<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">

  <title>Mettle News</title>
  <link rel="alternate" href="http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi/list/mettlenewsletter/"/>
  <link rel="self"      href="http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi/archive_atom/mettlenewsletter/"/>
  
  <updated>2012-02-05T02:16:40Z</updated>
  <author>
    <name>Mettle News List Owner</name>
     
    <email>&#109;&#101;&#x74;&#x74;&#x6C;&#101;&#110;&#101;&#119;&#x73;&#x40;&#109;&#x65;&#x74;&#x74;&#x6C;&#x65;&#x6E;&#x65;&#x74;&#x77;&#111;&#114;&#x6B;&#115;&#46;&#99;&#x6F;&#x6D;</email>
  </author>
  <id>http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi</id>
 
  <generator>Dada Mail 3.0.0</generator>
 

  <entry>
    <title>Mettle News November, 2010</title>
    <link rel="alternate" href="http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi/archive/mettlenewsletter/20101129172942/"/>
    <id>tag:newsletter.mettlenetworks.com,2010-11-29:%2Fcgi-bin%2Fmail.cgi%2Farchive%2Fmettlenewsletter%2F20101129172942%2F</id>
    
    <published>2010-11-29T17:29:42Z</published>
    <updated>2010-11-29T17:29:42Z</updated>
    <content type="html">&lt;p&gt;&lt;br /&gt;
&lt;br /&gt;
METTLE NEWS&lt;br /&gt;
[News letter on Mettle(tm) brand of products; Industry updates, Tips and Case&lt;br /&gt;
studies]&lt;br /&gt;
&lt;br /&gt;
November 2010 &lt;br /&gt;
Volume 3, Issue 9 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In this issue: &lt;br /&gt;
&lt;br /&gt;
* Editorial &lt;br /&gt;
* IT Industry news: Stuxnet Worm &lt;br /&gt;
* Tip of the month: Deactivating Content Filter &amp;#38; Gateway Anti virus &lt;br /&gt;
* A Mettle SE feature:  Captive Portal&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Editorial &lt;br /&gt;
&lt;br /&gt;
If you keep a log of viruses and worms coming out every month, you won't be amazed on new break outs and only&lt;br /&gt;
thing is that you need to be prepared for it. Preparation is a vague word to describe this scenario. And this&lt;br /&gt;
time, the threat is in the form of a worm called Stuxnet and its destruction power is not limited to just&lt;br /&gt;
computer system but process control system. See this months industry news for more information.&lt;br /&gt;
&lt;br /&gt;
Many a time, you might need to turn off Content scanning and Gateway anti-virus feature for one reason or&lt;br /&gt;
other. This month's Tip of the Month column describes how to do this.&lt;br /&gt;
&lt;br /&gt;
Captive Portal is one of the admired features in Mettle SE that allows you to prompt your users to login&lt;br /&gt;
before accessing WAN/Internet. This month's Mettle SE Feature describes how easy it is to set up.&lt;br /&gt;
&lt;br /&gt;
As we enter into the last month of the year, we are preparing to for a change for the better; details will&lt;br /&gt;
follow.&lt;br /&gt;
&lt;br /&gt;
Warm regards,&lt;br /&gt;
&lt;br /&gt;
Editor, Mettle News&lt;br /&gt;
(&lt;a href=&quot;mailto:&amp;#x6D;&amp;#101;&amp;#x74;&amp;#x74;&amp;#108;&amp;#101;&amp;#110;&amp;#x65;&amp;#119;&amp;#x73;&amp;#64;&amp;#x6D;&amp;#x65;&amp;#116;&amp;#116;&amp;#108;&amp;#x65;&amp;#x2E;&amp;#105;&amp;#110;&quot;&gt;&amp;#x6D;&amp;#101;&amp;#x74;&amp;#x74;&amp;#108;&amp;#101;&amp;#110;&amp;#x65;&amp;#119;&amp;#x73;&amp;#64;&amp;#x6D;&amp;#x65;&amp;#116;&amp;#116;&amp;#108;&amp;#x65;&amp;#x2E;&amp;#105;&amp;#110;&lt;/a&gt;)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* IT Industry News: Stuxnet Worm &lt;br /&gt;
&lt;br /&gt;
US government officials revealed that a malicious computer worm which targets Iran's nuclear plants could be&lt;br /&gt;
modified to wreak havoc on industrial computer systems around the world and could be the most severe cyber&lt;br /&gt;
threat known to industry. &lt;br /&gt;
&lt;br /&gt;
As industrial houses merge the networks and computer systems to increase efficiency and productivity they are&lt;br /&gt;
becoming more vulnerable to the Stuxnet worm. Stuxnet's complex code is able to infiltrate and take over&lt;br /&gt;
systems that control manufacturing and critical operations and has sophisticated abilities to steal&lt;br /&gt;
intellectual property and sensitive data. Symantec Corporation's Global Intelligence Director, Dean Turner,&lt;br /&gt;
told the US homeland officials that the real world implications of the Stuxnet worm is is beyond any threat&lt;br /&gt;
seen so far. &lt;br /&gt;
&lt;br /&gt;
Experts warned that the industries are becoming increasingly vulnerable to the so-called Stuxnet worm as they&lt;br /&gt;
merge networks and computer systems to increase efficiency. The growing danger, said lawmakers, makes it&lt;br /&gt;
imperative that Congress move on legislation that would expand government controls and set requirements to&lt;br /&gt;
make systems safer. &lt;br /&gt;
&lt;br /&gt;
Stuxnet targets businesses using Windows operating system and a control system designed by Siemens AG.&lt;br /&gt;
Sean McGurk, the acting director of US Homeland Security's cyber security operations center, says that this&lt;br /&gt;
Windows and Siemens combination software is used in many critical sectors, like automobile assembly and&lt;br /&gt;
chemical industries. Experts have warned that attackers can use information made public about the Stuxnet worm&lt;br /&gt;
to develop variations targeting other industries. &lt;br /&gt;
&lt;br /&gt;
Michael Assante, President of the National Board of Information Security Examiners have told authorities that&lt;br /&gt;
control systems needs to be walled off from other networks to secure it from unauthorized access from the&lt;br /&gt;
hackers and make it harder for them to access it. Mr. Assante participated in a research in 2007 at the&lt;br /&gt;
national lab, in which during a test they used commands delivered over the Internet to destroy a Diesel&lt;br /&gt;
generator. He believes stuxnet worm could be such a weapon but with capability to wreak chaos on a larger&lt;br /&gt;
scale. &lt;br /&gt;
&lt;br /&gt;
India ranks 4th, followed by United States in 5th in the Stuxnet invasion statistics. &lt;br /&gt;
&lt;br /&gt;
Read more: &lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://news.yahoo.com/s/ap/20101117/ap_on_hi_te/us_cyber_threats&quot;&gt;http://news.yahoo.com/s/ap/20101117/ap_on_hi_te/us_cyber_threats&lt;/a&gt; &lt;br /&gt;
&lt;a href=&quot;http://news.yahoo.com/s/csm/20101118/ts_csm/344234_1&quot;&gt;http://news.yahoo.com/s/csm/20101118/ts_csm/344234_1&lt;/a&gt; &lt;br /&gt;
&lt;a href=&quot;http://en.wikipedia.org/wiki/Stuxnet&quot;&gt;http://en.wikipedia.org/wiki/Stuxnet&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Tip of the month: Deactivating Content Filter &amp;#38; Gateway Anti virus &lt;br /&gt;
&lt;br /&gt;
Turning off the Content Filter or the Gateway Anti virus is not recommended operation for the sake of your&lt;br /&gt;
network security. But if you ever need to disable these services for this is how you do it. &lt;br /&gt;
&lt;br /&gt;
1. In the Mettle SE web interface go to Status --&amp;#62;Services. You can see the list of running services here. &lt;br /&gt;
2. The green 'Play' button against each item means that it is active. &lt;br /&gt;
3. To stop the Content filtering service, click on the 'Stop' button next to Dansguardian. &lt;br /&gt;
4. To stop the Gateway anti virus service, click on the 'stop' button next to ClamAV. &lt;br /&gt;
&lt;br /&gt;
Once you have stopped these two services the content filtering will no longer work and the network will be&lt;br /&gt;
vulnerable to viruses, worms, trojans and similar threats from the Internet. Be sure to re-activate these two&lt;br /&gt;
services as soon as the need for them being inactive is over. &lt;br /&gt;
&lt;br /&gt;
To re-activate these services, come back to the same page and click on the 'Restart' button next to them. &lt;br /&gt;
&lt;br /&gt;
KB article: &lt;a href=&quot;http://kb.mettle.in/entry/8/&quot;&gt;http://kb.mettle.in/entry/8/&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* A Mettle SE feature: Captive Portal &lt;br /&gt;
&lt;br /&gt;
Captive portal is the technique in which a device trying to access the Internet is forced to a login page&lt;br /&gt;
asking for credentials before it is allowed to access the Internet. Mettle SE supports Captive Portal used for&lt;br /&gt;
HTTP authentication with a web browser. When Captive Portal is enabled the clients on the network will be&lt;br /&gt;
re-directed to a HTTP authentication web page before they can access the Internet. &lt;br /&gt;
&lt;br /&gt;
This is how you enable Captive Portal feature in your Mettle SE. &lt;br /&gt;
&lt;br /&gt;
1. Go to Services --&amp;#62; Captive Portal --&amp;#62; Captive Portal tab &lt;br /&gt;
2. To enable captive portal check the box &amp;#34;Enable Captive Portal&amp;#34; &lt;br /&gt;
3. Choose the interface captive portal is to enabled. Usually this is your local network. &lt;br /&gt;
4. Enter the maximum number of concurrent connections to be allowed &lt;br /&gt;
5. Enter the idle timeout in minutes. Idle clients will be logged out after the timeout. &lt;br /&gt;
6. Enter the hard timeout in seconds. Clients including active clients will be logged out after the timeout. &lt;br /&gt;
7. Check the box to enable logout pop up window if required. &lt;br /&gt;
8. Redirection URL - All clients will be redirected to the specified URL after logging in. &lt;br /&gt;
9. Concurrent logins - If enabled only the most recent login of a user will be active. Previous logins of the&lt;br /&gt;
   same user will be logged out. &lt;br /&gt;
10. MAC filtering - If disabled, attempts will not be made to ensure that the MAC address of clients stays the&lt;br /&gt;
    same while they're logged in. This is required when the MAC address of the client cannot be determined&lt;br /&gt;
    (usually when there are routers between Mettle SE and client computers). RADIUS MAC authentication cannot&lt;br /&gt;
    be used when MAC filtering is enabled. &lt;br /&gt;
11. Authentication - Select an authentication method; 'No Authentication', 'Local user manager' or 'RADIUS'.&lt;br /&gt;
    If RADIUS is chosen, enter RADIUS server details below. If 'Local User Manager' is selected you can manage&lt;br /&gt;
    users in the &amp;#34;Users&amp;#34; tab. &lt;br /&gt;
12. Enable HTTPS login - If enabled, login information would be transmitted over secure HTTPS connection. &lt;br /&gt;
13. Enter HTTPS server details in the fields below. &lt;br /&gt;
14. Click on 'Save' &lt;br /&gt;
&lt;br /&gt;
Captive Portal Pass through MAC &lt;br /&gt;
&lt;br /&gt;
Pass through MAC If a pass through MAC is added to Captive portal then users logging in from this MAC address&lt;br /&gt;
will not be taken to a portal authentication page. &lt;br /&gt;
&lt;br /&gt;
1. Select Services --&amp;#62; Captive Portal-- &amp;#62; Pass through MAC tab to enable this. &lt;br /&gt;
2. Click on the '+' button &lt;br /&gt;
3. Enter the MAC address &lt;br /&gt;
4. Enter a description (not parsed) &lt;br /&gt;
5. Click on 'Save' &lt;br /&gt;
&lt;br /&gt;
Captive Portal Allowed IP address &lt;br /&gt;
&lt;br /&gt;
Adding allowed IP addresses will allow IP access to/from these addresses through the captive portal without&lt;br /&gt;
being taken to the portal page. This can be used for a web server serving images for the portal page or a DNS&lt;br /&gt;
server on another network, for example. By specifying from addresses, &lt;br /&gt;
&lt;br /&gt;
1. Select Services --&amp;#62; Captive Portal --&amp;#62; Allowed IP addresses &lt;br /&gt;
2. Click on the '+' button to add an IP address &lt;br /&gt;
3. Choose the direction either From or To &lt;br /&gt;
4. Enter the IP address to be allowed &lt;br /&gt;
5. Enter a description for the IP address added (not parsed) &lt;br /&gt;
6. Click on 'Save' &lt;br /&gt;
&lt;br /&gt;
Managing Captive Portal Users &lt;br /&gt;
&lt;br /&gt;
1. Select Services --&amp;#62; Captive Portal --&amp;#62; Users &lt;br /&gt;
2. To add an user click on the '+' button &lt;br /&gt;
3. Enter the user name &lt;br /&gt;
4. Enter the password &lt;br /&gt;
5. Confirm the password &lt;br /&gt;
6. Enter users full name (not parsed) &lt;br /&gt;
7. Enter an expiry date for the user you have created by clicking on the 'Calendar' button next to the text&lt;br /&gt;
   area. If a date is not entered the account will not expire. &lt;br /&gt;
8. Click on 'Save' &lt;br /&gt;
&lt;br /&gt;
KB article: &lt;a href=&quot;http://kb.mettle.in/entry/31/&quot;&gt;http://kb.mettle.in/entry/31/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
We would like to receive feedback regarding the content of this newsletter and&lt;br /&gt;
request for articles. Please send in your valuable suggestions to&lt;br /&gt;
&lt;a href=&quot;mailto:&amp;#x6D;&amp;#101;&amp;#x74;&amp;#x74;&amp;#108;&amp;#101;&amp;#110;&amp;#x65;&amp;#119;&amp;#x73;&amp;#64;&amp;#x6D;&amp;#x65;&amp;#116;&amp;#116;&amp;#108;&amp;#x65;&amp;#x2E;&amp;#105;&amp;#110;&quot;&gt;&amp;#x6D;&amp;#101;&amp;#x74;&amp;#x74;&amp;#108;&amp;#101;&amp;#110;&amp;#x65;&amp;#119;&amp;#x73;&amp;#64;&amp;#x6D;&amp;#x65;&amp;#116;&amp;#116;&amp;#108;&amp;#x65;&amp;#x2E;&amp;#105;&amp;#110;&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
Mettle and Linuxense are trademarks of Linuxense Information Systems Pvt. Ltd.&lt;br /&gt;
Other trademarks belong to respective owners. 2010 (C) Linuxense Information&lt;br /&gt;
Systems Pvt. Ltd. All rights reserved.&lt;/p&gt;
    	&lt;!-- begin subscription_form_widget.tmpl --&gt; 



