<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>CiscoNews, News, Reviews and Guides</title>
	<atom:link href="http://cisconews.co.uk/feed/" rel="self" type="application/rss+xml" />
	<link>http://cisconews.co.uk</link>
	<description></description>
	<pubDate>Thu, 23 Apr 2009 13:35:40 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
			<item>
		<title>Cisco IPS v7</title>
		<link>http://cisconews.co.uk/2009/04/23/cisco-ips-v7-update-announcement/</link>
		<comments>http://cisconews.co.uk/2009/04/23/cisco-ips-v7-update-announcement/#comments</comments>
		<pubDate>Thu, 23 Apr 2009 13:26:31 +0000</pubDate>
		<dc:creator>Ray</dc:creator>
		
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://cisconews.co.uk/?p=134</guid>
		<description><![CDATA[Cisco announced the arival of IPS v7 on April 21st 2009, with one major new feature to drive forward the Cisco Self Defending Network&#8230;

In recent times Cisco IDS/IPS has fallen short on some of the offerings around today for intrusion detection and prevention, its signature based methodology though comprehensive lacks the intelligence seen by many [...]]]></description>
			<content:encoded><![CDATA[<p>Cisco announced the arival of IPS v7 on April 21st 2009, with one major new feature to drive forward the Cisco Self Defending Network&#8230;<br />
<span id="more-134"></span></p>
<p>In recent times Cisco IDS/IPS has fallen short on some of the offerings around today for intrusion detection and prevention, its signature based methodology though comprehensive lacks the intelligence seen by many other vendors products in the market today. </p>
<p>In a nutshell Cisco are attempting to modernise their IDS/IPS and appear to be adopting an approach simlilar to those used by other vendors by correlating global data to make inteligent decisions. Cisco have the following to say about about the new release:</p>
<blockquote><p>&#8220;Correlation for intrusion prevention system (IPS) harnesses the power of Cisco Security Intelligence Operations, a powerful threat-defense ecosystem, to achieve unprecedented threat-protection efficacy. Cisco turns global threat data captured from a massive footprint of security devices into dynamic updates and actionable intelligence, such as &#8220;reputation&#8221; scores, and pushes that intelligence out to a business&#8217;s network security infrastructure for protective action. By incorporating Global Correlation, Cisco IPS 7.0 is up to two times as effective in stopping malicious attacks, in a shorter amount of time, than traditional signature-only IPS technologies.&#8221;</p>
</blockquote>
<p>More information can be seen at <a href="http://newsroom.cisco.com">http://newsroom.cisco.com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://cisconews.co.uk/2009/04/23/cisco-ips-v7-update-announcement/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Cisco ASA 8.2 Software</title>
		<link>http://cisconews.co.uk/2009/04/23/cisco-asa-82-software/</link>
		<comments>http://cisconews.co.uk/2009/04/23/cisco-asa-82-software/#comments</comments>
		<pubDate>Thu, 23 Apr 2009 12:54:42 +0000</pubDate>
		<dc:creator>Rich</dc:creator>
		
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://cisconews.co.uk/?p=133</guid>
		<description><![CDATA[ASA 8.2]]></description>
			<content:encoded><![CDATA[<p>Cisco have announced the 8.2 version ASA code. Plenty of new features in this one so Ill bullet point some of the key ones and leave the rest for you to dig out from Cisco.com.</p>
<p>* BotNET Traffic Filter<br />
* Transparent Firewalling for IPV6<br />
* Shared SSL VPN Licensing across multiple ASAs<br />
<span id="more-133"></span><br />
* Per Group Certificate Authentication for remote access VPN.<br />
* Cisco Secure Netflow across all ASA models, as opposed to just the 5580s.<br />
* A wizard to set up public access to a server or host on your network. I imagine this will set up all the required translations and access for you. Could be quite cool if implemented well.</p>
<p>Official release is <a href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/product_bulletin_c25-526545.html">here</a></p>
]]></content:encoded>
			<wfw:commentRss>http://cisconews.co.uk/2009/04/23/cisco-asa-82-software/feed/</wfw:commentRss>
		</item>
		<item>
		<title>ASA 5505 IPS Module at last&#8230;.</title>
		<link>http://cisconews.co.uk/2009/04/23/asa-5505-ips-module-at-last/</link>
		<comments>http://cisconews.co.uk/2009/04/23/asa-5505-ips-module-at-last/#comments</comments>
		<pubDate>Thu, 23 Apr 2009 12:47:21 +0000</pubDate>
		<dc:creator>Rich</dc:creator>
		
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://cisconews.co.uk/?p=130</guid>
		<description><![CDATA[It looks like Cisco have finally announced the SSC5 (as well as IPS v7) - an IPS module for the diminutive ASA 5505.
Not sure on pricing or availability yet, but it looks like it is missing some features from the full blown IPS sensors.

