Blog Archives

Reflexive access-lists on a Cisco router

Reflexive access-lists are one of the methods that can help us achieve full firewall functionality with a Cisco router. Setting up the access-lists I always tend to call my router/firewall access-lists the same thing, one called inside_out, and one called

Tagged with: , , ,
Posted in Cisco

BIND – preparing for DNSSEC

“The Domain Name System Security Extensions (DNSSEC) is a suite of Internet Engineering Task Force (IETF) specifications for securing certain kinds of information provided by the Domain Name System (DNS) as used on Internet Protocol (IP) networks. It is a

Tagged with: , , , , , ,
Posted in Linux

Default edge access-list

What should you be filtering on your edge routers? Cisco provides the following template as a good start to securing your edge routers. I recommend you have a good read through this and implement as much as you can. !—

Tagged with: , , ,
Posted in Cisco

OpenSWAN Sonicwall Netscreen IPSEC VPN

This tutorial will run through creating an IPSEC VPN tunnel between a central Netscreen firewall and a Linux server (CentOS) running OpenSWAN. Network Summary I am working with the following network scenario -: Central NetScreen firewall – 1.1.1.1 Linux OpenSWAN

Tagged with: , , , , , , ,
Posted in Linux