 

    &lt;form action=&quot;http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi&quot; method=&quot;post&quot;&gt;

 

&lt;fieldset&gt;
&lt;legend&gt;
 Subscribe/Unsubscribe  on Mettle News
&lt;/legend&gt;

 
    

    &lt;input type=&quot;hidden&quot; name=&quot;list&quot; value=&quot;mettlenewsletter&quot; /&gt;


&lt;p&gt;
&lt;label for=&quot;email&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot; &gt;
Email&amp;nbsp;Address: 
&lt;/label&gt;
&lt;input type=&quot;text&quot; name=&quot;email&quot; id=&quot;email&quot; value=&quot;&quot; /&gt; &lt;span class=&quot;error&quot;&gt;* Required&lt;/span&gt;
&lt;/p&gt;

 

    &lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

     
    
        &lt;p&gt;
        &lt;label for=&quot;name&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
        Name: 
        &lt;/label&gt;
        &lt;input type=&quot;text&quot; name=&quot;name&quot; id=&quot;name&quot; value=&quot;&quot;  /&gt;
        &lt;/p&gt;
    
    
     

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

 
    &lt;p&gt;
    &lt;label for=&quot;f_s&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
    Subscribe
    &lt;/label&gt;
    &lt;input type=&quot;radio&quot; name=&quot;f&quot; id=&quot;f_s&quot; value=&quot;subscribe&quot; checked=&quot;checked&quot; /&gt;
    &lt;/p&gt; 
    
    &lt;p&gt; 
    &lt;label for=&quot;f_u&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;Unsubscribe&lt;/label&gt; 
    &lt;input type=&quot;radio&quot; name=&quot;f&quot;  id=&quot;f_u&quot;  value=&quot;unsubscribe&quot;  /&gt;
    &lt;/p&gt;   

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

&lt;p style=&quot;text-align:right;display:block&quot;&gt;
&lt;input type=&quot;submit&quot; value=&quot;Submit Your Information&quot; class=&quot;processing&quot; /&gt;
&lt;/p&gt; 


 

    &lt;p style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;&lt;a href=&quot;http://dadamailproject.com&quot; target=&quot;_blank&quot; style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;Powered by Dada Mail 3.0.0 Mailing List Manager&lt;/a&gt;&lt;/p&gt;

 




&lt;/fieldset&gt;
&lt;/form&gt; 



  
&lt;!-- end subscription_form_widget.tmpl --&gt; 
     
    </content>
  </entry>

 

  <entry>
    <title>Mettle News October, 2010</title>
    <link rel="alternate" href="http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi/archive/mettlenewsletter/20101102131043/"/>
    <id>tag:newsletter.mettlenetworks.com,2010-11-02:%2Fcgi-bin%2Fmail.cgi%2Farchive%2Fmettlenewsletter%2F20101102131043%2F</id>
    
