a free service that are decent speeds and have a number of servers around the world, many of which can be used to find the one that provides you with the best speed. There are also many paid proxies, which give you access to greater speeds and a range of other features, such as multiple connections etc.

I have used a free proxy since I arrived in China, it has allowed me to play my favorite MMORPGS (EVE and WOW) and view all the websites I've wanted to. The only draw back to using a free service is that you are disconnected after a few hours or so, this is not a problem as you can easily press reconnect.

For a corporate user, the paid options would be of little consequence when compared with the amount of "freedom" you are getting. Your team can now access any website, know for sure that all communications are getting through and are able to develop freely using the internet.

Just how it should be.




Tom C W Higgins

For more information relating to 3D or character creation check out my site.
http://www.3dmaxit.com

My Links : find more about best Hoover Tempo Widepaths you can find more best about wheelchair cup holder come to wheelchair cup holder save find more about blueant come to blueant review Scansnap S1500 Cheap can help you find more best about Scansnap

Tuesday, June 7, 2011

IP Spoofing and IPS Protection With a Cisco ASA 5500 Firewall

The Cisco ASA firewall appliance provides great security protection out-of-the box with its default configuration. However, to increase the security protection even further, there are several configuration enhancements that can be used to implement additional security features. Two of these features are IP Spoofing protection and basic Intrusion Prevention (IPS) support.

IP Spoofing Protection

IP spoofing attacks are those that change the actual source IP address of packets to obscure their true origin. This means that packets arriving at a particular interface (e.g inside) must have a valid source IP address that matches the correct source interface according to the firewall routing table. Normally the firewall only looks at the destination address of a packet in order to forward it accordingly. If you enable the IP Spoofing mechanism, the firewall checks also the source address of the packets.

If for example our inside interface connects to internal network 192.168.1.0/24, this means that packets arriving at the inside firewall interface must have a source address in the range 192.168.1.0/24 otherwise they will be dropped (if IP Spoofing is configured).

The IP Spoofing feature uses the Unicast Reverse Path Forwarding (Unicast RPF) mechanism, which dictates that for any traffic that you want to allow through the security appliance, the security appliance routing table must include a route back to the source address.

To enable IP Spoofing protection, enter the following command:

CiscoASA5500(config)# ip verify reverse-path interface "interface_name"
For example, to enable IP spoofing on the inside interface, use the following command:
CiscoASA5500(config)# ip verify reverse-path interface inside

Basic IPS Protection

Although the ASA Firewall supports full IPS functionality with an extra IPS hardware module (AIP-SSM), it supports also basic IPS protection which is built-in by default without using an extra hardware module. The built-in IPS feature supports a basic list of signatures and you can configure the security appliance to perform one or more actions on traffic that matches a signature. The command that implements the basic IPS feature is called "ip audit".

There are two signature groups embedded in the firewall software: "Informational" and "Attack" signatures. You can define an IP audit policy for each signature group as following:

For informational signatures:

CiscoASA5500 (config)# ip audit name "name" info [action [alarm] [drop] [reset]]
For attack signatures:
CiscoASA5500 (config)# ip audit name "name" attack [action [alarm] [drop] [reset]]
The keywords [alarm], [drop], [reset] define the actions to perform on a malicious packet that matches one of the signatures. [alarm] generates a system message showing that a packet matched a signature, [drop] drops the packet, and [reset] drops the packet and closes the connection.

After defining an IP audit policy (IPS policy) as shown above, we need to attach the policy to a specific interface:

CiscoASA5500 (config)# ip audit interface "interface_name" " policy_name"

Let's see an actual example:

CiscoASA5500 (config)# ip audit name dropattacksattack action drop
CiscoASA5500 (config)# ip audit interface outside dropattacks
You can visit my website in my resource box below for more information about Cisco products and solutions. You can also learn how to configure any Cisco ASA 5500 Firewall Here.




You can check out my website Cisco Networks Training for more Cisco configuration examples and other related details about designing and implementing Cisco solutions. The following link is about Cisco ASA training.

Tags : find more about best Hoover Tempo Widepaths find best and save Cookware Set come to Cookware Set Reviews