
<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ryanreed.NET &#187; Internet Security</title>
	<atom:link href="http://www.ryanreed.net/category/internet-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ryanreed.net</link>
	<description>Hand carrying packets since 2008!</description>
	<lastBuildDate>Sat, 13 Feb 2010 22:16:24 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Network Specialist Resume</title>
		<link>http://www.ryanreed.net/2009/07/13/network-specialist-resume/</link>
		<comments>http://www.ryanreed.net/2009/07/13/network-specialist-resume/#comments</comments>
		<pubDate>Tue, 14 Jul 2009 04:10:37 +0000</pubDate>
		<dc:creator>Ryan Reed</dc:creator>
				<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Network Security]]></category>

		<guid isPermaLink="false">http://www.ryanreed.net/?p=314</guid>
		<description><![CDATA[Just got around to updating the 'ol resume and Monster.com profile.  I need to update the resume a tiny bit more to include the new company, SecureWorks as the sale has been completed.

I also need to export the new resume to pdf.  Ah, no rush, I suppose.]]></description>
			<content:encoded><![CDATA[<p>Just got around to updating the 'ol <a href="http://www.ryanreed.net/wp-content/themes/ryanreed2.0/resume.php" title="Resume">resume</a> and <a href="http://www.monster.com/" title="Monster.com">Monster.com</a> profile.  I need to update the resume a tiny bit more to include the new company, <a href="http://www.secureworks.com/" title="SecureWorks">SecureWorks</a> as the sale has been completed.</p>

<p>I also need to export the new resume to pdf.  Ah, no rush, I suppose.</p>]]></content:encoded>
			<wfw:commentRss>http://www.ryanreed.net/2009/07/13/network-specialist-resume/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CCSA &#8211; Checkpoint Security Administration Certification</title>
		<link>http://www.ryanreed.net/2009/06/19/ccsa-checkpoint-security-administration/</link>
		<comments>http://www.ryanreed.net/2009/06/19/ccsa-checkpoint-security-administration/#comments</comments>
		<pubDate>Fri, 19 Jun 2009 17:10:32 +0000</pubDate>
		<dc:creator>Ryan Reed</dc:creator>
				<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Network Security]]></category>

		<guid isPermaLink="false">http://www.ryanreed.net/2009/06/19/ccsa-checkpoint-security-administration/</guid>
		<description><![CDATA[Quick update.  I passed my CCSA exam today.  3 certs this year and counting.  CCNA coming very soon.]]></description>
			<content:encoded><![CDATA[<p>Quick update.  I passed my CCSA exam today.  3 certs this year and counting.  CCNA coming very soon.</p>]]></content:encoded>
			<wfw:commentRss>http://www.ryanreed.net/2009/06/19/ccsa-checkpoint-security-administration/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>JNCIA Certification</title>
		<link>http://www.ryanreed.net/2009/06/08/jncia-certification/</link>
		<comments>http://www.ryanreed.net/2009/06/08/jncia-certification/#comments</comments>
		<pubDate>Mon, 08 Jun 2009 16:33:34 +0000</pubDate>
		<dc:creator>Ryan Reed</dc:creator>
				<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Network Security]]></category>

		<guid isPermaLink="false">http://www.ryanreed.net/?p=261</guid>
		<description><![CDATA[Quick update, just got my JNCIA certification.  Wasn't as bad as I thought it would be.]]></description>
			<content:encoded><![CDATA[<p>Quick update, just got my JNCIA certification.  Wasn't as bad as I thought it would be.</p>]]></content:encoded>
			<wfw:commentRss>http://www.ryanreed.net/2009/06/08/jncia-certification/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pix/ASA Site-to-Site VPN Generator</title>
		<link>http://www.ryanreed.net/2009/01/26/pix-asa-site-to-site-vpn-generator/</link>
		<comments>http://www.ryanreed.net/2009/01/26/pix-asa-site-to-site-vpn-generator/#comments</comments>
		<pubDate>Tue, 27 Jan 2009 03:15:48 +0000</pubDate>
		<dc:creator>Ryan Reed</dc:creator>
				<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Network Security]]></category>

		<guid isPermaLink="false">http://www.ryanreed.net/?p=142</guid>
		<description><![CDATA[I decided that after working on various Pix and ASA firewalls, that it would be nice to have a VPN generator that could easily output the code needed to setup a site to site VPN.  Apparently, someone at the 'ol workplace had created one but I only realized it after I ha mostly created [...]]]></description>
			<content:encoded><![CDATA[<p>I decided that after working on various Pix and ASA firewalls, that it would be nice to have a VPN generator that could easily output the code needed to setup a site to site VPN.  Apparently, someone at the 'ol workplace had created one but I only realized it after I ha mostly created the script.  Ah well, not a huge deal.</p>