    <published>2010-11-02T13:10:43Z</published>
    <updated>2010-11-02T13:10:43Z</updated>
    <content type="html">&lt;p&gt;&lt;br /&gt;
&lt;br /&gt;
METTLE NEWS&lt;br /&gt;
[News letter on Mettle(tm) brand of products; Industry updates, Tips and Case&lt;br /&gt;
studies]&lt;br /&gt;
&lt;br /&gt;
October 2010 &lt;br /&gt;
Volume 3, Issue 8 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In this issue: &lt;br /&gt;
&lt;br /&gt;
* Editorial &lt;br /&gt;
* IT Industry news: SpamBot wants to be your friend &lt;br /&gt;
* Tip of the month: NAT Reflection &lt;br /&gt;
* A Mettle SE feature: Split-Horizon DNS &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Editorial *&lt;br /&gt;
&lt;br /&gt;
Greetings,&lt;br /&gt;
&lt;br /&gt;
Social networking has been a boom; it helped us to connect back with our lost friends, maintain business&lt;br /&gt;
relationships, etc. It has come to a culture that it is near impossible to maintain our social life without an&lt;br /&gt;
account in one of the social networking sites. This month's industry news talks about security and privacy&lt;br /&gt;
problems posed by social networking web sites.&lt;br /&gt;
&lt;br /&gt;
In many enterprise/campus networks, there will be a set of services hosted in the DMZ (with port forwarding)&lt;br /&gt;
which are publically accessible. There are occasions that requires accessing those services from within the&lt;br /&gt;
private LAN as well. &amp;#34;Tip of month&amp;#34; sections describes about a feature of Mettle SE, called, NAT Reflection&lt;br /&gt;
and how to attain this.&lt;br /&gt;
&lt;br /&gt;
Split Horizon is a feature that can meet the above requirement if it is possible to configure DMZ servers with&lt;br /&gt;
private IP addresses. But this requires that those who are accessing those servers from inside the LAN should&lt;br /&gt;
get that private IP addresses of those servers. Mettle SE provide a feature called Split Horizon to meet this&lt;br /&gt;
requirement. Read in detail in the &amp;#34;A Mettle SE Feature&amp;#34; section.&lt;br /&gt;
&lt;br /&gt;
Happy networking!&lt;br /&gt;
&lt;br /&gt;
Editor, Mettle News&lt;br /&gt;
(&lt;a href=&quot;mailto:&amp;#x6D;&amp;#x65;&amp;#x74;&amp;#x74;&amp;#x6C;&amp;#101;&amp;#x6E;&amp;#101;&amp;#119;&amp;#115;&amp;#x40;&amp;#x6D;&amp;#101;&amp;#x74;&amp;#x74;&amp;#108;&amp;#101;&amp;#46;&amp;#x69;&amp;#x6E;&quot;&gt;&amp;#x6D;&amp;#x65;&amp;#x74;&amp;#x74;&amp;#x6C;&amp;#101;&amp;#x6E;&amp;#101;&amp;#119;&amp;#115;&amp;#x40;&amp;#x6D;&amp;#101;&amp;#x74;&amp;#x74;&amp;#108;&amp;#101;&amp;#46;&amp;#x69;&amp;#x6E;&lt;/a&gt;)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* IT Industry News: SpamBot wants to be your friend * &lt;br /&gt;
&lt;br /&gt;
Finding new friends and contacts on social networking sites and keeping in touch with your old and new friends&lt;br /&gt;
and relatives  have become just as routine as texting or emailing. As more and more number of people migrate&lt;br /&gt;
to social networking websites security risks of these websites pose are becoming more common. &lt;br /&gt;
&lt;br /&gt;
Gilbert Wondracek and Christian Platzer of the Secure Systems Lab at Vienna University of Technology have been&lt;br /&gt;
doing research on such security issues. With a few simple tricks they managed to match more than 1.2 million&lt;br /&gt;
social network profiles with corresponding email addresses. Gilbert and Platzer did this experiment for&lt;br /&gt;
scientific research, but what if next attack is launched by hackers intending to cause grief? &lt;br /&gt;
&lt;br /&gt;
For an average user creating a profile on social networking sites they want to get into contact with as many&lt;br /&gt;
contacts as possible. These social networking websites offer an easy way to find contacts you may know from&lt;br /&gt;
your email address book and the website list profiles matching the email addresses in your address book.&lt;br /&gt;
Christian Platzer says it is a cause for concern because even if an user has chosen to hide the email address&lt;br /&gt;
in his profile, the social networking website would still use it to identify the user. &lt;br /&gt;
&lt;br /&gt;
The researchers used email addresses taken from an offline spam-server and using simple computer programs,&lt;br /&gt;
email addresses could be checked on various social networking sites in a short period of time. If the social&lt;br /&gt;
network site responds that there is indeed a user profile for a given email address, then it is most likely&lt;br /&gt;
that an address still in use and in addition, the user profile provides valuable personal information about&lt;br /&gt;
the owner of the email address. In someone's user profile a list of names of their friends can be found&lt;br /&gt;
usually, from this list, new email addresses can be generated. The researchers used a computer program to&lt;br /&gt;
create a list of possible email addresses for each name. Then these email addresses can again be tested like&lt;br /&gt;
previously to find out if any of these addresses are registered on a social network site. That way, hundreds&lt;br /&gt;
of thousands of valid email addresses could be found rapidly. &lt;br /&gt;
&lt;br /&gt;
Further dangers are posed by user groups on various social network sites. On user groups, people discuss their&lt;br /&gt;
favourite topics and get to know other people with similar interests. But such groups can cause users to lose&lt;br /&gt;
their web anonymity. A harmless-looking website may search the user's browser history and find out which group&lt;br /&gt;
websites have been visited recently. If the malicious website knows the list of groups the user has joined and&lt;br /&gt;
then his identity can, in many cases, be determined quite accurately. It is rather improbable that several&lt;br /&gt;
users are members of exactly the same set of groups. That way the website can even guess the user's name even&lt;br /&gt;
if the site itself is in no way affiliated with social network sites. &lt;br /&gt;
&lt;br /&gt;
The most harmless thing that could happen to the victim is they're going to get truckloads of spam, but&lt;br /&gt;
serious frauds are also possible. Tricksters could pretend to be friends or business partners and contact the&lt;br /&gt;
victim using text made using victim's personal data obtained from the social network profile, and the victim&lt;br /&gt;
is tempted to believe that the sender is the person he claims to be. &lt;br /&gt;
&lt;br /&gt;
Researchers have already reported the new found security hazards to the social networking websites and the&lt;br /&gt;
problems have been fixed in some cases. But for Internet users it pays to be careful but not paranoid,&lt;br /&gt;
following some simple safety steps could prevent you from becoming a victim. &lt;br /&gt;
&lt;br /&gt;
1) It is never a good idea to upload one's email address book anywhere on the Internet. Valuable data which&lt;br /&gt;
   should better be kept private is distributed that way. &lt;br /&gt;
2) Most social network sites offer the possibility of deciding what information should be visible to others&lt;br /&gt;
   and which should be restricted to personal friends. It is advisable to choose restrictive settings. &lt;br /&gt;
3) Special care should be taken with tagging photographs. Not everybody needs to identify you in photos posted&lt;br /&gt;
   by others. &lt;br /&gt;
4) Telephone numbers or private addresses should never be posted in the profile. Data like that should only be&lt;br /&gt;
   given personally to people who are actually supposed to have it. &lt;br /&gt;
&lt;br /&gt;
For detailed reading: &lt;a href=&quot;http://www.tuwien.ac.at/news/news_detail/article/6670//EN/&quot;&gt;http://www.tuwien.ac.at/news/news_detail/article/6670//EN/&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Tip of the month: NAT Reflection *&lt;br /&gt;
&lt;br /&gt;
NAT Reflection refers to the ability to access   services hosted in DMZ from the internal network by its&lt;br /&gt;
public IP address. Mettle SE offers NAT Reflection.&lt;br /&gt;
&lt;br /&gt;
To enable NAT Reflection: &lt;br /&gt;
&lt;br /&gt;
1) Go to:  System --&amp;#62; Advanced &lt;br /&gt;
2) Scroll down to Network Address Translation and uncheck &amp;#34;Disable NAT Reflection&amp;#34; check box &lt;br /&gt;
3) Click on &amp;#34;Save&amp;#34;.&lt;br /&gt;
&lt;br /&gt;
NAT reflection will now be enabled. &lt;br /&gt;
&lt;br /&gt;
Read more here: &lt;a href=&quot;http://kb.mettle.in/entry/56/&quot;&gt;http://kb.mettle.in/entry/56/&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* A Mettle SE Feature: Split-Horizon DNS *&lt;br /&gt;
&lt;br /&gt;
In a Split-Horizon DNS infrastructure two DNS zones are created for the same domain, one to be used by&lt;br /&gt;
Internal network and the other to be used by the external network. A split DNS routes the internal hosts to an&lt;br /&gt;
internal domain name server for name resolution and external hosts are directed to an external domain name&lt;br /&gt;
server for name resolution. &lt;br /&gt;
&lt;br /&gt;
If you're using Mettle SE as the DNS server for internal hosts you can use DNS forwarder override to implement&lt;br /&gt;
split DNS deployment.&lt;br /&gt;
&lt;br /&gt;
Adding an override to DNS forwarder: &lt;br /&gt;
&lt;br /&gt;
1) Go To:  Services --&amp;#62; DNS Forwarder &lt;br /&gt;
2) Click the '+' button under &amp;#34;You may enter records that override the results from the forwarders below&amp;#34; &lt;br /&gt;
3) This brings up the DNS forwarder: Edit host screen You will need to add an override for each hostname in&lt;br /&gt;
   use behind your firewall. &lt;br /&gt;
&lt;br /&gt;
Examples for DNS overrides for mettle.in www.mettle.in &lt;br /&gt;
&lt;br /&gt;
a) Host: &lt;br /&gt;
   Domain: mettle.in &lt;br /&gt;
   IP Address: 192.168.1.5 &lt;br /&gt;
   Description: Override for mettle.in web server &lt;br /&gt;
&lt;br /&gt;
b) Host: www &lt;br /&gt;
   Domain: mettle.in &lt;br /&gt;
   IP Address: 192.168.1.5 &lt;br /&gt;
   Description: Override for www.mettle.in &lt;br /&gt;
&lt;br /&gt;
If using other DNS servers in your internal network like Microsoft Active Directory, you will need to create&lt;br /&gt;
zones for all the domains hosted inside the network along with all other records for those domains. &lt;br /&gt;
&lt;br /&gt;
In network scenarios with BIND DNS server where the public DNS is hosted on the same server as the private&lt;br /&gt;
DNS, BIND's views feature is used to resolve DNS differently for internal hosts and external ones. &lt;br /&gt;
&lt;br /&gt;
Read more here: &lt;a href=&quot;http://kb.mettle.in/entry/55/&quot;&gt;http://kb.mettle.in/entry/55/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
We would like to receive feedback regarding the content of this newsletter and&lt;br /&gt;
request for articles. Please send in your valuable suggestions to&lt;br /&gt;
&lt;a href=&quot;mailto:&amp;#x6D;&amp;#x65;&amp;#x74;&amp;#x74;&amp;#x6C;&amp;#101;&amp;#x6E;&amp;#101;&amp;#119;&amp;#115;&amp;#x40;&amp;#x6D;&amp;#101;&amp;#x74;&amp;#x74;&amp;#108;&amp;#101;&amp;#46;&amp;#x69;&amp;#x6E;&quot;&gt;&amp;#x6D;&amp;#x65;&amp;#x74;&amp;#x74;&amp;#x6C;&amp;#101;&amp;#x6E;&amp;#101;&amp;#119;&amp;#115;&amp;#x40;&amp;#x6D;&amp;#101;&amp;#x74;&amp;#x74;&amp;#108;&amp;#101;&amp;#46;&amp;#x69;&amp;#x6E;&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
Mettle and Linuxense are trademarks of Linuxense Information Systems Pvt. Ltd.&lt;br /&gt;
Other trademarks belong to respective owners. 2008 (C) Linuxense Information&lt;br /&gt;
Systems Pvt. Ltd. All rights reserved.&lt;/p&gt;
    	&lt;!-- begin subscription_form_widget.tmpl --&gt; 



 

    &lt;form action=&quot;http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi&quot; method=&quot;post&quot;&gt;

 

&lt;fieldset&gt;
&lt;legend&gt;
 Subscribe/Unsubscribe  on Mettle News
&lt;/legend&gt;

 
    

    &lt;input type=&quot;hidden&quot; name=&quot;list&quot; value=&quot;mettlenewsletter&quot; /&gt;


&lt;p&gt;
&lt;label for=&quot;email&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot; &gt;
Email&amp;nbsp;Address: 
&lt;/label&gt;
&lt;input type=&quot;text&quot; name=&quot;email&quot; id=&quot;email&quot; value=&quot;&quot; /&gt; &lt;span class=&quot;error&quot;&gt;* Required&lt;/span&gt;
&lt;/p&gt;

 

    &lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

     
    
        &lt;p&gt;
        &lt;label for=&quot;name&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
        Name: 
        &lt;/label&gt;
        &lt;input type=&quot;text&quot; name=&quot;name&quot; id=&quot;name&quot; value=&quot;&quot;  /&gt;
        &lt;/p&gt;
    
    
     

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

 
    &lt;p&gt;
    &lt;label for=&quot;f_s&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
    Subscribe
    &lt;/label&gt;
    &lt;input type=&quot;radio&quot; name=&quot;f&quot; id=&quot;f_s&quot; value=&quot;subscribe&quot; checked=&quot;checked&quot; /&gt;
    &lt;/p&gt; 
    
    &lt;p&gt; 
    &lt;label for=&quot;f_u&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;Unsubscribe&lt;/label&gt; 
    &lt;input type=&quot;radio&quot; name=&quot;f&quot;  id=&quot;f_u&quot;  value=&quot;unsubscribe&quot;  /&gt;
    &lt;/p&gt;   

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

&lt;p style=&quot;text-align:right;display:block&quot;&gt;
&lt;input type=&quot;submit&quot; value=&quot;Submit Your Information&quot; class=&quot;processing&quot; /&gt;
&lt;/p&gt; 


 

    &lt;p style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;&lt;a href=&quot;http://dadamailproject.com&quot; target=&quot;_blank&quot; style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;Powered by Dada Mail 3.0.0 Mailing List Manager&lt;/a&gt;&lt;/p&gt;

 




&lt;/fieldset&gt;
&lt;/form&gt; 



  
&lt;!-- end subscription_form_widget.tmpl --&gt; 
     
    </content>
  </entry>

 

  <entry>
    <title>Mettle News September, 2010</title>
    <link rel="alternate" href="http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi/archive/mettlenewsletter/20100930161707/"/>
    <id>tag:newsletter.mettlenetworks.com,2010-09-30:%2Fcgi-bin%2Fmail.cgi%2Farchive%2Fmettlenewsletter%2F20100930161707%2F</id>
    
