Wednesday, June 13, 2012

Hardware-based Firewall, Ensure Your Business’ Security


Firewalls play a critical role in protecting an organization’s network from a never-ending list of Internet-borne threats. Firewall selection also often determines how easily remote locations connect to centralized systems to access essential resources or to complete important tasks. When you choose a hardware-based firewall, consider these 10 factors to ensure that your business maximizes its investment, security, and productivity.
                                                        
1: Trusted security
Numerous entities market unified threat management devices. With a variety of business models, some network security devices include a broad range of features and services at premium prices, while others include only essential services but for lower cost.
Be sure to select a well-recognized and trusted platform. Barracuda, Cisco, SonicWALL, and WatchGuard are among the brands having carved market share, and they’ve earned that market share for good reason: They deliver trusted security. Whichever brand you select, confirm that the firewall is ICSA certified, the industry standard for packet inspection.

2: Approachability
Global multinational enterprises typically require excessive security controls, but even those organizations that need tremendous protection don’t have to limit themselves to command-line-only configured equipment. Many firewall models deliver tight security and offer GUI-friendly administration.
The benefits are several. GUIs help prevent installation mistakes. GUIs make it easier to diagnose and correct failures. GUIs make it easier to train staff and implement changes, upgrades, and replacement.
When selecting a hardware-based firewall, consider the benefits of approachability. The easier a platform is to administer, the easier it will be to locate professionals capable of installing, maintaining, and troubleshooting the platform.

3: VPN support
A firewall’s purpose isn’t just to keep hackers and unauthorized traffic out of the network. A good firewall also establishes and monitors secure channels, enabling remote connectivity. Look for a hardware-based firewall that supports both SSL- and IPSec- protected VPN connections from similar devices (for point-to-point or site-to-site VPNs), as well as secure connections from traveling employees.

4: Capacity
Firewalls, due to their network role, typically serve as an organization’s Internet gateway. Smaller offices may leverage a firewall in a dual capacity, to serve as both a security device and as a network switch. Larger organizations, meanwhile, usually just drop the firewall into a larger architecture in which the firewall’s only role is to filter traffic.

Confirm that a firewall can manage assigned loads. This means ensuring that it has the appropriate number of Ethernet ports and the appropriate speeds (10Mbps/100Mbps and/or 1000Mbps, if necessary). But there’s more. Ensure that the firewall you select and/or maintain has the CPU capacity necessary to perform packet inspection, gateway security services, and routing functions.

Pay close attention to the manufacturer’s recommendations for maximum node support. Exceed a router’s capacity and you’ll experience errors, flat-out traffic denials due to lack of licenses, and/or unacceptable performance.

5: Technical support
Hardware fails. Worse, just because a device is new and fresh from the factory doesn’t mean it will work properly. Check that 24×7 technical support is available and implement technical support contracts with the firewall’s manufacturer.

Before purchasing, call a manufacturer’s technical support team and ask configuration and deployment questions. The quickness and accuracy of the responses you receive will reveal much as to the service you will receive when the unit fails in the field.

6: Secure wireless
Even if an organization doesn’t believe it’s needed, consider hardware-based firewalls that include wireless network features. IT staff can deploy the units with the wireless service disabled. The costs of adding WLAN functionality to a new purchase are incremental, yet when guest access or network flexibility is required, secure wireless connectivity is just a few clicks away (and an entirely new router need not be purchased). And as an organization’s needs change, the WLAN functionality may prove necessary.

7: Gateway security services
Many organizations successfully reduce costs by centralizing virus, spyware, and spam protection on their firewall. When comparing firewall capabilities and determining total costs of ownership, factor the cost savings that can result if you deploy these services on the firewall device, versus a traditional domain controller or other server.

8: Content filtering
While many IT departments are migrating to OpenDNS for content filtering purposes, some firewall manufacturers offer Web filtering subscriptions. The benefit is that all the network services associated with a business, from gateway security services to content filtering, can be consolidated on a single device. The drawback is that you have to pay for the privilege.
When reviewing potential hardware-based firewall solutions, consider your organization’s needs and budget. Determine whether content filtering should be administered from the firewall. If the answer is yes, select a firewall that supports reliable, proven content filtering.