Basically, it seems to be missing anomoly detection, Virtual Sensors, Custom signatures, [...]]]></description>
			<content:encoded><![CDATA[<p>It looks like Cisco have finally announced the SSC5 (as well as IPS v7) - an IPS module for the diminutive ASA 5505.<br />
Not sure on pricing or availability yet, but it looks like it is missing some features from the full blown IPS sensors.<br />
<span id="more-130"></span></p>
<p>Basically, it seems to be missing anomoly detection, Virtual Sensors, Custom signatures, Global correlation (new in 7.0) and the ability to re-enable retired signatures. It is capable of 75Mbps of throughput, approximately 50% of the 5505&#8217;s capacity. It has no dedicated management port unlike the AIP-SSMs.</p>
]]></content:encoded>
			<wfw:commentRss>http://cisconews.co.uk/2009/04/23/asa-5505-ips-module-at-last/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to Encrypt your ISAKMP keys in the running config!</title>
		<link>http://cisconews.co.uk/2008/10/31/how-to-encrypt-your-isakmp-keys-in-the-running-config/</link>
		<comments>http://cisconews.co.uk/2008/10/31/how-to-encrypt-your-isakmp-keys-in-the-running-config/#comments</comments>
		<pubDate>Fri, 31 Oct 2008 21:55:13 +0000</pubDate>
		<dc:creator>Rich</dc:creator>
		
		<category><![CDATA[Config. Guides]]></category>

		<category><![CDATA[Tricks and Tips]]></category>

		<guid isPermaLink="false">http://cisconews.co.uk/?p=128</guid>
		<description><![CDATA[Here is a quick and dirty config tip.
If you look at your running config you will notice that your ISAKMP keys are stored in plain-text. In other words, unencrypted. This still stands after issuing the &#8220;service password-encryption&#8221; command.
Click more to find out how to encrypt those keys using AES!

So, what we start out with looks [...]]]></description>
			<content:encoded><![CDATA[<p>Here is a quick and dirty config tip.</p>
<p>If you look at your running config you will notice that your ISAKMP keys are stored in plain-text. In other words, unencrypted. This still stands after issuing the &#8220;service password-encryption&#8221; command.</p>
<p>Click more to find out how to encrypt those keys using AES!</p>
<p><span id="more-128"></span></p>
<p>So, what we start out with looks something like this:</p>
<blockquote><p>crypto isakmp key myweakpassword address 1.1.1.1</p></blockquote>
<p>What we ideally want to do is encrypt this password to prevent a potential leak of the config causing you problems, not to mention just so that you can follow best practice!</p>
<p>All we need to enter is the following two lines of config:</p>
<blockquote><p>MyRouter(config)#key config-key password-encrypt thisismyencryptionpassword<br />
MyRouter(config)#password encryption aes</p></blockquote>
<p>Easy right? Ok lets verify this works by issuing the &#8220;sh run&#8221;:</p>
<blockquote><p>crypto isakmp key 6 V]PMeY]cO[TQ[EWaQ\[D`XViUTA`LZMVR_[[SUQVgF address 1.1.1.1</p></blockquote>
<p>Hope that helps!</p>
]]></content:encoded>
			<wfw:commentRss>http://cisconews.co.uk/2008/10/31/how-to-encrypt-your-isakmp-keys-in-the-running-config/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Verify your IOS before reloading that router!</title>
		<link>http://cisconews.co.uk/2008/07/22/verify-your-ios-before-reloading-that-router/</link>
		<comments>http://cisconews.co.uk/2008/07/22/verify-your-ios-before-reloading-that-router/#comments</comments>
		<pubDate>Tue, 22 Jul 2008 10:41:31 +0000</pubDate>
		<dc:creator>Rich</dc:creator>
		