    <published>2010-09-30T16:17:07Z</published>
    <updated>2010-09-30T16:17:07Z</updated>
    <content type="html">&lt;p&gt;&lt;br /&gt;
&lt;br /&gt;
METTLE NEWS&lt;br /&gt;
[News letter on Mettle(tm) brand of products; Industry updates, Tips and Case&lt;br /&gt;
studies]&lt;br /&gt;
&lt;br /&gt;
September 2010 &lt;br /&gt;
Volume 3, Issue 7&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In this issue: &lt;br /&gt;
&lt;br /&gt;
* Editorial &lt;br /&gt;
* IT Industry news: 64bit Linux Kernel Vulnerability&lt;br /&gt;
* Tip of the month!: How to make OpenVPN clients use the VPN as the default gateway?&lt;br /&gt;
* Introducing a Mettle SE feature!: Establishing an IPsec VPN Tunnel&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Editorial&lt;br /&gt;
&lt;br /&gt;
This month's Industry News section contain the information about a 64 bit Linux kernel vulnerability. We have&lt;br /&gt;
included this article because many of our Mettle customers have deployed Linux machines for production use.&lt;br /&gt;
More over, those of our readers who are interested in knowing what this vulnerability is all about can dig&lt;br /&gt;
deeper with the links provided.&lt;br /&gt;
&lt;br /&gt;
Usage of VPN is on the increase. Those who have deployed Mettle SE would make that job easier and not to&lt;br /&gt;
mention in a very economic way. This month's tip of the month describes how Mettle SE SSL VPN server lets you&lt;br /&gt;
determine the gateway of the SSL VPN client.&lt;br /&gt;
&lt;br /&gt;
Continuing with the subject of VPN, this month's Mettle SE feature too deal with the subject. This month the&lt;br /&gt;
section talks about how to establish an IPSec VPN tunnel using Mettle SE.&lt;br /&gt;
&lt;br /&gt;
Yours Sincerely,&lt;br /&gt;
&lt;br /&gt;
Editor, Mettle News&lt;br /&gt;
(&lt;a href=&quot;mailto:&amp;#109;&amp;#x65;&amp;#116;&amp;#x74;&amp;#x6C;&amp;#101;&amp;#x6E;&amp;#101;&amp;#x77;&amp;#x73;&amp;#x40;&amp;#109;&amp;#101;&amp;#116;&amp;#116;&amp;#x6C;&amp;#x65;&amp;#46;&amp;#x69;&amp;#110;&quot;&gt;&amp;#109;&amp;#x65;&amp;#116;&amp;#x74;&amp;#x6C;&amp;#101;&amp;#x6E;&amp;#101;&amp;#x77;&amp;#x73;&amp;#x40;&amp;#109;&amp;#101;&amp;#116;&amp;#116;&amp;#x6C;&amp;#x65;&amp;#46;&amp;#x69;&amp;#110;&lt;/a&gt;)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* IT Industry News: 64bit Linux Kernel Vulnerability&lt;br /&gt;
&lt;br /&gt;
On 17th September a potentially harmful security vulnerability was identified which affects computers running&lt;br /&gt;
on 64bit Linux operating systems (CVE-2010-3081 ). This backdoor vulnerability allows a hacker to take over a&lt;br /&gt;
server and give him full root access. This is a critical security lapse since this vulnerability has been&lt;br /&gt;
exploited much quicker than usual. This security vulnerability was introduced into the the 64bit Linux Kernel&lt;br /&gt;
in April 2008 and it means every 64bit Linux distribution is affected including the most popular ones.&lt;br /&gt;
&lt;br /&gt;
If a system was already compromised using CVE-2010-3081 exploit, a simple update will not heal and seal the&lt;br /&gt;
exploit. The exploit may continue to be active even after it has been updated because of the backdoor&lt;br /&gt;
installed by the exploit. It is also possible that the hacker could have installed other backdoors in your&lt;br /&gt;
server. Use the 'chkrootkit' command to scan for known and detectable backdoors and rootkits.&lt;br /&gt;
&lt;br /&gt;
Ksplice has published an application with which you can check is the vulnerability has been exploited in your&lt;br /&gt;
server and if a backdoor is running into memory. If your system has not been compromised it is recommended&lt;br /&gt;
that you should patch your kernel now, most popular distributions have come up with a kernel patch.&lt;br /&gt;
&lt;br /&gt;
If you use or administer a 64bit Linux computer we suggest you use the tool to ascertain whether the machines&lt;br /&gt;
were compromised and act accordingly. You can get the tool from here.&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.ksplice.com/uptrack/cve-2010-3081&quot;&gt;http://www.ksplice.com/uptrack/cve-2010-3081&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
You can read More for more information regarding the CVE-2010-3081 exploit and also for the links to kernel&lt;br /&gt;
patches at the following link.&lt;br /&gt;
&lt;a href=&quot;http://blog.iweb.com/en/2010/09/64bits-linux-important-security-vulnerability-identified/5437.html&quot;&gt;http://blog.iweb.com/en/2010/09/64bits-linux-important-security-vulnerability-identified/5437.html&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Tip of the month: How to make OpenVPN clients use the VPN as the default gateway?&lt;br /&gt;
&lt;br /&gt;
Certain VPN deployment scenarios may require that the VPN client use the VPN as the gateway of host PC. You&lt;br /&gt;
can implement this with Mettle SE VPN by issuing a simple command.&lt;br /&gt;
&lt;br /&gt;
1) Go to: VPN --&amp;#62; OpenVPN&lt;br /&gt;
2) Under Server tab click the 'e' button to edit the OpenVPN server configuration&lt;br /&gt;
3) Then in the server configuration page go down to 'Custom Options' and in the text field enter the text&lt;br /&gt;
   - push &amp;#34;redirect-gateway def1&amp;#34;;&lt;br /&gt;
4) Save the settings&lt;br /&gt;
&lt;br /&gt;
KB Article: &lt;a href=&quot;http://kb.mettle.in/entry/46/&quot;&gt;http://kb.mettle.in/entry/46/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Introducing a Mettle SE feature!: Establishing an IPsec VPN Tunnel&lt;br /&gt;
&lt;br /&gt;
If your offices or campuses are located at different regions separated by long distances you might need to&lt;br /&gt;
establish a permanent VPN tunnel between different locations for reasons mainly to do with secure transmission&lt;br /&gt;
of data. Described below is how you can create a IPsec VPN tunnel to establish the connection.&lt;br /&gt;
&lt;br /&gt;
Step 1: VPN Tunnel Creation&lt;br /&gt;
&lt;br /&gt;
a) Go to VPN --&amp;#62; IPsec--&amp;#62; Tunnels&lt;br /&gt;
b) Under 'Tunnels' check the 'Enable IPsec' check box and click on 'Save'&lt;br /&gt;
c) To create a new IPsec tunnel click on '+' button&lt;br /&gt;
d) Select WAN interface&lt;br /&gt;
e) At 'Local Subnet' enter local Network IP address, this is the Network to give access to VPN hosts&lt;br /&gt;
f) At 'Remote Subnet' enter IP address of the remote Network which will be connecting to the VPN&lt;br /&gt;
g) At 'Remote Gateway' enter public IP address of the remote Gateway&lt;br /&gt;
h) Enter a name or description for the Tunnel&lt;br /&gt;
&lt;br /&gt;
Step 2: The Phase 1 (Authentication) of configuration. Options selected here and changes made should reflect&lt;br /&gt;
in the remote VPN device.&lt;br /&gt;
&lt;br /&gt;
a) Select negotiation mode - Main for more security&lt;br /&gt;
b) Choose and set an Identifier&lt;br /&gt;
c) Choose an encryption mode - DES for low security 3DES for higher security&lt;br /&gt;
d) Choose a hash algorithm&lt;br /&gt;
e) Choose a DH key group&lt;br /&gt;
f) Enter key lifetime in seconds. Lower number for increased security &amp;#38; lower performance or higher number for&lt;br /&gt;
   vice versa&lt;br /&gt;
g) Choose authentication method - RSA signature for higher security. Pre Shared Key for ease of use&lt;br /&gt;
h) If the RSA signature is selected RSA certificates then certificate and key should be generated and pasted&lt;br /&gt;
   in their respective fields&lt;br /&gt;
h.1) Remote host should have matching RSA certificates and key string&lt;br /&gt;
i) If pre shared key is the preferred method then a key string should be entered in the field for 'Pre Shared&lt;br /&gt;
   Key'&lt;br /&gt;
i.1) Remote VPN host should have matching key string&lt;br /&gt;
&lt;br /&gt;
Step 3: The Phase 2 (SA/Key exchange) configuration.&lt;br /&gt;
&lt;br /&gt;
a) Choose ESP as protocol&lt;br /&gt;
b) Choose encryption algorithm(s)&lt;br /&gt;
c) Choose hash algorithm(s)&lt;br /&gt;
d) Choose PFS key group&lt;br /&gt;
e) Enter lifetime in seconds&lt;br /&gt;
f) Enter IP address of the remote host to ping so as to keep the connection alive (optional)&lt;br /&gt;
&lt;br /&gt;
KB article: &lt;a href=&quot;http://kb.mettle.in/entry/25/&quot;&gt;http://kb.mettle.in/entry/25/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
We would like to receive feedback regarding the content of this newsletter and&lt;br /&gt;
request for articles. Please send in your valuable suggestions to&lt;br /&gt;
&lt;a href=&quot;mailto:&amp;#109;&amp;#x65;&amp;#116;&amp;#x74;&amp;#x6C;&amp;#101;&amp;#x6E;&amp;#101;&amp;#x77;&amp;#x73;&amp;#x40;&amp;#109;&amp;#101;&amp;#116;&amp;#116;&amp;#x6C;&amp;#x65;&amp;#46;&amp;#x69;&amp;#110;&quot;&gt;&amp;#109;&amp;#x65;&amp;#116;&amp;#x74;&amp;#x6C;&amp;#101;&amp;#x6E;&amp;#101;&amp;#x77;&amp;#x73;&amp;#x40;&amp;#109;&amp;#101;&amp;#116;&amp;#116;&amp;#x6C;&amp;#x65;&amp;#46;&amp;#x69;&amp;#110;&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
Mettle and Linuxense are trademarks of Linuxense Information Systems Pvt. Ltd.&lt;br /&gt;
Other trademarks belong to respective owners. 2008 (C) Linuxense Information&lt;br /&gt;
Systems Pvt. Ltd. All rights reserved.&lt;/p&gt;
    	&lt;!-- begin subscription_form_widget.tmpl --&gt; 



 

    &lt;form action=&quot;http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi&quot; method=&quot;post&quot;&gt;

 

&lt;fieldset&gt;
&lt;legend&gt;
 Subscribe/Unsubscribe  on Mettle News
&lt;/legend&gt;

 
    

    &lt;input type=&quot;hidden&quot; name=&quot;list&quot; value=&quot;mettlenewsletter&quot; /&gt;


&lt;p&gt;
&lt;label for=&quot;email&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot; &gt;
Email&amp;nbsp;Address: 
&lt;/label&gt;
&lt;input type=&quot;text&quot; name=&quot;email&quot; id=&quot;email&quot; value=&quot;&quot; /&gt; &lt;span class=&quot;error&quot;&gt;* Required&lt;/span&gt;
&lt;/p&gt;

 

    &lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

     
    
        &lt;p&gt;
        &lt;label for=&quot;name&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
        Name: 
        &lt;/label&gt;
        &lt;input type=&quot;text&quot; name=&quot;name&quot; id=&quot;name&quot; value=&quot;&quot;  /&gt;
        &lt;/p&gt;
    
    
     

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

 
    &lt;p&gt;
    &lt;label for=&quot;f_s&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
    Subscribe
    &lt;/label&gt;
    &lt;input type=&quot;radio&quot; name=&quot;f&quot; id=&quot;f_s&quot; value=&quot;subscribe&quot; checked=&quot;checked&quot; /&gt;
    &lt;/p&gt; 
    
    &lt;p&gt; 
    &lt;label for=&quot;f_u&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;Unsubscribe&lt;/label&gt; 
    &lt;input type=&quot;radio&quot; name=&quot;f&quot;  id=&quot;f_u&quot;  value=&quot;unsubscribe&quot;  /&gt;
    &lt;/p&gt;   