9: Advanced monitoring and reporting
Firewalls manage critical network tasks. Repeatedly throughout just one business day, a single router can block thousands of intrusion attempts, detect consolidated attacks, and log failing or failed network connections. But this information is helpful to network administrators only if it’s available in a readily accessible format.

Look for firewalls that not only monitor important events, but that also logs this data in compatible formats. A good firewall should generate email alerts, too, at least for critical events.

10: Failover
Some organizations require WAN failover, or redundant Internet connections with automatic fault detection and correction. Many firewall models don’t have support for automatic failover. If that feature is critical to your organization, confirm that the model you select includes seamless failover; don’t assume high-end firewalls include such functionality by default.

In addition, make sure the model you select supports the failover methods your organization will use. For example, a unit possessing two RJ-45 WAN Ethernet ports will do no good if the second connection is to run off a cellular card. In such cases, appropriate integrated USB support for GSM cards or adapters may be required.

Thursday, June 7, 2012

Cisco 880 Series Routers, What’s Its Bright Points?


Cisco 880 Series Integrated Services Routers, a type of fixed-configuration router, provide collaborative business solutions for secure voice and data communication to small businesses and enterprise teleworkers. Cisco 880 routers offer concurrent broadband services over third-generation (3G), Metro Ethernet, and multiple DSL technologies to provide business continuity.

The Cisco 880 Series delivers features including firewall, content filtering, VPNs, and wireless LANs (WLANs) at broadband speeds to small offices.

To know further information, we can check the following details of what Cisco router 880 series offer:
a.      High performance for broadband access in small offices and small branch-office and teleworker sites
b.      Collaborative services with secure analog, digital voice, and data communication
c.       Business continuity and WAN diversity with redundant WAN links: Fast Ethernet, G.SHDSL, Multi-mode DSL (VDSL2 and ADSL2/2+), 3G, and ISDN
d.      Survivable Remote Site Telephony (SRST) voice continuity for enterprise small branch-office and teleworker sites
e.      Enhanced security, including:
. Firewall with advance application and control for email, Instant Messaging (IM), and HTTP traffic
. Site-to-site remote-access and dynamic VPN services: IP Security (IPsec) VPNs (Triple Data Encryption Standard [3DES] or Advanced Encryption Standard [AES]), Dynamic Multipoint VPN (DMVPN), Group Encrypted Transport VPN with onboard acceleration, and Secure Sockets Layer (SSL) VPN
. Intrusion prevention system (IPS): An inline, deep-packet inspection feature that effectively mitigates a wide range of network attacks
. Content filtering: A subscription-based integrated security solution that offers category-based reputation rating; keyword blocking; and protection against adware, malware, spyware, and URL blocking
f.        Four-port 10/100 Fast Ethernet managed switch with VLAN support; two ports support Power over Ethernet (PoE) for powering IP phones or external access points
g.      Secure 802.11g/n access-point option based on draft 802.11n standard with support for autonomous or Cisco Unified WLAN architectures
h.      CON/AUX port for console or external modem
i.        One USB 1.1 port for security eToken credentials, booting from USB, and loading configuration
j.        Easy setup, deployment, and remote-management capabilities through web-based tools and Cisco IOS Software

List some hot Cisco 880 Series Data Models
Cisco 881: WAN Interface : 10/100-Mbps Fast Ethernet
         LAN Interfaces: 4-port 10/100-Mbps managed switch
         802.11g/n Option: Cisco 881W
         Integrated 3G:Cisco 881G

Cisco 888: WAN Interface: G.SHDSL (ATM)
          LAN Interfaces: 4-port 10/100-Mbps managed switch
          802.11g/n Option: Cisco 888W
          Cisco 888W:Cisco 888G
          Integrated ISDN Dial Backup: Yes

In one word, the Cisco 880 series enable enterprise IT managers and service providers to take full advantage of a solution that can be easily set up at the remote site and can be centrally managed to reduce ongoing operational costs.