		<category><![CDATA[Config. Guides]]></category>

		<category><![CDATA[Tricks and Tips]]></category>

		<guid isPermaLink="false">http://cisconews.co.uk/?p=125</guid>
		<description><![CDATA[A lot of cisco techs are in the same position. You only have remote access to a router but need to perform an IOS upgrade. This might be to squash a bug or simply because Cisco TAC will not proceed with a TAC case until you do so.
How do you verify that the IOS image [...]]]></description>
			<content:encoded><![CDATA[<p>A lot of cisco techs are in the same position. You only have remote access to a router but need to perform an IOS upgrade. This might be to squash a bug or simply because Cisco TAC will not proceed with a TAC case until you do so.</p>
<p>How do you verify that the IOS image has not been corrupted between cisco.com and your device? Read on to find out!</p>
<p><span id="more-125"></span></p>
<p>All of the IOS downloads have an MD5 sum that identifies the original unaltered files. MD5 hashing is basically a way of taking an input, in this case the IOS, running it through a hashing algorithm and coming up with a string/Value. The important thing to note here is no matter who runs the IOS through the hashing algorithm, the output will always be the same. If even a slight change has been made to the file then the output will be different.</p>
<p>So, once your IOS is on the router you need to do the following:</p>
<p>router#verify /md5 disk0:c1700-advsecurityk9-mz.123-14.T7.bin</p>
<p>At this point the router will respond with the hash value of the file you have uploaded which can now be compared to the hash value from cisco.com. If these values do not match <strong>DO NOT RELOAD THE ROUTER!!!</strong> If you do the chances are you will end up with a paper weight until you can get out to site.<br />
You should re-upload the IOS to ensure that it is correct and perform the above again. If you get a mismatched input then the chances are the IOS on your TFTP server is corrupt and you will need to re-download from Cisco.com.</p>
<p>Hope that helps you avoid those &#8220;uh oh&#8221; moments when a device doesnt return to service!</p>
<p>Thanks for reading.</p>
]]></content:encoded>
			<wfw:commentRss>http://cisconews.co.uk/2008/07/22/verify-your-ios-before-reloading-that-router/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Cisco related Ebay Bargains!!</title>
		<link>http://cisconews.co.uk/2008/07/21/cisco-related-ebay-bargains/</link>
		<comments>http://cisconews.co.uk/2008/07/21/cisco-related-ebay-bargains/#comments</comments>
		<pubDate>Mon, 21 Jul 2008 19:45:33 +0000</pubDate>
		<dc:creator>Rich</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[Tricks and Tips]]></category>

		<guid isPermaLink="false">http://cisconews.co.uk/?p=121</guid>
		<description><![CDATA[As any of my colleagues will tell you, I suffer from what is almost an addiction to buying tech related items.
To name a few of my Ebay Cisco bargains, I picked up an ACS 1113 appliance for £129 and sold it for £1200, bought a Cat 500 24 port switch for £35 and an AP1242 [...]]]></description>
			<content:encoded><![CDATA[<p>As any of my colleagues will tell you, I suffer from what is almost an addiction to buying tech related items.<br />
To name a few of my Ebay Cisco bargains, I picked up an ACS 1113 appliance for £129 and sold it for £1200, bought a Cat 500 24 port switch for £35 and an AP1242 for £70.</p>
<p>Its at this point that I am going to point you towards our ebay Feed, which will bring up any Cisco related Auction Items that are in their last 4 hours. This way you will never miss another bargain!</p>
<p>Check it out <a href="http://rss.api.ebay.com/ws/rssapi?FeedName=SearchResults&#038;siteId=3&#038;language=en-GB&#038;output=RSS20&#038;catref=C5&#038;sacqy=&#038;sacur=0&#038;saslt=2&#038;from=R6&#038;saobfmts=exsif&#038;dfsp=32&#038;afepn=5336009285&#038;sacqyop=ge&#038;saslc=0&#038;floc=1&#038;sabfmts=0&#038;ga10244=10425&#038;saprclo=&#038;saprchi=&#038;saaff=afepn&#038;ftrv=6&#038;ftrt=1&#038;fcl=3&#038;ft=1&#038;frpp=50&#038;customid=&#038;nojspr=y&#038;satitle=Cisco&#038;afmp=&#038;sacat=58058&#038;saslop=1&#038;fss=0">HERE!</a></p>
]]></content:encoded>
			<wfw:commentRss>http://cisconews.co.uk/2008/07/21/cisco-related-ebay-bargains/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Cisco VPN on iPhone</title>
		<link>http://cisconews.co.uk/2008/07/21/cisco-vpn-on-iphone/</link>
		<comments>http://cisconews.co.uk/2008/07/21/cisco-vpn-on-iphone/#comments</comments>
		<pubDate>Mon, 21 Jul 2008 18:22:48 +0000</pubDate>
		<dc:creator>Rich</dc:creator>
		