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

&lt;p style=&quot;text-align:right;display:block&quot;&gt;
&lt;input type=&quot;submit&quot; value=&quot;Submit Your Information&quot; class=&quot;processing&quot; /&gt;
&lt;/p&gt; 


 

    &lt;p style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;&lt;a href=&quot;http://dadamailproject.com&quot; target=&quot;_blank&quot; style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;Powered by Dada Mail 3.0.0 Mailing List Manager&lt;/a&gt;&lt;/p&gt;

 




&lt;/fieldset&gt;
&lt;/form&gt; 



  
&lt;!-- end subscription_form_widget.tmpl --&gt; 
     
    </content>
  </entry>

 

  <entry>
    <title>Mettle News August, 2010
</title>
    <link rel="alternate" href="http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi/archive/mettlenewsletter/20100830131320/"/>
    <id>tag:newsletter.mettlenetworks.com,2010-08-30:%2Fcgi-bin%2Fmail.cgi%2Farchive%2Fmettlenewsletter%2F20100830131320%2F</id>
    
    <published>2010-08-30T13:13:20Z</published>
    <updated>2010-08-30T13:13:20Z</updated>
    <content type="html">&lt;p&gt;&lt;br /&gt;
&lt;br /&gt;
METTLE NEWS&lt;br /&gt;
[News letter on Mettle(tm) brand of products; Industry updates, Tips and Case studies]&lt;br /&gt;
&lt;br /&gt;
August 2010 &lt;br /&gt;
Volume 3, Issue 6&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In this issue: &lt;br /&gt;
&lt;br /&gt;
* Editorial &lt;br /&gt;
* IT Industry news: Google's Speedy&lt;br /&gt;
* Tip of the month: Backup &amp;#38; Restore Mettle SE Running Configuration&lt;br /&gt;
* Mettle SE feature: Event logging on Remote Sys log Server&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Editorial *&lt;br /&gt;
&lt;br /&gt;
Greetings,&lt;br /&gt;
&lt;br /&gt;
Most of the IT managers are keen on updating Internet link bandwidth to speed up browsing experience. But the situation is more complex now. Even if there is more than enough bandwidth, the page load often exceeds acceptable limit. The &amp;#34;Industry News&amp;#34; section talks about a presentation by Google in the Velocity conference on this subject.&lt;br /&gt;
&lt;br /&gt;
Mettle SE is designed to make you feel confident about your IT infrastructure besides performing its basic functions. This month's &amp;#34;Tip of the Month&amp;#34; describes how you can retain your most trusted configuration even if you play around with it or if you replace/upgrade your Mettle SE.&lt;br /&gt;
&lt;br /&gt;
Logs provides live information about what happens in the system. Mettle SE has a provision to connect a log server to it so that you can process the logs using third-party tools of your choice. This month's &amp;#34;Feature of the Month&amp;#34; explains this facility.&lt;br /&gt;
&lt;br /&gt;
With you a month ahead filled with technology and excitement.&lt;br /&gt;
&lt;br /&gt;
Editor, Mettle News&lt;br /&gt;
(&lt;a href=&quot;mailto:&amp;#x6D;&amp;#x65;&amp;#x74;&amp;#x74;&amp;#x6C;&amp;#x65;&amp;#x6E;&amp;#101;&amp;#119;&amp;#x73;&amp;#64;&amp;#x6D;&amp;#x65;&amp;#116;&amp;#116;&amp;#108;&amp;#101;&amp;#x2E;&amp;#x69;&amp;#110;&quot;&gt;&amp;#x6D;&amp;#x65;&amp;#x74;&amp;#x74;&amp;#x6C;&amp;#x65;&amp;#x6E;&amp;#101;&amp;#119;&amp;#x73;&amp;#64;&amp;#x6D;&amp;#x65;&amp;#116;&amp;#116;&amp;#108;&amp;#101;&amp;#x2E;&amp;#x69;&amp;#110;&lt;/a&gt;)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* IT Industry News: Speedy - Google's SPDY Protocol&lt;br /&gt;
&lt;br /&gt;
During the Velocity conference in Santa Clara, CA, Google's VP of Engineering Urs Holzle has warned that any improvement to the network bandwidth will be wasted unless the underlying protocols are updated. He said that even though the average network bandwidth will grow by a factor of three from 1.8Mbps to 5.4Mbps users will not be able to exploit the increase in bandwidth unless the underlying protocol is fixed.&lt;br /&gt;
&lt;br /&gt;
Internal tests conducted by Google has obtained the result that average website size is 320KB. So with average user bandwidth at 1.84Mbps, website load times should be around 1.4secs. But Google's tests have shown that real load times were close to 5secs. Holzle reckons this variation in theoretical to actual speeds is not due to the network bandwidth but due to the protocol and the browser.&lt;br /&gt;
&lt;br /&gt;
Holzle said in the conference that Google's goal is to achieve 100millisecond load times on the Google Chrome web browser and this will only be possible with the improvements to the Internet's underlying protocols. Chrome was one of the fastest web browsers when it arrived in 2008, the increased speed, in part, was contributed by the revamped JavaScript engine.&lt;br /&gt;
&lt;br /&gt;
Google boosted its image search engine speed by 18 percent by making some modest changes to the TCP protocol, but without making any changes to the site itself. Google believes that on an average 12 percent speed boost can be had with TCP tweaks. Holzle said the modest change which involved increasing TCP's initial congestion window involved changing about 10 lines of code.&lt;br /&gt;
&lt;br /&gt;
Pushing the speed envelope, Google is developing a new application protocol it calls SPDY (pronounced Speedy) meant to reduce web latency via multiplexed streams, request prioritisation and HTTP header compression. According to Holzle the new protocol can reduce packet count by 40pc and byte count by 15pc and an improvement in downloading speed of upto 55pc over simulated home connections. SPDY creates a session layer between HTTP application layer and TCP transport layer, it is not a HTTP replacement protocol but augments it. SPDY overrides parts of HTTP protocol such as connection management and data transfer formats. Holzle said that on low bandwidth links with SPDY's header compression alone has seen a latency reduction of 85pc.&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://arstechnica.com/web/news/2009/11/spdy-google-wants-to-speed-up-the-web-by-ditching-http.ars&quot;&gt;http://arstechnica.com/web/news/2009/11/spdy-google-wants-to-speed-up-the-web-by-ditching-http.ars&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Tip of the month: Backup &amp;#38; Restore Mettle SE Running Configuration *&lt;br /&gt;
&lt;br /&gt;
Backing up:&lt;br /&gt;
It is wise to backup the running configuration of Mettle SE after you have made changes to the system settings. Keeping backup of running configuration ready allows you to relax and be on the safe side if things go wrong. To take backup of your running configuration:&lt;br /&gt;
&lt;br /&gt;
- Go to Diagnostics --&amp;#62; Backup/Restore.&lt;br /&gt;
- It is recommended to keep the backup area as 'All'&lt;br /&gt;
- Click on 'Download configuration' button.&lt;br /&gt;
- The configuration file would be downloaded into your system and named in this format - config-&amp;#60;host name&amp;#62;-&amp;#60;timestamp&amp;#62;.xml&lt;br /&gt;
- Keep the configuration backup file safe.&lt;br /&gt;
&lt;br /&gt;
Restoring from backup:&lt;br /&gt;
You can restore Mettle SE to a running configuration as saved in the backup file from the same screen you did the backing up from. To restore to a saved configuration:&lt;br /&gt;
&lt;br /&gt;
- Select a restore area, usually 'All'&lt;br /&gt;
- Click 'Browse' and select the backup configuration file from your computer.&lt;br /&gt;
- Click on 'Restore configuration' button.&lt;br /&gt;
&lt;br /&gt;
Mettle SE would reboot once you have clicked on the 'Restore configuration' button and restored settings would be applied.&lt;br /&gt;
&lt;a href=&quot;http://kb.mettle.in/entry/53/&quot;&gt;http://kb.mettle.in/entry/53/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Mettle SE Feature: Event logging on Remote Sys log Server&lt;br /&gt;
&lt;br /&gt;
Factory setting of Mettle SE is set to store the log entries locally in the hard drive. But it is possible for you to enable remote logging in Mettle SE which will store the long entries remotely in a sys log server. Log entries in Mettle SE can only be of a specific size and as new log is generated old logs are deleted. If you have a sys log server, enabling remote logging is a good practice as it will aid with troubleshooting and long term monitoring and there is no limit to the log size except for your hard drive capacity.&lt;br /&gt;
&lt;br /&gt;
- To enable remote sys log logging go to:&lt;br /&gt;
- Status --&amp;#62; System Logs&lt;br /&gt;
- Go to the 'Settings' tab and tick on 'Enable sys log'ing to remote sys log server'&lt;br /&gt;
- To disable local logging you may tick on 'Disable writing log files to the local ram disk'. But this is neither required nor recommended.&lt;br /&gt;
- Enter the IP address of the remote sys log server in the text field.&lt;br /&gt;
- Next you have to select what all events are to be logged in the sys log server. Tick each category you want to have logged.&lt;br /&gt;
- Click on 'Save' once the settings are confirmed.&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://kb.mettle.in/entry/54/&quot;&gt;http://kb.mettle.in/entry/54/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
We would like to receive feedback regarding the content of this newsletter and&lt;br /&gt;
request for articles. Please send in your valuable suggestions to&lt;br /&gt;
&lt;a href=&quot;mailto:&amp;#x6D;&amp;#x65;&amp;#x74;&amp;#x74;&amp;#x6C;&amp;#x65;&amp;#x6E;&amp;#101;&amp;#119;&amp;#x73;&amp;#64;&amp;#x6D;&amp;#x65;&amp;#116;&amp;#116;&amp;#108;&amp;#101;&amp;#x2E;&amp;#x69;&amp;#110;&quot;&gt;&amp;#x6D;&amp;#x65;&amp;#x74;&amp;#x74;&amp;#x6C;&amp;#x65;&amp;#x6E;&amp;#101;&amp;#119;&amp;#x73;&amp;#64;&amp;#x6D;&amp;#x65;&amp;#116;&amp;#116;&amp;#108;&amp;#101;&amp;#x2E;&amp;#x69;&amp;#110;&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
Mettle and Linuxense are trademarks of Linuxense Information Systems Pvt. Ltd.&lt;br /&gt;
Other trademarks belong to respective owners. 2008 (C) Linuxense Information&lt;br /&gt;
Systems Pvt. Ltd. All rights reserved.&lt;/p&gt;
    	&lt;!-- begin subscription_form_widget.tmpl --&gt; 



 

    &lt;form action=&quot;http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi&quot; method=&quot;post&quot;&gt;

 

&lt;fieldset&gt;
&lt;legend&gt;
 Subscribe/Unsubscribe  on Mettle News
&lt;/legend&gt;

 
    

    &lt;input type=&quot;hidden&quot; name=&quot;list&quot; value=&quot;mettlenewsletter&quot; /&gt;


&lt;p&gt;
&lt;label for=&quot;email&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot; &gt;
Email&amp;nbsp;Address: 
&lt;/label&gt;
&lt;input type=&quot;text&quot; name=&quot;email&quot; id=&quot;email&quot; value=&quot;&quot; /&gt; &lt;span class=&quot;error&quot;&gt;* Required&lt;/span&gt;
&lt;/p&gt;