If you are a small business, or enterprise small branch office, will you select a Cisco router 880? Hard to choose? Ok, you can check the full list of Cisco 880 series at RouterSwitch.com to help you make it.

Reference:
http://www.cisco.com/en/US/prod/collateral/routers/ps380/data_sheet_c78_459542.html


After overview on Cisco 880 Series Integrated Services Routers, if you want to better know features and benefits of Cisco Router 880, you can check the table as follows to determine to buy or not to buy. Here it is:
Feature
Benefit
Increased performance to run concurrent services
• Cisco 880 Series Router performance allows customers to take advantage of broadband network speeds while running secure, concurrent data, voice, video, and wireless services.




Enhanced security
• An integrated stateful and application inspection firewall provides network perimeter security.
• High-speed IPsec 3DES and AES encryption offers data privacy over the Internet.
• Intrusion prevention enforces security policy in a larger enterprise or service provider network.
• Content filtering offers category-based URL classification and blocking, thus providing increased productivity and better use of company resources.
WAN Diversity
• Multiple WAN links: Fast Ethernet, Multi-mode VDSL2/ADSL2/2+, G.SHDSL, 3G, and ISDN.
Redundant WAN links
• Redundant WAN links provide business continuity and WAN diversity with

Four-port 10/100-Mbps managed switch
• The Cisco 880 Series allows for connection of multiple devices in a small office, with the ability to designate a port as the network edge.
• An optional external PoE adapter powers IP phones and external access points to avoid individual power supplies or power injectors.
• VLANs allow for secure segmentation of network resources.
CON/AUX port
• A single dual-purpose port provides direct connection to a console or external modem for management or backup access points.



Optional 802.11g/n access point
• This broadband router offers a secure integrated access point in a single device.
• This integrated Wi-Fi access point offers IEEE 802.11n draft 2.0 standard support for mobile access to high-bandwidth data, voice, and video applications through the use of multiple-input, multiple-output (MIMO) technology that provides increased throughput, reliability, and predictability.
• The Cisco 880 Series supports both autonomous and unified modes.

Real-time clock
• A built-in real-time clock maintains an accurate date and time for applications that require an accurate time stamp, such as logging and digital certificates.
SRST (supported on SRST models)
• SRST provides business continuity for voice when the WAN link fails by switching calls to the PSTN.
Cisco Configuration Professional
• Cisco Configuration Professional uses smart wizards and task-based tutorials, which resellers and customers can use to quickly and easily deploy, configure, and monitor a Cisco access router without requiring knowledge of the Cisco IOS Software command-line interface (CLI).
Unified wireless management
• Configuration and management of access points is automated and simplified without manual intervention.
• A unified hybrid remote-edge access point (HREAP) provides the following:
• WLAN services to remote and branch offices without deploying a wireless LAN controller at each location
• Central configuration and control of unified WLAN services for remote offices through a WAN link
• Flexibility in setting up wireless access at remote locations by specifying how traffic is to be bridged or tunneled

Sunday, June 3, 2012

Cisco 6500 Series: Retired Veteran or Re-discovered Super Soldier?


Tried and true isn't a descriptor awarded lightly. It's earned only after emerging battle-hardened from the front lines. It doesn't matter if you're the only survivor of the super-soldier program, or the flagship switch in the armada that is Cisco - history speaks for itself. For just a moment let's take a quick look at that history.

The Cisco6500 was debuted in 1999 at the end of a decade that brought us legends such as Pogs, Street Fighter 2, and the Macarena. Even the popularity of the internet was only beginning to catch on.

We began with the Supervisor 1 and its 32gb switch fabric. Next, we graduated to the Supervisor 2 still at 32gb but with the ability to go to 256gb with the switch fabric module. Then we got the Supervisor 720. The 720 introduced 720gb switch fabrics, and then eventually the VSS (virtual switching system) which expanded even further to an upwards of 1.4Tbps! Now, Cisco has debuted the Supervisor 2T which grows the upwards limits to 2Tbps, and doubles the per slot bandwidth from 40gb to 80gb!

