My Apps on Ubuntu

May 12, 2012

0

The Ubuntu is my best OS after Fedora. The basic installation contains many applications I need, but not all. I am pretty sure that I will reinstall my linux and those apps should I install again: – skype from http://www.skype.com/intl/en-us/get-skype/on-your-computer/linux/ – openssh-server – secure shell (SSH) server, for secure access from remote machines – virtualbox […]

Posted in: Linux

external CA for Remote Access VPN

May 9, 2012

19

Checkpoint has a complete Certificate Authority infrastructure and I would use it for small and medium sized businesses where there is only some user for remote access. For large enterprises or for companies with existing CA infrasturcture it is worth to use their certificates, because it gives much more flexibility. In this example I illustrate […]

Posted in: Checkpoint, Security, VPN

Virtualbox – the tool I use for virtualization of course with CLI

April 24, 2012

0

The Task: Create your virtual machine on a linux server and install it without X. Ohh, without GUI? iI must be difficult or not? Lets see it, to belive it. First I had to update the server and then install virtualbox. It can be done easily with apt. As my test server is behind a […]

Certficate renewal – how was it after years?

April 18, 2012

0

Actually you cannot renew an existing certificate, but you can generate a new one with the same subject and same mandatory fields. For that you have to generate a certificate request again within a new trustpoint and not with the old one. The issuer of the previous certificate should sign the new certificate request and […]

Posted in: ASA, Cisco, Security, VPN

Edge troubleshooting note

April 17, 2012

0

Its April, but I have just realised the new features of Checkpoint Edge Firewall, in my point of view it is the worst firewall I have ever seen regarding the granurality in management or in troubleshooting, but it works fine as its expected and its small and nice and can be integrated under the same […]

Posted in: Checkpoint, Edge, Security

openssl update on ddwrt, is it Checkmate or Check?

April 17, 2012

0

After reading an old articel on TLSv1 vulnerability I wanted to test it. The website I have red about this TLSv1 Issue: http://www.theregister.co.uk/2011/09/19/beast_exploits_paypal_ssl/ After reading I wanted to look for a webserver that support TLSv1. For that task I need only an openssl on a device with public internet access, that is actually my ddwrt […]

Posted in: Linux, openssl, Security

Debugging Fortigate VPNs

March 22, 2012

12

In the following post I will do some “research” on VPN debugs in Fortigate. It may usefull for those who has basic Foritgate VPN problems or the peer Fortigate has a Problem. Debugging should be usefull for troubleshooting, but should not only be used for troubleshooting. It should be used to understand and see how […]

Network topology with graphviz – Task 3.

March 20, 2012

1

Task 3. Create the input data for digraph: IPSO Firewall ‘clish -c “show route static”‘ output (filename: fw_static_routes_firewall1.txt): S 30.30.30.0/24 via 10.10.10.10, ae1c0, cost 0, age 6132971 S 40.40.40.0/24 via 10.10.10.10, ae1c0, cost 0, age 6132972 S 50.50.50.0/24 via 10.10.10.10, ae1c0, cost 0, age 6132973 S 60.60.60.0/24 via 20.20.20.10, ae2c1, cost 0, age 6132974 S […]

Network topology with graphviz – Task 2.

March 20, 2012

1

Task 2. List the interface name, the network address and the IP Address and the the DNS suffix. IPSO Firewall ‘clish -c “show route direct”‘ output (filename: fw_direct_routes_firewall1.txt): C 127.0.0.1/32 is directly connected, loop0c0 C 10.10.10.0/29 is directly connected, ae1c0 C 20.20.20.0/28 is directly connected, ae2c1 C 80.80.80.0/28 is directly connected, ae3c1 . # awk […]

Network topology with graphviz – Task 1.

March 20, 2012

1

Task 1. List the interface name, the IP address and the DNS suffix for the domain the IP belongs to. IPSO Firewall ‘clish -c “show interfaces”‘ output (filename: fw_interfaces_firewall1.txt): Physical Interface ae1 Up Logical Interface ae1c0 Active On link_avail Up Type i802.3ad IP Address Destination 10.10.10.1 10.10.10.0/29 Physical Interface ae2 Up Logical Interface ae2c0 Active […]