 

    &lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

     
    
        &lt;p&gt;
        &lt;label for=&quot;name&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
        Name: 
        &lt;/label&gt;
        &lt;input type=&quot;text&quot; name=&quot;name&quot; id=&quot;name&quot; value=&quot;&quot;  /&gt;
        &lt;/p&gt;
    
    
     

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

 
    &lt;p&gt;
    &lt;label for=&quot;f_s&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
    Subscribe
    &lt;/label&gt;
    &lt;input type=&quot;radio&quot; name=&quot;f&quot; id=&quot;f_s&quot; value=&quot;subscribe&quot; checked=&quot;checked&quot; /&gt;
    &lt;/p&gt; 
    
    &lt;p&gt; 
    &lt;label for=&quot;f_u&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;Unsubscribe&lt;/label&gt; 
    &lt;input type=&quot;radio&quot; name=&quot;f&quot;  id=&quot;f_u&quot;  value=&quot;unsubscribe&quot;  /&gt;
    &lt;/p&gt;   

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

&lt;p style=&quot;text-align:right;display:block&quot;&gt;
&lt;input type=&quot;submit&quot; value=&quot;Submit Your Information&quot; class=&quot;processing&quot; /&gt;
&lt;/p&gt; 


 

    &lt;p style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;&lt;a href=&quot;http://dadamailproject.com&quot; target=&quot;_blank&quot; style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;Powered by Dada Mail 3.0.0 Mailing List Manager&lt;/a&gt;&lt;/p&gt;

 




&lt;/fieldset&gt;
&lt;/form&gt; 



  
&lt;!-- end subscription_form_widget.tmpl --&gt; 
     
    </content>
  </entry>

 

  <entry>
    <title>Mettle News May, 2010</title>
    <link rel="alternate" href="http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi/archive/mettlenewsletter/20100531170045/"/>
    <id>tag:newsletter.mettlenetworks.com,2010-05-31:%2Fcgi-bin%2Fmail.cgi%2Farchive%2Fmettlenewsletter%2F20100531170045%2F</id>
    
    <published>2010-05-31T17:00:45Z</published>
    <updated>2010-05-31T17:00:45Z</updated>
    <content type="html">&lt;p&gt;&lt;br /&gt;
&lt;br /&gt;
METTLE NEWS&lt;br /&gt;
[News letter on Mettle(tm) brand of products; Industry updates, Tips and Case&lt;br /&gt;
studies]&lt;br /&gt;
&lt;br /&gt;
May 2010 &lt;br /&gt;
Volume 3, Issue 5 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In this issue: &lt;br /&gt;
&lt;br /&gt;
* Editorial &lt;br /&gt;
* IT Industry news: How fragile is the Internet?&lt;br /&gt;
* Tip of the month: Troubleshooting Firewall Rules&lt;br /&gt;
* Mettle SE feature: Firewall logs&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Editorial *&lt;br /&gt;
&lt;br /&gt;
Greetings!&lt;br /&gt;
&lt;br /&gt;
Networking has two faces: Enterprise networking and the Internet (as seen by ISPs and carriers). The Internet&lt;br /&gt;
side of networking is quite challenging and demands a lot of co-operation and trust among operators for it to&lt;br /&gt;
work. This month's Industry News provides an interesting but scary problem that prevails in the Internet.&lt;br /&gt;
&lt;br /&gt;
Many a time, every network administrator faces the problem is firewall rule verification-basically finding out&lt;br /&gt;
whether the rule written matches the packets. Mettle SE provides a mechanism for this. This saves time and&lt;br /&gt;
effort. Also let you know, positively, how good you are in writing firewall policies.&lt;br /&gt;
&lt;br /&gt;
This month's feature section, we explain you the firewall rules and how effectively you can use them them. &lt;br /&gt;
&lt;br /&gt;
Happy networking.&lt;br /&gt;
&lt;br /&gt;
Editor, Mettle News&lt;br /&gt;
(&lt;a href=&quot;mailto:&amp;#109;&amp;#101;&amp;#x74;&amp;#x74;&amp;#108;&amp;#x65;&amp;#x6E;&amp;#101;&amp;#119;&amp;#115;&amp;#x40;&amp;#109;&amp;#101;&amp;#116;&amp;#x74;&amp;#x6C;&amp;#101;&amp;#x2E;&amp;#x69;&amp;#x6E;&quot;&gt;&amp;#109;&amp;#101;&amp;#x74;&amp;#x74;&amp;#108;&amp;#x65;&amp;#x6E;&amp;#101;&amp;#119;&amp;#115;&amp;#x40;&amp;#109;&amp;#101;&amp;#116;&amp;#x74;&amp;#x6C;&amp;#101;&amp;#x2E;&amp;#x69;&amp;#x6E;&lt;/a&gt;)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* IT Industry news: How fragile is the Internet? * &lt;br /&gt;
&lt;br /&gt;
Brief Description: Unfixed routing glitch causing concern &lt;br /&gt;
&lt;br /&gt;
Story: &lt;br /&gt;
&lt;br /&gt;
In 1998 a hacker claimed that Internet could be brought down to its heels in 30minutes by exploiting a flaw&lt;br /&gt;
which caused online outages occasionally by misdirecting data. &lt;br /&gt;
&lt;br /&gt;
In 2010 the flaw still causes outages every year, although most of the outages are innocent and fixed quickly,&lt;br /&gt;
the problem still could be exploited by a hacker to spy on data traffic or take down websites. Reliance on the&lt;br /&gt;
Internet has only increased in all these years and an outage could disrupt businesses and governments which&lt;br /&gt;
require Internet to function normally. &lt;br /&gt;
&lt;br /&gt;
These outages are called &amp;#34;hijackings&amp;#34; and are caused by the haphazard way through which traffic is passed&lt;br /&gt;
between companies that carry Internet data. It is the Internet's open nature which has stimulated its dazzling&lt;br /&gt;
growth, and it is this same open nature which is contributing to the outage problem of the Internet. &lt;br /&gt;
&lt;br /&gt;
When an email is sent and a website is opened or done anything else online, the data you send and receive is&lt;br /&gt;
handed from one carrier of Internet  to another. The data might be handed from your ISP to a third party&lt;br /&gt;
company which operates a global network of fiber-optic lines that carry Internet data across long distances.&lt;br /&gt;
It, in turn, might pass the data to another carrier that's connected directly to the server computers the data&lt;br /&gt;
is intended for. &lt;br /&gt;
&lt;br /&gt;
The crux of the problem is that each carrier along the way figures out how to route the data based only on&lt;br /&gt;
what the surrounding carriers in the chain say, rather than by looking at the whole path. Because carriers&lt;br /&gt;
pass information between themselves about where data should go, and this system has no secure automatic&lt;br /&gt;
means of verifying the routing information is correct, data can be routed to some carrier that isn't&lt;br /&gt;
expecting the information. The carrier doesn't know what to do with it, and usually just drops it.&lt;br /&gt;
&lt;br /&gt;
On April 25, 1997, millions of people in North America lost access to all of the Internet for about an hour,&lt;br /&gt;
caused by an employee mis-programming a router at a small Internet service provider. That's what happens&lt;br /&gt;
when an Internet route gets hijacked. It falls into a &amp;#34;black hole.&amp;#34; Routing errors has previously blocked&lt;br /&gt;
Internet access in different parts of the world, at different times, often for millions of people.&lt;br /&gt;
 &lt;br /&gt;
Last month a Chinese Internet service provider halted access from around the world to a vast number of sites,&lt;br /&gt;
including Dell.com and CNN.com, for about 20 minutes.&lt;br /&gt;
&lt;br /&gt;
In 2008, Pakistan Telecom tried to comply with a government order to prevent access to YouTube from the&lt;br /&gt;
country and intentionally &amp;#34;black-holed&amp;#34; requests for YouTube videos from Pakistani Internet users. But it also&lt;br /&gt;
accidentally published the route international upstream carrier, the upstream carrier accepted the routing&lt;br /&gt;
message, and passed it along to other carriers across the world, which started sending all requests for&lt;br /&gt;
YouTube videos to Pakistan Telecom. Soon, even Internet users in the U.S. were denied YouTube access for a few&lt;br /&gt;
hours.&lt;br /&gt;
&lt;br /&gt;
In 2004, the flaw was put to malicious use when someone got a computer in Malaysia to tell Internet service&lt;br /&gt;
providers that it was part of Yahoo Inc. A flood of spam was sent out, appearing to come from Yahoo.&lt;br /&gt;
&lt;br /&gt;
In 2003, the Bush administration's Critical Infrastructure Protection Board assembled a &amp;#34;National Strategy to&lt;br /&gt;
Secure Cyberspace&amp;#34; that concluded that it was vital to fix the routing system and make sure route always point&lt;br /&gt;
in the right direction.&lt;br /&gt;
&lt;br /&gt;
Unlike other Internet bugs that get discovered and fixed relatively quickly, the routing system has been&lt;br /&gt;
unreformed for more than a decade. There is some progress being made but there's little industry-wide momentum&lt;br /&gt;
behind efforts to introduce a permanent remedy. Data carriers regard the fallibility of the routing system as&lt;br /&gt;
the price to be paid for the Internet's open, flexible structure. The simplicity of the routing system makes&lt;br /&gt;
it easy for service providers to connect, a quality that has probably helped the explosive growth of the&lt;br /&gt;
Internet.&lt;br /&gt;
&lt;br /&gt;
Peiter Zatko, a member of the &amp;#34;hacker think tank&amp;#34; called the L0pht, told Congress in 1998 that he could use&lt;br /&gt;
the BGP vulnerability to bring down the Internet in half an hour. In recent years, Zatko, who now works for&lt;br /&gt;
the Pentagon's DARPA, has said the exploit would still work. However he added, it would likely take a few&lt;br /&gt;
hours rather than 30 minutes, partly because a greater number of Internet carriers would need to be hit.&lt;br /&gt;
&lt;br /&gt;
Plenty of solutions have been proposed in the Internet engineering community since 1995. The U.S. government&lt;br /&gt;
has supported these efforts, spurred in part by the Bush administration's 2003 strategy statement. It has&lt;br /&gt;
resulted in some trials of new technology, but adoption by data carriers still appears distant. And the&lt;br /&gt;
federal government doesn't have any direct authority to force changes.&lt;br /&gt;
&lt;br /&gt;
One solution being tested would stop short of making the routing system fully secure but would at least verify&lt;br /&gt;
part of it. Yet this system also worries carriers because they would have to work through a central database.&lt;br /&gt;
&lt;br /&gt;
Weakness in the system are in the routing between carriers. It doesn't help if one carrier introduces a new&lt;br /&gt;
system, every one it connects with has to make the change as well.&lt;br /&gt;
&lt;br /&gt;
As Doug Maughan of the US Homeland Security puts it, &amp;#34;It's kind of everybody's problem, because it impacts the&lt;br /&gt;
stability of the Internet, but at the same time it's nobody's problem because nobody owns it&amp;#34;.&lt;br /&gt;
&lt;br /&gt;
Meanwhile, network administrators deal with hijacking an old-fashioned way: calling their counterparts close&lt;br /&gt;
to where the hijacking is happening to get them to manually change data routes. Let us hope that researchers&lt;br /&gt;
will come up with something robust and practical to keep the Internet secure soon.&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://detnews.com/article/20100508/BIZ04/5080399/Unfixed-Internet-glitch-could-strand-users-offline&quot;&gt;http://detnews.com/article/20100508/BIZ04/5080399/Unfixed-Internet-glitch-could-strand-users-offline&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Tip of the month: Troubleshooting Firewall Rules * &lt;br /&gt;
&lt;br /&gt;
This month we will help you troubleshoot your firewall rules if they are not behaving as you expect it to. &lt;br /&gt;
&lt;br /&gt;
Check firewall logs:- First step to take while debugging suspected blocked traffic is to check the firewall&lt;br /&gt;
logs.  With factory setting Mettle SE logs all dropped traffic and will not log passed traffic. If there is no&lt;br /&gt;
traffic with a red X next to it in your firewall logs, Mettle SE is not dropping the traffic.&lt;br /&gt;
(Firewall logs explained in &amp;#34;Feature of the month&amp;#34;section). &lt;br /&gt;
&lt;br /&gt;
Review rule parameters:- Edit the suspected rule and review the parameters you have specified for each field.&lt;br /&gt;
For TCP and UDP traffic the source and destination ports are almost never the same and should be set to any.&lt;br /&gt;
If the default deny rule is the cause of problem, you have to create a new pass rule that will match the&lt;br /&gt;
traffic that is to be allowed. &lt;br /&gt;
&lt;br /&gt;
Review rule order:- First matching rule for a case wins. No further rules are evaluated. &lt;br /&gt;
&lt;br /&gt;
Rules and interfaces:- Make sure the rules are assigned on the correct interface. Traffic is filtered only by&lt;br /&gt;
the rule set configured on the interface where traffic is initiated. &lt;br /&gt;
&lt;br /&gt;
Enable rule logging: By enabling logging on your pass rules, you can view firewall logs and click on an entry&lt;br /&gt;
to determine which rule passed the traffic. This can be helpful to determine which rule is matching the&lt;br /&gt;
traffic in question. &lt;br /&gt;
&lt;br /&gt;
Packet captures:- This is a mighty good tool for troubleshooting and debugging firewall and traffic issues.&lt;br /&gt;
With packet capture you can tell if the traffic is reaching the outside interface or leaving the inside&lt;br /&gt;
interface and among many other uses. &lt;br /&gt;
&lt;br /&gt;
How to use packet capture:- &lt;a href=&quot;http://kb.mettle.in/entry/43/&quot;&gt;http://kb.mettle.in/entry/43/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Mettle SE feature: Firewall logs * &lt;br /&gt;
&lt;br /&gt;
A firewall log entry is made for each rule that is set to log and for the default deny rule. To view the&lt;br /&gt;
parsed logs you have to go to Status -&amp;#62; System Logs on the Firewall tab. &lt;br /&gt;
&lt;br /&gt;
Parsed logs are displayed in 6 columns: Action - Time - Interface - Source - Destination - Protocol. Action&lt;br /&gt;
tells what happened to the packet which generated the log entry - its either Pass, Block, or Reject. Time&lt;br /&gt;
tells the time when the packet has arrived. Interface is the interface through which the packet entered&lt;br /&gt;
Mettle SE. Source is the source IP address and the port the packet originated from, Destination is the&lt;br /&gt;
destination IP address and port of the packet. Protocol is the protocol of the packet. &lt;br /&gt;
&lt;br /&gt;
The 'Action' icon displayed in the logs is a link, clicking it will lookup and display the rule which caused&lt;br /&gt;
the log entry. &lt;br /&gt;
&lt;br /&gt;
If the Protocol is TCP, you will see extra fields that represent TCP flags present in the packet. These flags&lt;br /&gt;
indicate various connection states or packet attributes, some common flags are: &lt;br /&gt;
 &lt;br /&gt;
S (Syn) - Synchronise sequence numbers. Indicates a new connection attempt when only SYN is set. &lt;br /&gt;
A (Ack) - Acknowledgement to the data received. &lt;br /&gt;
F (Fin) - Indicates there is no more data from the sender, connection closing. &lt;br /&gt;
R (Rst) - Connection reset &lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://kb.mettle.in/entry/52/&quot;&gt;http://kb.mettle.in/entry/52/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
We would like to receive feedback regarding the content of this newsletter and&lt;br /&gt;
request for articles. Please send in your valuable suggestions to&lt;br /&gt;
&lt;a href=&quot;mailto:&amp;#109;&amp;#101;&amp;#x74;&amp;#x74;&amp;#108;&amp;#x65;&amp;#x6E;&amp;#101;&amp;#119;&amp;#115;&amp;#x40;&amp;#109;&amp;#101;&amp;#116;&amp;#x74;&amp;#x6C;&amp;#101;&amp;#x2E;&amp;#x69;&amp;#x6E;&quot;&gt;&amp;#109;&amp;#101;&amp;#x74;&amp;#x74;&amp;#108;&amp;#x65;&amp;#x6E;&amp;#101;&amp;#119;&amp;#115;&amp;#x40;&amp;#109;&amp;#101;&amp;#116;&amp;#x74;&amp;#x6C;&amp;#101;&amp;#x2E;&amp;#x69;&amp;#x6E;&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
Mettle and Linuxense are trademarks of Linuxense Information Systems Pvt. Ltd.&lt;br /&gt;
Other trademarks belong to respective owners. 2008 (C) Linuxense Information&lt;br /&gt;
Systems Pvt. Ltd. All rights reserved.&lt;/p&gt;
    	&lt;!-- begin subscription_form_widget.tmpl --&gt; 