In addition to the newer supervisor engines, the chassis has also evolved. Now with the E series chassis, the Cisco Catalyst 6500 is capable of supporting the larger wattage power supplies and the newer supervisors and line cards. While it looks the same, these subtle differences help push the platform into the next generation.

What does that mean for the future of the Cisco 6500 platform?

Well with the announcement of new non-blocking 10gb cards and mention of 40gb support coming, it means that the Cisco 6500 series is here to stay. Some are saying it's here to stay for another 10 years. Bold words from an already aging platform. However, I'm reminded of the old adage "if it ain't broke, don't fix it." The Cisco 6500 switch was built around the idea of expandability, and dependability. It has proven itself time and again in both arenas.

So what does this mean for people who purchase pre-owned network hardware or are interested in the Catalyst 6500 switches?

It means that purchasing a Cisco 6500 is an investment, and a wise one at that.

For people that already have the platform?

They can continue to grow as needed, and as their companies and organizations grow. A recent Network World article mentioned that Cisco says it has 25,000 customers for the Catalyst 6500 and 700,000 chassis installed worldwide. That same article quoted John McCool, senior vice president and general management of Cisco's core technology group, saying:

"We'd be silly to walk away from that installed base and loyal set of customers."

Knowing that Cisco is only continuing to develop for the 6500 platform is peace of mind that your budget dollars were spent well. In addition, new cards and expansions mean price drops and pre-owned market availability on current cards like the Supervisor 720′s and 6700 series line cards in the not too distant future.

Cisco engineers like me are ready and willing to help you talk through your 6500 growth, and the needs and requirements that come along with it. We can help you navigate the sometimes slippery slope of your network hardware upgrades and save you time and money along the way.  We'd be happy to chat more in depth on the topic!

All things considered, the best just keeps getting better. The Cisco 6500 is here to stay and no one should feel bad about having this shield-slinging super-hero anywhere in their network. After all, it takes a veteran to show the new guys the ropes.

Comments from some Cisco fans:
It still has its uses, but IMHO the highly oversubscribed, high latency networking architectures of the past won't make sense in the modern Data Center even at the access layer. Even looking at newer Cisco products like the 5548, let alone even higher density products from companies like Force10, Juniper, Brocade and Arista, which have substantially higher densities, substantially lower cost per port, substantially better performance across the board. Not to mention they all use a tiny fraction of the power and space and emit a tiny fraction of the heat.

Art Fewell: "Even re-purposing this box in the campus has limited utility because of the power, space and heating requirements. Given that the price of 10gig is coming down drastically (on other platforms) and most campus access switches come with 10gig uplinks, so many enterprises are upgrading their campus cores to support higher densities of 10gig. Other platforms can support 64 10gig ports in 1 rack unit with again a small fraction of the overhead costs. These newer platforms have such a lower cost basis that even used 6500's are substantially more expensive. Even keeping an existing 6500 is often much more in overhead costs than purchasing newer higher density equipment." 

Jason: “Cisco 6500 is like the C-130 of the network devices. It does the heavy lifting of being the core router or switch of any enterprise or simply aggregating multiple devices on the edge of network. I think the reason it will go on for another decade, are the service modules, like ACE, NAM, VPN, FWSM, AIP etc... I think without these modules, having a 6500 in a SMB, would have been over kill.... The idea of integrating modules in 6500 is the main life saver of this legendary network ANVIL.”                

Ali_A: "I have been working with C6500 since 2000 .great product with great features. You can do whatever you want with the switch .it can be your Service Chassis switch, Campus, Core , … . I always love them and happy to hear that Cisco have plan to support them (maybe) for another decade. The C6500 show its stability and versatility it the battlefield.i still have C6500+SUP-2 with FWSM installed as datacenter service chassis with no problem and constant software update (SUP-2 lasted software update was 2010 even the device is EOS) take the product survived longer. Also the great blue-print, Deign guide, Cisco-SAFE for C6500 make everything straight when you want to deployment the switch in a scenario, easier without the risk of wrong deployment or down-time."    

More Related Cisco 6500 Info: