Showing posts with label cisco. Show all posts
Showing posts with label cisco. Show all posts

Sunday, February 14, 2016

Cisco to showcase Security Everywhere strategy at GISEC 2016

Cisco announced its participation in the Gulf Information Security Expo & Conference (GISEC 2016) which will be held at Dubai World Trade Centre from 29th to 31st March 2016.

The company aims to showcase and deliver its strategy of Security Everywhere – from the cloud, network and endpoints with new security products and features and a threat awareness service as organisations execute on their digital transformation.

According to Cisco, they will be extending Security Everywhere with new capabilities and services that deliver greater visibility, context and control from the cloud to the network to the endpoint, for organisations of all sizes. At GISEC 2016, the company will demonstrate and showcase how its products and solutions can support its customers safely and securely through digital transformation and how they can weave in the security techniques and deployment as part of it. The value of Cisco architecture is its emphasis on embedding security spanning the extended network – including routers, switches and the data center – closing gaps across the attack continuum – before, during and after – and significantly reducing time to detection and remediation.

Monday, October 19, 2015

Cisco dedicates security project to 'pissing off the bad guys'

Project Aspis will help hosting providers remove persistent criminal activity from their networks before it spreads to end users



Following its disruption of a major distributor of Angler ransomware, Cisco is offering up free security consulting for hosting providers that’s aimed at wiping out persistent attacks that abuse providers’ services and threaten the rest of the Internet.
Cisco’s Talos security intelligence and research group has launched Project Aspis, which hosting providers can sign up for to work with Talos and in return receive help including systems forensics, reverse engineering, threat intelligence sharing and, in the right circumstances, dedicated research engineers to work with, according to Cisco’s security blog.
“This collaboration will help the hosting provider maintain a safe and cost-effective environment and assist Talos in its mission of pissing off the bad guys,” the Talos team says in the blog.

Tuesday, June 25, 2013

Cisco delivers "monster" Catalyst switch in major product refresh

Programmable and optimized for 10/40/100G, Cisco Catalyst 6800 line still does not yet retire the decade-old Cat 6500

Cisco this week will significantly update its enterprise network line-up with programmable campus and branch switches and routers designed to tightly bind applications to network hardware and services.
The new products include the Catalyst 6800 backbone switching line, a new supervisor engine for Cisco’s 4500-E chassis-based access switch, a new high-end ISR branch router and application performance extensions to the ASR 1000 edge router.
Cisco 6800
Cisco 6800
“Cisco has…delivered a monster Catalyst,” says Bill Carter, senior business communications analyst at value-added reseller Sentinel Technologies in Springfield, Ill. “This gives customers a core switch with 10G/40G/100G with the feature set required in the campus.”
The company, which this week hosts itsCisco Live event in Orlando, says its new products fit within an Enterprise Network Architecture under which applications, network services software and hardware networking functions all work together.
Much of this synergy is facilitated by Cisco’s ONE API framework for programmable networking and associated ASICs optimized for Cisco ONE programmability. Cisco ONE and its onePK API set is Cisco’s response to software-defined networking (SDN), in which many of the functions of network behavior are divorced from hardware and centrally administered by software controllers.
SDN makes network functions less reliant on specific hardware and operating systems, and more accommodating to commodity switching and open source software. It threatens Cisco’s dominance and fat profits in routers and switches.
Cisco is combatting the SDN trend by attempting to tightly link software programmability of network infrastructure to custom-developed ASIC hardware and hardware-specific operating systems, and defending its incumbency and massive installed base. These new products are instantiations of that strategy.

Monday, June 24, 2013

Every Network Failure Should Be Used to Improve the Network

Some advice for rebounding from network failure.

Let's accept reality. A network is so much more than just the sum of its electronic parts, operating systems, and configurations. It is an extension of the past and the present of our company. Much like the growth rings of a tree, we can look at our company's network and see all the human history of our company.  
That is probably why post-mortems are so hard and completely avoided or unproductive. People often bring much "baggage"  to the post-mortem. Agendas, politics, silos, likes, dislikes, fears. The list goes on and on. How can the post mortem possibly get anywhere? 
But of course, we've all heard the expression "Nothing changes if nothing changes."
Do you know how muscles grow bigger and stronger? During a workout you develop microscopic tears in your muscle fiber. Your body works to repair the damage. Voila. Muscle growth. No judgement. No thinking "that shouldn't have failed." Just the focus on the response.
Think of your network. Don't you want that for your network? Seriously, imagine it. Take just one minute right now. Can you even picture what your network woud look like if "every network failure was used to improve the network"? You can help to do that. You can help make the difference.   
While "speak softly, and carry a big stick” (Theodore Roosevelt) might have been a great foreign policy position, it is really something to be avoided in the conference room during a post-mortem. 