<p>So what are some of the feature of the generator?</p>

<ul class="article">
  <li>Has the ability to generate version 6 or 7/8 code for VPNs</li>
  <li>If not pre-shared key is entered, a random key will be generated</li>
  <li>The information stays on the page and is not posted. All the processing is done on the client's computer so that the sensitive information isn't transmitted over the internet</li>
</ul><br />

<p>There are a few things this script does not do</p>

<ul class="article">
  <li>It will not create the access-lists required (for the encryption domains)</li>
  <li>The NONAT will not be generated (leaves it open to the user to decide if NONATting is desired, etc)</li>
  <li>Has not been completely tested as of yet (syntax wise)</li>
</ul><br />

<p>Because I'm all for openness, I'm releasing the script under the <a href="http://www.gnu.org/licenses/gpl.html" title="General Public License">GPL</a>.  Take it, enjoy it.  A small request, if you modify the code, let me know.  I'm a curious one.</p>

<p><a href="http://www.ryanreed.net/PixVPN/" title="Pix/ASA Site-to-Site Generator">Pix/ASA Site-to-Site VPN Generator</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.ryanreed.net/2009/01/26/pix-asa-site-to-site-vpn-generator/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Juniper Netscreens..</title>
		<link>http://www.ryanreed.net/2009/01/10/juniper-netscreens/</link>
		<comments>http://www.ryanreed.net/2009/01/10/juniper-netscreens/#comments</comments>
		<pubDate>Sat, 10 Jan 2009 16:59:47 +0000</pubDate>
		<dc:creator>Ryan Reed</dc:creator>
				<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Network Security]]></category>

		<guid isPermaLink="false">http://www.ryanreed.net/?p=112</guid>
		<description><![CDATA[I have to say that of the three main firewalls I work with on a daily basis, the Netscreen is one of the best out there.  All 3 firewalls have their pros and cons: 

Checkpoint


  Pros
  Easy to use and understand
  The gui is built for ease of use
  tcpdump [...]]]></description>
			<content:encoded><![CDATA[<p>I have to say that of the three main firewalls I work with on a daily basis, the Netscreen is one of the best out there.  All 3 firewalls have their pros and cons: </p>

<p><a href="http://www.checkpoint.com/" title="Checkpoint">Checkpoint</a></p>

<ul class="article">
  <li class="nolist"><b>Pros</b></li>
  <li>Easy to use and understand</li>
  <li>The gui is built for ease of use</li>
  <li>tcpdump is one of my favorite tools to sniff traffic and it works well the Nokias and Crossbeams</li>
  <li class="nolist"><b>Cons</b></li>
  <li>The log viewer seems to "lie" sometimes, not showing the proper rule numbers at times</li>
  <li>Editing rules via CLI is extremely tough</li>
</ul><br />

<p><a href="http://www.cisco.com/web/go/pix" title="Cisco Pix/ASA">Cisco Pix/ASA</a></p>

<ul>
  <li class="nolist"><b>Pros</b></li>
  <li>Fast</li>
  <li>Relatively easy to use</li>
  <li>Lots of documentation online and on Cisco's website for many things</li>
  <li class="nolist"><b>Cons</b></li>
  <li>I'm not a personal fan of the capture command, although it does work</li>
  <li>Trace routes are not stateful and only the newer versions can actually perform a virtual inspection of those packets</li>
</ul><br />

<p><a href="http://www.juniper.net/" title="Juniper Netscreen">Juniper Netscreen's</a> are excellent firewalls.  They tend to be extremely quick and the commands are straight forward.  The log viewing on the firewall is excellent and gives a good amount of information.  The only issue I have with these firewalls is the gui, the Netscreen Manager.  NSM has some excellent features and the gui tends to be relatively easy.  Unfortunately it's programmed in Java.  The app can be extremely slow and unresponsive.  When running NSM on the local machine, the software has a tendency to max the cpu usage for a while.  The newest NSM software version I've been using (can't recall the exact version, sorry) has a memory leak that causes the application to eat up memory until all the free memory on the machine is being used by NSM.  The only way to solve the issue is to minimize the app for a minute or to close NSM and reopen it.</p>

<p>I should reiterate the point that I do like Netscreens.  I even own a Netscreen 5xp for my own home use.  I do wish that they would work on improving the Netscreen Manager.  I'm not a fan of using Java for the app.  If they ever overhaul the application, I think it could be the best firewall on the market.  I would still recommend for small offices and home use the <a href="http://shop.ebay.com/items/_W0QQ_nkwZnetscreenQ205xpQQ_armrsZ1QQ_fromZR40QQ_mdoZ" title="Netscreen 5xp">Netscreen 5XP</a> and for the larger business/organizations, take a look at their higher end products.</p>]]></content:encoded>
			<wfw:commentRss>http://www.ryanreed.net/2009/01/10/juniper-netscreens/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