 

    &lt;form action=&quot;http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi&quot; method=&quot;post&quot;&gt;

 

&lt;fieldset&gt;
&lt;legend&gt;
 Subscribe/Unsubscribe  on Mettle News
&lt;/legend&gt;

 
    

    &lt;input type=&quot;hidden&quot; name=&quot;list&quot; value=&quot;mettlenewsletter&quot; /&gt;


&lt;p&gt;
&lt;label for=&quot;email&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot; &gt;
Email&amp;nbsp;Address: 
&lt;/label&gt;
&lt;input type=&quot;text&quot; name=&quot;email&quot; id=&quot;email&quot; value=&quot;&quot; /&gt; &lt;span class=&quot;error&quot;&gt;* Required&lt;/span&gt;
&lt;/p&gt;

 

    &lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

     
    
        &lt;p&gt;
        &lt;label for=&quot;name&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
        Name: 
        &lt;/label&gt;
        &lt;input type=&quot;text&quot; name=&quot;name&quot; id=&quot;name&quot; value=&quot;&quot;  /&gt;
        &lt;/p&gt;
    
    
     

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

 
    &lt;p&gt;
    &lt;label for=&quot;f_s&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
    Subscribe
    &lt;/label&gt;
    &lt;input type=&quot;radio&quot; name=&quot;f&quot; id=&quot;f_s&quot; value=&quot;subscribe&quot; checked=&quot;checked&quot; /&gt;
    &lt;/p&gt; 
    
    &lt;p&gt; 
    &lt;label for=&quot;f_u&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;Unsubscribe&lt;/label&gt; 
    &lt;input type=&quot;radio&quot; name=&quot;f&quot;  id=&quot;f_u&quot;  value=&quot;unsubscribe&quot;  /&gt;
    &lt;/p&gt;   

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

&lt;p style=&quot;text-align:right;display:block&quot;&gt;
&lt;input type=&quot;submit&quot; value=&quot;Submit Your Information&quot; class=&quot;processing&quot; /&gt;
&lt;/p&gt; 


 

    &lt;p style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;&lt;a href=&quot;http://dadamailproject.com&quot; target=&quot;_blank&quot; style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;Powered by Dada Mail 3.0.0 Mailing List Manager&lt;/a&gt;&lt;/p&gt;

 




&lt;/fieldset&gt;
&lt;/form&gt; 



  
&lt;!-- end subscription_form_widget.tmpl --&gt; 
     
    </content>
  </entry>

 

  <entry>
    <title>Mettle News April, 2010</title>
    <link rel="alternate" href="http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi/archive/mettlenewsletter/20100430170805/"/>
    <id>tag:newsletter.mettlenetworks.com,2010-04-30:%2Fcgi-bin%2Fmail.cgi%2Farchive%2Fmettlenewsletter%2F20100430170805%2F</id>
    