Monday, May 20, 2013

What Can Be Done About the Cybersecurity Skills Shortage?


IBM paper suggests changes are needed in cybersecurity education to address this silent problem.


I’ve written countless times about the cybersecurity skills shortage but here’s a quick summary of a few ESG research data points that illustrate the scope of this problem: 1. 25% of mid-market (i.e. 100 to 999 employees) and enterprise (i.e. more than 1,000 employees) report a “problematic shortage” of IT security skills. 2. 36% of organizations increasing IT headcount this year plan to hire information security staff. Of all the IT headcount being added in 2013, hiring information security professionals is the highest of priority. 3. 83% of enterprise organizations say that it is “extremely difficult” or “somewhat difficult” to recruit and hire information security specialists. Those organizations having the hardest time include companies in rural areas, mid-market firms, and vertical industries like academia, and the public sector. I remain amazed and incredulous that the cybersecurity skills shortage gets so little attention but a few others are also screaming from the hilltops to get governments, the security industry, and educators to pay attention. For example, IBM recognizes that a dearth of cybersecurity skills presents a threat to its customers, its security business, and its services organization. Let’s face it; no one will build “smarter planet” applications if there aren’t a whole bunch of highly-skilled security professionals to keep them safe. IBM isn’t just assuming the role of Chicken Little and yelling about how the cybersecurity skills sky is falling. Rather, the folks in Armonk are actually trying to do something about it. For example, IBM just published a paper called, Cybersecurity Education for the Next Generation

Wednesday, April 10, 2013

Juniper to unveil programmable core switch for software-defined networking


Based on MX router, what becomes of Juniper's QFabric Interconnect, EX8200?

Juniper Networks is readying a new programmable core switch to address software-defined networking in campuses and data centers.
Sources say it is called the EX9200 and is based on the MX router. It comes in three configurations: 4-slot, 8-slot and 14-slot chassis, the same form factors as the company's successful MX 240, 480 and 960 routers for enterprises and service providers.
Juniper MX routers
Credit: Juniper
Sources say that the form factor of Juniper Networks' new programmable core switch is based on the company's MX family of routers, shown here.
An overview of it can be found here. Juniper confirmed it will be unveiling a "new, advanced switch" and offered an embargoed briefing, but Network Worlddeclined.
The EX9200 is based on custom silicon -- the Juniper One programmable ASIC. The MX 240, 480 and 960 are based on Juniper's I-Chip and Trio chipsets. The EX9200 will support 240G/slot, and 40xGigabit Ethernet, 32x10G, 4x40G and 2x100G interface line cards.
Programmability features, in addition to the Juniper One ASIC, include an XML- and Netconf-accessible automation toolkit, and Puppet, Python and OpenFlow interfaces.Puppet is an open-source operations management software system; Python is a programming language; and OpenFlow is a popular controller-to-switch protocol and API for SDNs.
SDNs are a way to make network more programmable through software so that they can be reconfigured quickly and functionally extended more easily.

Saturday, January 26, 2013

After selling Linksys, Cisco aims to reach consumers through carriers


Though it's pushing off its big consumer unit, Cisco is following service-provider networks into homes

IDG News Service - Cisco Systems' sale of its home networking business to Belkin International marks the end of a 10-year odyssey through the world of consumer products, but the company plans to keep reaching consumers through their carriers and cable companies.
Belkin announced on Thursday that it would buy Cisco's Home Networking Business Unit, including its Linksys brand, for an undisclosed sum. The privately held maker of networking gear, peripherals and accessories plans to fold Linksys' employees and products into its operations while keeping the Linksys brand alive.
The deal, which is expected to close in March, has been in the cards since Cisco'sshutdown of its Flip video camera business in early 2011. The company made that move as it kicked off a major reorganization in response to disappointing business results. Since then, Cisco has been sharpening its focus on enterprises and service providers, and the writing has been on the wall for the consumer business. Next Thursday, the company will shut down the short-lived home telepresence service it offered in conjunction with its already-discontinued Umi device.