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://cisconews.co.uk/?p=118</guid>
		<description><![CDATA[As some of you may know, Cisco VPN support was added to the iPhone as of Firmware 2.0.
I have tested the functionality and can report that not only does it work, but it is very easy to set up.

I tested the functionality last night by connecting into both of our Hosting site VPNs. It literally [...]]]></description>
			<content:encoded><![CDATA[<p>As some of you may know, Cisco VPN support was added to the iPhone as of Firmware 2.0.<br />
I have tested the functionality and can report that not only does it work, but it is very easy to set up.</p>
<p><span id="more-118"></span></p>
<p>I tested the functionality last night by connecting into both of our Hosting site VPNs. It literally is as simple as configuring Cisco&#8217;s own VPN client.<br />
Once configured you get a VPN section in the &#8220;settings&#8221; menu of the phone.<br />
Multiple VPNs are possible too which was a concern when I first set out to configure it.</p>
<p>Anyway, I would post a config guide but it is very basic to set up. If you run into any issues leave a comment and we will see what can be done!</p>
<p>Cheers,</p>
]]></content:encoded>
			<wfw:commentRss>http://cisconews.co.uk/2008/07/21/cisco-vpn-on-iphone/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Cisco IOS - NEW Feature</title>
		<link>http://cisconews.co.uk/2008/07/15/cisco-ios-new-feature/</link>
		<comments>http://cisconews.co.uk/2008/07/15/cisco-ios-new-feature/#comments</comments>
		<pubDate>Tue, 15 Jul 2008 08:32:47 +0000</pubDate>
		<dc:creator>Ray</dc:creator>
		
		<category><![CDATA[Config. Guides]]></category>

		<category><![CDATA[News]]></category>

		<category><![CDATA[Software]]></category>

		<category><![CDATA[Study Related]]></category>

		<category><![CDATA[Tricks and Tips]]></category>

		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://cisconews.co.uk/?p=117</guid>
		<description><![CDATA[Starting from IOS 12.4T Cisco are offering the facility for object groupings, those who use ASA/PIX will already be famliar with this concept.  Benefits include allowing easier management of larger access lists as well as reducing configuration sizes. This can be implemented as follows:
Step 1. Define the Object Group:

! Define network type object-groups to [...]]]></description>
			<content:encoded><![CDATA[<p>Starting from IOS 12.4T Cisco are offering the facility for object groupings, those who use ASA/PIX will already be famliar with this concept. <span id="more-117"></span> Benefits include allowing easier management of larger access lists as well as reducing configuration sizes. This can be implemented as follows:</p>
<p>Step 1. Define the Object Group:</p>
<blockquote><p>
! Define network type object-groups to group IP hosts and networks object-group network Engineering<br />
10.240.12.0 255.255.255.0<br />
10.245.10.0 255255.255.0<br />
object-group network Web-Servers<br />
10.1.1.0 255.255.255.0<br />
host 10.10.10.100<br />
object-group network Mail-Servers<br />
10.32.1.0 255.255.255.0<br />
! Define a service type object group to group you protocols and ports<br />
object-group service Web-ports<br />
tcp www<br />
tcp 8080<br />
object-group service Mail-ports<br />
tcp smtp<br />
tcp pop3<br />
tcp 587<br />
tcp 143
</p>
</blockquote>
<p>Step 2. Use Object Groups in ACL Configurations:</p>
<blockquote><p>
<p>ip access-list extended access-policy<br />
10 permit object-group Web-ports object-group Engineering object-group Web-Servers<br />
20 permit object-group Mail-ports object-group Engineering object-group Mail-Servers
</p>
</blockquote>
<p><strong><em>(All Examples used here and other new features can be found <a href="http://www.cisco.com/en/US/prod/collateral/iosswrel/ps8802/ps6968/ps6441/product_bulletin_c25-409474.html">here</a>)</p>
]]></content:encoded>
			<wfw:commentRss>http://cisconews.co.uk/2008/07/15/cisco-ios-new-feature/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Training Resources - CBT Nuggets</title>
		<link>http://cisconews.co.uk/2008/07/11/training-resources-cbt-nuggets/</link>
		<comments>http://cisconews.co.uk/2008/07/11/training-resources-cbt-nuggets/#comments</comments>
		<pubDate>Fri, 11 Jul 2008 09:59:32 +0000</pubDate>
		<dc:creator>Ray</dc:creator>
		
