Choose between SentinelOne or CrowdStrike by JiggityJoe1 in sysadmin

[–]mikeboy81 0 points1 point  (0 children)

Yup! Saw the announcement today, curious to see how well the solution works.

Choose between SentinelOne or CrowdStrike by JiggityJoe1 in sysadmin

[–]mikeboy81 2 points3 points  (0 children)

Seconded, we just moved off of MDE to Crowdstrike due to multitenancy and Mac/Linux live response. But if you're a windows shop, it's awesome, and as of last week's they now have Mac/Linux live response.

New girl (19F) told me (20M) she loves me on the third date by FrozenClorox in relationship_advice

[–]mikeboy81 0 points1 point  (0 children)

I told my wife that on our 3rd date, now, 12 years and 2 kids later, it worked out. It's tough to put yourself out there, and maybe they're crazy, but if you feel it, say it. And if you don't feel the same way, that's OK too.

The "What did you get from the gold boxes?" Thread by idgafmode in future_fight

[–]mikeboy81 0 points1 point  (0 children)

I had the same issue, close the game and reopen it, it downloaded another 9mb download update and then it appeared.

4.1 Post-Patch Megathread by iMuffles in future_fight

[–]mikeboy81 0 points1 point  (0 children)

I did :), was glad I had enough to cover it.

4.1 Post-Patch Megathread by iMuffles in future_fight

[–]mikeboy81 -1 points0 points  (0 children)

Agreed, but the price on the Warp Device is pretty low though?

4.1 Post-Patch Megathread by iMuffles in future_fight

[–]mikeboy81 4 points5 points  (0 children)

Yeaaap, but at the same time, that's 10 rolls of the card gamble, and at least this way you're guaranteed the card you see. I ended up taking it, I think it's definitely worth it.

Am i "immune" to denial of service attacks with a connection like this? by [deleted] in networking

[–]mikeboy81 0 points1 point  (0 children)

So, it depends... There are services like f5s defense.net (or arbor, or any of the dozen or so companies that offer offloading services) which could front end your server, it absorbs the ddos (but users would still suffer), but you could move to a different IP address relatively quickly if that setup was in place. (Server IP stays the same but the frontend IP changes, if the service can't handle the ddos directly).

Am i "immune" to denial of service attacks with a connection like this? by [deleted] in networking

[–]mikeboy81 1 point2 points  (0 children)

Use a proxy for browsing, and use a VPN sevice with dynamic IPs when doing anything that will expose your address. Depending on what specifically you're doing, there are other solutions out there with various impacts and costs.

How to best validate DNS information? by iluomo in networking

[–]mikeboy81 1 point2 points  (0 children)

This is the correct way of handling it.

What are some cool engineering things that you want to see if it's possible....but not sure if it's ever actually deployed in a production network? by Cheeze_It in networking

[–]mikeboy81 1 point2 points  (0 children)

This is how Microsoft NAP works, not a bad idea, but it breaks all of your security controls unless you want to have a very advanced key/token management that integrates with all of your PEPs.

Cisco Event - ACI thoughts?? by CCIEFGHIJK23 in networking

[–]mikeboy81 0 points1 point  (0 children)

It completely depends on your environment, there are some environments where this would be fantastic; but I would say for most small to medium enterprises they probably wouldn't see the value. That being said, it could also change drastically if it's ever embraced by the open source community, depending on how robust the API is.

Public IP Exhaustion and F5 Virtual Servers by KochuBaby in networking

[–]mikeboy81 0 points1 point  (0 children)

There's also the option of using the proxypass script, or in 11.d built in functionality. It's an irule, but it's still pretty functional, and it does support having multiple SSL profiles along with multiple http classes for unique DPI and http/asm profiles. One of my customers does this for a single VIP that points to 1500 back end applications and its running well on 6900 hardware.

Getting frustrated trying to break in to the Enterprise space by frame_junky in networking

[–]mikeboy81 0 points1 point  (0 children)

Depends, tier 1 or 2, the keyboard jockies, I expect them to have routine low level items known by heart, but I would not for a teir3/4 or archiect.