Monday, January 21, 2013

Random security predictions for 2013


Lots of malware and industry activity but continuing intransigence in Washington

It’s January 15 which means I probably should have posted a blog on my security predictions for 2013. Here is a somewhat random list of things I believe will happen this year:
1. Visible increase in hacktivism. Hacktivists have a lot to build upon in 2013 including the tragic death or Aaron Swartz, some notable 2012 successes by Anonymous (ex. OpVendetta), the trial of PFC Bradley Manning, etc. There is also a growing trend toward global hacktivism against domestic organizations and the U.S. government. I expect at least one major hacktivism incident per month this year.
2. Continued cybersecurity waffling on Capitol Hill. It took the financial sword of Damocles to get Democrats and Republicans to compromise on legislation to avoid falling off the fiscal cliff at the eleventh hour. Regrettably, cybersecurity legislation lacks a similar trigger. Given the volume of cybersecurity breaches, we should hear a lot of rhetoric from both parties but Washington has bigger fish to fry and legislators aren’t anxious for geeky debates about things they don’t understand. The wild card is a major cybersecurity incident. If this happens, expect lots of finger pointing and a reactive bill that serves as the cybersecurity equivalent of the USA Patriot Act. In short, we can expect inaction or bad action from Washington and nothing more.

Big Data Security Challenges


Collecting massive amounts of security data is easy. Data analysis and visualization? Not so much.

According to ESG Research, 47% of enterprise organizations collect 6TB of security data or more on a monthly basis to support their cybersecurity analysis requirements. Furthermore, 43% of enterprise organizations collect “substantially more” security data then they did 2 years ago while an additional 43% of enterprise organizations collect “somewhat more” security data then they did 2 years ago.
Just what types of data are they collecting? Everything. User activities, firewall logs, asset data, vulnerability scans, DNS logs, etc. Most enterprises aren’t collecting, storing, and analyzing large volumes of network packets (i.e. Full-packet capture or PCAP) today but they will increasingly do so in the future. Once this happens, security data volume collection will take another quantum leap.
If this activity doesn’t signal the need for big data security analytics than nothing does. Nevertheless, CISOs’ need go beyond dumping a bunch of unstructured data in a Hadoop cluster.

Friday, May 25, 2012

The Four Lies of Networking


Commonly heard fallacies and half truths we've all encountered in networking.

Big Data and networking in general are all about numbers and statistics. We talk about our Petabytes of data, the number of packets per second and the Mbytes replicated in an hour. We want to know about the uptime percentages of our services and the time to repair on our circuits. We’re sold on loss ratios and round trip times.
And like statistics and their “Lies, damned lies,” as Mark Twain put it, networking has its own set of fallacies and half truths we’ve all run up against. Here are the four that bug me a bunch. I’d be interested in hearing which ones are on your hit list:

“Network performance is guaranteed by the SLA”

I love this one. Every one of the hundreds of IT managers I’ve spoken with in my 20 years of reporting on IT looked at SLAs as a necessary evil. You need something to hold your carriers accountable, but few expect the SLA to reflect the true conditions of the network and even fewer expected to collect on their agreements. SLAs will cover the carrier core not the last mile, where most of the problems occur. Some will promise zero percent packet loss, but that’s averaged over a months, not by minutes. Others might talk about 99.99% uptime in a year, which sounds great, but neglect to mention that equates to nearly an hour of downtime at any given moment. It’s for those reasons that finding a service provider with a straightforward SLA is so refreshing.

Cisco router rival invests in Cisco video foe


Juniper takes stake in Vidyo, maker of software-based telepresence for enterprises, clouds

Juniper has invested in Vidyo, a competitor of Cisco's in videoconfencing. Juniper is a strategic investor in Vidyo through its Junos Innovation Fund, which invests in software start-ups targeting emerging markets.
Terms of Juniper's stake were not disclosed but the Cisco rival joins lead investor QuestMark Partners and other existing investors Menlo Ventures, Rho Ventures, Star Ventures, and Four Rivers Group to raise Vidyo's funding to $97 million. Vidyo said Juniper's investment allows it to build up go-to-market activities and integrate its telepresence-style videoconferencing software with Juniper's routers and switches.
Vidyo has more than 1,850 enterprise, healthcare, education and government customers. Juniper views video as an expanding market, especially with mobile devices proliferating in enterprises, and is looking to have its products participate in it by integrating technology to improve the experience for business customers.