		<category><![CDATA[Study Related]]></category>

		<guid isPermaLink="false">http://cisconews.co.uk/?p=116</guid>
		<description><![CDATA[I was surprised recently when an IT professional told me they hadn’t heard of CBT nuggets! I thought I better put text to screen and quickly explain this valuable training resource&#8230;..

CBT Nuggets are short videos (nuggets) of information relating to specific areas of IT in relation to current exams. In short CBT Nuggets are a [...]]]></description>
			<content:encoded><![CDATA[<p>I was surprised recently when an IT professional told me they hadn’t heard of CBT nuggets! I thought I better put text to screen and quickly explain this valuable training resource&#8230;..</p>
<p><span id="more-116"></span></p>
<p>CBT Nuggets are short videos (nuggets) of information relating to specific areas of IT in relation to current exams. In short CBT Nuggets are a perfect accompaniment to the self studying students array of study guides, software and notes, great to quickly run through before an exam as well as providing the viewer with a good visual on the product/topic.</p>
<p>The videos are done by experts in the related fields, for example CCIE&#8217;s demonstrating various Cisco products and how to use them. Jeremy Cioara is one of the well known Cisco trainers, holding numerous qualification himself including multiple CCIE&#8217;s! His enthusiasm is present throughout the videos and really helps you to secure the knowledge, although it may border on fanaticism at times. <img src='http://cisconews.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>(Jeremy has his own blog at <a href="http://www.ciscoblog.com">ciscoblog.com </a>check it out! lots of interesting stuff)</p>
<p>Good Luck and get using CBT Nuggets!</p>
]]></content:encoded>
			<wfw:commentRss>http://cisconews.co.uk/2008/07/11/training-resources-cbt-nuggets/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Bluetooth to Serial adapters for Cisco Console Access</title>
		<link>http://cisconews.co.uk/2008/07/11/bluetooth-to-serial-adapters-for-cisco-console-access/</link>
		<comments>http://cisconews.co.uk/2008/07/11/bluetooth-to-serial-adapters-for-cisco-console-access/#comments</comments>
		<pubDate>Fri, 11 Jul 2008 09:36:33 +0000</pubDate>
		<dc:creator>Rich</dc:creator>
		
		<category><![CDATA[Tricks and Tips]]></category>

		<guid isPermaLink="false">http://cisconews.co.uk/?p=115</guid>
		<description><![CDATA[It seemed like a good idea to me, and when searching I found this:
http://www.microdirect.co.uk/ProductInfo.aspx?ProductID=17745&#038;source=googleps
They aren’t cheap that for sure. Security also starts to become a concern, but I can imagine these being exceptionally useful. With the prevalence of Bluetooth in laptops it looks like a tidy idea!
Let us know what you think in the comments [...]]]></description>
			<content:encoded><![CDATA[<p>It seemed like a good idea to me, and when searching I found this:</p>
<p>http://www.microdirect.co.uk/ProductInfo.aspx?ProductID=17745&#038;source=googleps</p>
<p>They aren’t cheap that for sure. Security also starts to become a concern, but I can imagine these being exceptionally useful. With the prevalence of Bluetooth in laptops it looks like a tidy idea!</p>
<p>Let us know what you think in the comments section!</p>
]]></content:encoded>
			<wfw:commentRss>http://cisconews.co.uk/2008/07/11/bluetooth-to-serial-adapters-for-cisco-console-access/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>