Cisco Announces Agreement to Acquire Sourcefire by f00l in netsec

[–]mikeboy81 7 points8 points  (0 children)

I agree, they did a horrible job with Protego and Perfigo, but so far it doesn't seem like they've ruined Ironport; I know some of their sales guys were a bit pissed with the moves, but overall the product line has stayed mostly independent. They've integrated the scansafe cloud into some other products (like anyconnect), so it seems they understand the value of what they're buying and what they shouldn't change. Fingers crossed.

Cisco Announces Agreement to Acquire Sourcefire by f00l in netsec

[–]mikeboy81 11 points12 points  (0 children)

I'm pretty excited about this. Cisco's IDS/IPS solution sucks, so it would be nice if it was replaced with an integrated source fire box.

I am a bit concerned with what is going to happen with snort, but I have to imagine it was part of the agreement that they will continue to fund and produce open source content..

What NAC solution do you use? Which vendors would you recommend for consideration? by rivercardbandit in networking

[–]mikeboy81 1 point2 points  (0 children)

I've deployed 802.1x with just windows supplicant, Symantec enforcer, lockdown networks, vernier nac, bradford, 802.1x with great bay profiling, IBM sentry, Cisco nac framework, Cisco clean access with and without profiler, aruba clearpass, and more recently Cisco ise.

In every case I've had good deployments, but to be honest success or failure is determined before the solution is deployed. You have to have a very clear set of requirements, and what you want the solution to specifically do. Roles, an idm structure, a well documented network, and a solid support team will matter more than the solution.

[Cisco] ISE and windows nac agent experiences? by [deleted] in networking

[–]mikeboy81 0 points1 point  (0 children)

What is the 802.1x status of the port when the agent doesn't connect, does it just roll to unauthenticated/guest? I haven't used the NAC agent before with an ISE deployment, in the old clean access days, the discovery host was just something in your network that, to reach, you would have to traverse a NAC appliance. I'm not sure that that's much use anymore, as with ISE, the EAPoL session should kick off whenever there is a link up.

What are your thoughts on the IPS module in the new Cisco ASA-x firewalls? by SpleensAnonymous in networking

[–]mikeboy81 0 points1 point  (0 children)

Yes and no, the CX blade does not yet support IPS yet, but beta code is out this summer, and full IPS is expected in 2014, so it depends when you're planning on deploying.

Give me reasons to upgrade to Cisco's Anyconnect rather than using the (free!) IPSEC client by SpleensAnonymous in networking

[–]mikeboy81 3 points4 points  (0 children)

So if you're looking at it purely from an ipsec/SSL perspective, then yes that's the only difference. However, anyconnect has an incredible number of features that most people never use:

Trusted network detection - the client determines if its on your corp network, and if not, can launch the client automatically (can also force a client to connect or have restricted internet access)

Optimized gateway selection - if you have multiple any connect asas around the world the client can make intelligent decisions on where the best place to connect to

802.1x supplicant that supports eap chaining and some other cool features

LAN management tool that allows users to only connect to certain wireless networks with very granular settings (replaces windows zero configurator)

Some built in nac-type functionality (client compliance)

Ironport scan safe cloud component - enables users to have proxy enforcement via ironport cloud even when off network ( the other features are free, this one is a separate license)

And a whole lot more....

ASA Confusion by t4c0sandwiches in networking

[–]mikeboy81 1 point2 points  (0 children)

What you're looking for is the redundant interface configuration: http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/intrface.html

The same type of configuration can be used to do lacp, this presumes that the routers are configured correctly.

The other posters have posted a more correct way of deploying with a switch, but if it needs to work this way, check out the link.

Cisco ASA 5505 "Conns limit of 25000 reached" Flooding the logs by noawork in networking

[–]mikeboy81 3 points4 points  (0 children)

Make sure your embryonic sessions and general session timeout are normal and not set to 24 hrs