Wednesday, May 23, 2012

ALU expected to challenge Cisco, Juniper in core


Edge router rival ready for a core revival 10 years after dealing ACEIS

Alcatel-Lucent is reportedly ready to give Cisco and Juniper a run for the money in core routing. The company, which dukes it out with both in service provider edge routing, is about to pop a core router based on its 400Gbps FP3 processor, according to ITWire.
This would be ALU's second run at the core. Anyone remember the 7770 Routing Core Platform and7670 Routing Switch Platform with ACEIS? The 7770 was then respun into the 7770 Optical Branch Exchange.
Only the 7670 RSP appears to have survived from that fearsome foursome.
Ten Years After. Looks like the FP3 has inspired ALU to take another run at it. That, and its No. 2 or 3 position in edge routing. Observers are crowing about the potential of the FP3, according to the ITWire piece. Maybe it can correct the mistakes of the 7770 and ACEIS.
ALU will be re-entering a core router market that declined 7% in the first quarter, according to a bulletin issued this week from investment firm UBS. Cisco gained share in Q1, and now stands at 62% vs. 59% in 2011. Juniper's share declined by four percentage points, to 25% from 29% in Q1 of 2011. Huawei's share was flat at 10%.
UBS stated in its bulletin that ALU is "likely to enter mkt in 2012."
In the edge, the market grew 5% in Q1 to $1.6B, but shrank 6% from Q4 2011. Cisco had a 41% share in Q1, up 4% from last year, while Juniper grew share from Q4 but was down 3% from Q1 of 2011.  
ALU's share was up slightly in Q1 from a year ago, at 25% vs. 24%, but down from 26% in Q4.

Preparing Your Enterprise for World IPv6 Launch


Things you should be doing even if you are not participating

Last year on June 8, 2011 we all experienced World IPv6 Day. This was a 24-hour test for web sites to use both an IPv4 and IPv6 addresses simultaneously for the same URL. One June 6, 2012 there will be World IPv6 Launch in which many organizations will enable IPv6 forever. Enterprises will need to prepare for World IPv6 Launch whether or not they are actively participating and enabling IPv6.
World IPv6 Day
Last year World IPv6 Day was organized by the Internet Society (ISOC) and several major content providers. IPv6 evangelists at Google, Facebook, Yahoo!, Akamai, Limelight Networks, and several other companies came up with the idea of conducting a 24-hour test of having their web sites have both an IPv4 DNS "A" record and an IPv6 DNS "AAAA" record simultaneously. The goal of this event was to test the end-user experience and help identify any problems their users might encounter if they were to fully deploy IPv6 someday. Hundreds of other organizations joined in, and in the end, it was determined that the amount of "IPv6 Brokenness" was less than previously measured. Fewer problems were encountered than anticipated and it showed that IPv6 was ready for broader deployment.

Monday, April 9, 2012

Why NEW architecture will happen


When economics combines with cloud performance on the WAN, the NEW architecture will gain popularity.

In my first column, I described a Next-generation Enterprise WAN (“NEW” for short) architecture. Here I’d like to cover why this NEW architecture will be widely deployed over the next few years.
Part of the reason – and some would argue, the primary reason – is, to paraphrase Bill Clinton and James Carville, "It's the economics, stupid!"
MPLS, from telcos like AT&T, Verizon and BT, is the dominant enterprise private WAN architecture in the U.S. and worldwide, and put simply, it’s very expensive. Branch and mid-sized office copper MPLS connectivity for U.S. locations typically costs $300 to $600 per Mbps per month, versus broadband Internet connections, which run $1.50 to $15 per Mbps per month. Fiber-based MPLS data center connectivity is typically in the $60 to $200 per Mbps per month range, versus Internet bandwidth costs at a carrier-neutral colocation facility of $10 to $20 per month.

Cisco, Juniper see government differently


Spending up in Juniper's Q1 while Cisco expects segment to be challenging for the rest of the year

Juniper's enterprise business may be doing better than expected this quarter, according to Oppenheimer & Co. Based on 26 interviews in the US and Europe, the investment firm says the Cisco rival is experiencing solid upgrade activity and a recovery in security and government spending.
Government spending has been soft in recent quarters, impacting the results of many leading vendors, including Cisco. Cisco still believes it will be an issue for the rest of the year, according to this post on the CNBC site.
About one-fifth of Cisco's revenue comes from the public sector.
Meanwhile, demand for Juniper enterprise products is strong in the US and mixed in Europe, Oppenheimer reports. Juniper's switching business appears to be mixed as well, with increased competition from Cisco and the slow ramp of the QFX/QFabric line. Oppenheimer expects some offset from sales of security products.
But the wild card is service provider routing, where softness has impacted the last two or so Juniper quarters. Limited visibility into a recovery in spending makes this business hard to gauge, compounded by product transitions in core routing: the T4000 router and the PTX packet/optical transport system.

Saturday, September 10, 2011

A new 15.1(2)T IOS feature that should be considered when upgrading


One of the first things to make sure when an H.323 gateway will not work with Cisco Unified Communication Manager (CUCM) is the IP address configuration. This is a common mistake where engineers would configure the gateway in CUCM using its voice interface IP address and would have no problem calling out from IP phones to the PSTN, but would fail on the inbound calls. The reason is that the gateway was using a different IP address (than the one configured on the voice vlan) to contact CUCM and CUCM would reject the call setup packet.
On the other end, the Cisco IOS gateway had no problems accepting calls from any IP address and would not require anything specific to be configured on it. The problem with this approach is toll fraud and call theft. On a gateway that has exposure to external networks such as the internet, hackers can use an H323 or SIP client and call out via the gateway to external destinations on your expense. There are ways to protect against that using access lists but in version 15.1(2)T Cisco secured the IOS and created a CUCM like behavior which means that everything is denied unless it was specifically allowed.

Wednesday, August 31, 2011

Cisco, VMware expand collaboration


Cisco and VMware this week expanded their 4+ year partnership by unveiling networkvirtualization extensions designed to expand the mobility range of virtual machines across multiple data centers and cloud environments.
At VMworld 2011, the companies also announced enhancements to several desktop virtualization and cloud infrastructure products designed to boost scalability, security and performance.
The new network virtualization enhancement, called Virtual Extensible Local Area Network, or VXLAN, is intended to allow enterprises to access compute and storage capacity wherever it resides. It is also intended to scale across millions of logical networks required to run applications in the cloud, Cisco says.

Tuesday, August 23, 2011

The real 'investment protection' story of the Cisco 6500


As I am sure you all saw, Cisco recently announced the Supervisor 2T, extending the lifespan of the much loved platform. This continues Cisco's marketing message of investment protection around the 6500 ... the problem is, that the 'investment protection' story told here is simply false. The truth is that an upgrade to the Supervisor-2T in the manner described in Cisco's launch announcements would result in no bandwidth improvement and potentially over 7x performance reduction from the performance of the Supervisor 720 .
Essentially, Cisco said that at $38,000, the Sup 2T is priced at one-third that of HP's A9508 switch yet is 3X the performance and supports 200+ features or services, claims Scott Gainey, Cisco director of marketing for Unified Access Solutions.  Gainey further said, "... a forklift upgrade to a comparable HP switch architecture would likely cost that customer more than $100,000, he said, and gives the customer only 720 Gbps of throughput."
Cisco Catalyst family at Cisco Live

Stronger IPsec VPN Configurations Needed


he use of IPsec is pervasive throughout the networking industry. However, many organizations are using IPsec in sub-optimal configurations that result in weaker connection security. Many organizations use IPsec with pre-shared keys and weak encryption algorithms and no form of authentication. Organizations should reconsider how they are using IPsec to ensure it provides maximum security for their organization's private communications.
Virtually all network professionals are familiar with the Internet Protocol Security (IPsec) standard. The Internet Engineering Task Force (IETF) created IPsec as a method to secure end-to-end IP communications by providing confidentiality, authenticity and integrity of the data. Originally, IPsec was a method of authenticating and encrypting IPv6 packets. However, it was such a great idea that it was also applied to IPv4.
Many organizations rely on IPsec to secure external communications to prevent against eavesdropping of the embedded application data. IPsec can provide data origin authentication, replay protection, confidentiality, connectionless integrity and access control. IPsec helps prevent against eavesdropping, replay and spoofed packet attacks, Man-in-the-Middle (MITM) attacks and Denial of Service (DoS) attacks. IPsec can perform all of these functions provided IPsec has been implemented correctly by the manufacturer and the administrator has configured in properly on their equipment and in their software. However, the unfortunately truth is that many organizations have not established their IPsec deployments using the industry best practices.

Thursday, August 18, 2011

Whatever Happened to Microsoft Forefront Endpoint Protection?


Back in 2007, Microsoft shook the security world when it entered the endpoint security market with what was then called Forefront Client Security (now Microsoft Forefront Endpoint Protection). Forefront was positioned as the endpoint security market for the commercial market while its sister product, OneCare, was aimed at the consumer market. This created a market fire storm, especially at companies like McAfee, Symantec, and Trend Micro that depended on PC security for the bulk of their 2007 revenue. The industry wondered, "would these powerful security companies get Netscaped?
Microsoft was pretty bullish about its announcement. When Forefront was announced, Bob Muglia, who was VP of Microsoft's server and tools business stated, "we think that this product will provide a level of integration and simplicity that really differentiates it, and really enables a different kind of solution." Microsoft wasn't alone in its expectations. Here at ESG, we had just done some market research revealing that: 1) Most security professionals looked at endpoint as a commodity product, and 2) They were already evaluating Forefront or were willing to do so. In other words, the market was open to Microsoft -- all it had to do was execute and beat the competition on price.