    <published>2010-04-30T17:08:05Z</published>
    <updated>2010-04-30T17:08:05Z</updated>
    <content type="html">&lt;p&gt;&lt;br /&gt;
&lt;br /&gt;
METTLE NEWS&lt;br /&gt;
[News letter on Mettle(tm) brand of products; Industry updates, Tips and Case&lt;br /&gt;
studies]&lt;br /&gt;
&lt;br /&gt;
April 2010 &lt;br /&gt;
Volume 3, Issue 4 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In this issue: &lt;br /&gt;
* Editorial &lt;br /&gt;
* IT Industry news: Accidentally Importing Foreign Censorship Policy &lt;br /&gt;
* Tip of the month: Firewall Rule Best Practices &lt;br /&gt;
* Mettle SE feature: Server Load Balancing &lt;br /&gt;
* Case Study: Mettle SE at a Research and Education Institute in Kerala&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Editorial *&lt;br /&gt;
&lt;br /&gt;
Greetings,&lt;br /&gt;
&lt;br /&gt;
This month passes with yet another episode of wrong BGP advertisement hogging the Internet. This occurred in&lt;br /&gt;
China this time. Result: China's censorship was enforced outside their country. Read the full story in the&lt;br /&gt;
Industry News section. &lt;br /&gt;
&lt;br /&gt;
A badly maintained system is prone to go wrong and will turn into a maintenance nightmare. Firewall is no&lt;br /&gt;
exception. This month's Tip of the Month section describes how the firewall configuration in Mettle SE can be&lt;br /&gt;
kept neat and tidy. It is nothing but a set of conventions that can be followed easily.&lt;br /&gt;
&lt;br /&gt;
Redundancy is what we think when it comes to high availability. It is easier said than done when it comes to&lt;br /&gt;
setting up redundant servers or services and putting them into use effectively. This requires additional&lt;br /&gt;
infrastructure components to direct traffic and check out availability etc. Mettle SE supports this and this&lt;br /&gt;
feature is part of standard firmware. Read about this in this month's Mettle SE Feature column.&lt;br /&gt;
&lt;br /&gt;
This month's case study explains how Mettle SE enabled a premier research institute to implement a secure IT&lt;br /&gt;
infrastructure and policy enforcement in their campus.&lt;br /&gt;
&lt;br /&gt;
Happy networking!&lt;br /&gt;
&lt;br /&gt;
Editor, Mettle News&lt;br /&gt;
(&lt;a href=&quot;mailto:&amp;#109;&amp;#x65;&amp;#116;&amp;#x74;&amp;#x6C;&amp;#x65;&amp;#110;&amp;#x65;&amp;#119;&amp;#115;&amp;#x40;&amp;#109;&amp;#x65;&amp;#116;&amp;#116;&amp;#108;&amp;#101;&amp;#x2E;&amp;#x69;&amp;#110;&quot;&gt;&amp;#109;&amp;#x65;&amp;#116;&amp;#x74;&amp;#x6C;&amp;#x65;&amp;#110;&amp;#x65;&amp;#119;&amp;#115;&amp;#x40;&amp;#109;&amp;#x65;&amp;#116;&amp;#116;&amp;#108;&amp;#101;&amp;#x2E;&amp;#x69;&amp;#110;&lt;/a&gt;)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* IT Industry News: Accidentally Importing Foreign Censorship Policy * &lt;br /&gt;
&lt;br /&gt;
You're browsing the Internet from a place with no Internet censorship, but one fine day the websites you used&lt;br /&gt;
to visit have become unavailable or you're presented with restricted user access. You may not have realised,&lt;br /&gt;
but your computer must have come under the Internet censorship policy of another country! Sounds strange?&lt;br /&gt;
Read on! &lt;br /&gt;
&lt;br /&gt;
With advancing technology, sophisticated filtering technologies are increasingly being applied to restrict&lt;br /&gt;
access to the Internet. Internet filtering is done by corporations and by some governments. Given the open&lt;br /&gt;
nature of the Internet, one country's restrictions, if not handled very carefully, can foul global Internet&lt;br /&gt;
access. This article is about one such incident, Internet filtering done in China affecting other parts of the&lt;br /&gt;
world and going undetected for 3 weeks. Given the increasing complexity and efficiency of this technology, and&lt;br /&gt;
the difficulty in controlling a very open Internet, and the desire of some to do just that could be a&lt;br /&gt;
harbinger of things to come. &lt;br /&gt;
&lt;br /&gt;
To understand this, one needs a bit of Internet routing know how, the behaviour of DNS and the root name&lt;br /&gt;
servers, and the economics of Internet routing. &lt;br /&gt;
&lt;br /&gt;
When you type www.facebook.com into your browser, your computer first contacts a DNS server to convert this&lt;br /&gt;
name into an IP address in order to contact the host serving this content. Answers to DNS requests are cached&lt;br /&gt;
on both your machine and the servers involved to save time and to reduce the load of subsequent identical&lt;br /&gt;
queries. Now suppose that the caches on your computer and your DNS server are both empty and you make the&lt;br /&gt;
above query. Your DNS server first contacts a Root name server with your request. If configured according to&lt;br /&gt;
convention, the Root name server will not provide the answer to your query by itself, instead directs your DNS&lt;br /&gt;
server to the .com Name servers. In turn, .com name servers will direct your DNS server to the Facebook.com's&lt;br /&gt;
name server, which will ultimately provide IP address to of Facebook's web servers. &lt;br /&gt;
&lt;br /&gt;
Now suppose corporate Z runs a root name server and Z wants to restrict Facebook access. Nothing requires Z to&lt;br /&gt;
direct you to the .com name servers as in the chain of resolution described above. Since Z sees your complete&lt;br /&gt;
request, it could just answer it directly. If Z gave you the wrong answer, it would effectively block your&lt;br /&gt;
access to Facebook. Since Internet runs on trust, you'll also end up caching Z's invalid response (called&lt;br /&gt;
&amp;#147;cache poisoning&amp;#148;) and with Z being the one who tells you how long to cache the result. Or Z could actually&lt;br /&gt;
provide the correct answer, but a firewall in front of Z could alter the DNS query response on its way back&lt;br /&gt;
to you. &lt;br /&gt;
 &lt;br /&gt;
Incident Details&lt;br /&gt;
&lt;br /&gt;
This scenario might seem very unlikely but it in fact just happened with the I-Root instance that runs out of&lt;br /&gt;
China. The problem existed from March 3rd until March 25th, before it was reported and corrected. Despite the&lt;br /&gt;
fact that a lot of people could have been impacted, the chances of any one of them having gotten the incorrect&lt;br /&gt;
DNS response are extremely remote. Thanks again to the way DNS operates and the overall resiliency of the&lt;br /&gt;
Internet. &lt;br /&gt;
&lt;br /&gt;
China censors the Internet in a variety of ways, one way is to return invalid answers to DNS requests to&lt;br /&gt;
Chinese users. For example, a Chinese DNS server is returning 46.82.174.68 as an IP address for&lt;br /&gt;
www.facebook.com, when in fact all legitimate Facebook IPs are of the form 66.220.x.y or 69.63.x.y. Such&lt;br /&gt;
seemingly random IPs are also returned for www.twitter.com, www.youtube.com and many other domains. This is&lt;br /&gt;
normal and expected behavior inside China.&lt;br /&gt;
&lt;br /&gt;
However, China hosts an instance of a Root name server, the I-Root, when this server became visible outside of&lt;br /&gt;
China on March 3rd, anyone who happened to query it could have got bogus responses. There are thirteen&lt;br /&gt;
different root name server IP addresses and the I-root is just one of these, namely 192.36.148.17. In&lt;br /&gt;
addition, there are dozens of instances of the I-Root housed in many locations around the world. To get a&lt;br /&gt;
bogus DNS response outside of China, you not only had to query the I-Root but you had to query the Chinese&lt;br /&gt;
version of it. Not surprisingly, the most exposed countries were all in Asia, but some prefixes in the US were&lt;br /&gt;
also vulnerable, more than half of which geo-locate to California. &lt;br /&gt;
&lt;br /&gt;
Let us review the unlikely series of events that would have been required to observe a bogus answer to&lt;br /&gt;
www.facebook.com.&lt;br /&gt;
&lt;br /&gt;
1. You attempt to go to www.facebook.com. &lt;br /&gt;
2. You don't have this entry in your DNS cache, nor does your DNS server. &lt;br /&gt;
3. Your DNS server does not have the .com servers cached either. &lt;br /&gt;
4. Your DNS server happens to choose the I-root (as opposed to A-root, B-root, C-root,... M-root etc). &lt;br /&gt;
5. Due to current Internet routing in place at your location, your DNS server happens to be directed to&lt;br /&gt;
China's instance.&lt;br /&gt;
&lt;br /&gt;
Since Facebook is blocked in China, your DNS server does not get the expected list of .com servers, but rather&lt;br /&gt;
a bogus response to your original request, either from the I-root itself or a firewall in between.&lt;br /&gt;
&lt;br /&gt;
You don't have any control over which I-root instance you see from your location. That is determined by&lt;br /&gt;
Internet routing. Many of the root name servers are &amp;#147;anycast&amp;#148; from multiple locations around the world. This&lt;br /&gt;
means that the associated IP prefixes are announced from multiple locations, all of which house servers with&lt;br /&gt;
copies of the appropriate data. BGP, the Internet routing protocol, is then used to sort out who sees which&lt;br /&gt;
instance of the root servers from which locations. In general, the Chinese I-root instance is supposedly only&lt;br /&gt;
visible from within China, but for 3 weeks these routes leaked out to the global Internet which created this&lt;br /&gt;
issue. This announcement leaked out of China when it was leaked by China Network Information Center. &lt;br /&gt;
&lt;br /&gt;
Internet routing is driven more by economics than by physical distance, although the two are often related.&lt;br /&gt;
For example, two smaller Internet service providers X and Y, agree to exchange traffic with each other for&lt;br /&gt;
free. This common arrangement on the Internet is known as peering and allows X and Y to save money in transit&lt;br /&gt;
costs to larger ISPs. Suppose further that X (or one of its customers) is running the I-root. If Y needs to&lt;br /&gt;
get to the I-root it should pick its peering link with X, rather than its link to a larger carrier for whom&lt;br /&gt;
they have to pay. China Telecom, the largest carrier in China, peers with nearly 100 other ISPs. If those ISPs&lt;br /&gt;
or their customers aren't running an instance of the I-root themselves, they might use their peering link to&lt;br /&gt;
China Telecom to reach their instance. This is how countries far from China could end up selecting the Chinese&lt;br /&gt;
I-root as the &amp;#34;best&amp;#34; of many possibilities. &lt;br /&gt;
&lt;br /&gt;
Conclusions&lt;br /&gt;
&lt;br /&gt;
The article illustrates both the fragility and the resiliency of the Internet. Its fragile because it is&lt;br /&gt;
ultimately trust-based and almost anyone can violate that trust, deliberately or by accident. Its resilient&lt;br /&gt;
because there are often many alternatives or workarounds for any sabotage or attempts to control it.&lt;br /&gt;
&lt;br /&gt;
Reference: Renesys blog: &lt;a href=&quot;http://www.renesys.com/blog/2010/03/fouling-the-global-nest.shtml&quot;&gt;http://www.renesys.com/blog/2010/03/fouling-the-global-nest.shtml&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Tip of the month: Firewall Rule Best Practices * &lt;br /&gt;
&lt;br /&gt;
Below are general best practice tips to consider when configuring firewall rules. Following best practices&lt;br /&gt;
tips will help you to create a secure and robust computer network and easy trouble shooting. &lt;br /&gt;
&lt;br /&gt;
1) Default deny: Two philosophies in computer security related access control are default allow and default&lt;br /&gt;
deny. Best practice is to have the default deny strategy. Configure your rules to permit only the bare minimum&lt;br /&gt;
required traffic for your networking needs, and let the rest drop with Mettle SE's built in default deny rule. &lt;br /&gt;
&lt;br /&gt;
2) Keep it short: The shorter the rule set, the easier it is to manage. Long rule sets are difficult to work&lt;br /&gt;
with, increase human error, tend to become overly permissive and significantly more difficult to audit.&lt;br /&gt;
Utilise 'Aliases' to help keep your rule set as short as possible. &lt;br /&gt;
&lt;br /&gt;
3) Review your rules: You should manually review your firewall rules and NAT configuration on a periodic basis&lt;br /&gt;
to ensure they still match minimum requirements of your current network environment. The recommended frequency&lt;br /&gt;
of such review will vary from one scenario to another. In networks that do not change frequently with a small&lt;br /&gt;
number of network administrators and good change control procedures, quarterly or semi-annually is usually&lt;br /&gt;
adequate. For fast changing environments or those with poor change control and several network administrators,&lt;br /&gt;
the configuration should be reviewed at least on a monthly basis. &lt;br /&gt;
&lt;br /&gt;
4) Document your configuration: Use of the 'description' field in firewall and NAT rules is always recommended&lt;br /&gt;
to document the purpose of each rule. In larger or more complex deployments, you should also maintain a more&lt;br /&gt;
detailed configuration document describing your entire Mettle SE configuration. When reviewing your&lt;br /&gt;
configuration in the future this should help you determine which rules are necessary and why they are there. &lt;br /&gt;
&lt;br /&gt;
5) Reducing log noise: Logging is enabled on the default deny rule in Mettle SE by default. This means all the&lt;br /&gt;
noise getting blocked from the Internet is going to get logged. Sometimes you won't see much noise, but in&lt;br /&gt;
many environments you will find something incessantly spamming your logs. Sometimes spamming cover up logs&lt;br /&gt;
that are important, and its a good idea to add a block rule on the WAN interface for repeated noise traffic.&lt;br /&gt;
By adding a block rule without logging enabled on the WAN interface, the traffic will still be blocked, but no&lt;br /&gt;
longer fill your logs. &lt;br /&gt;
&lt;br /&gt;
6) Logging Practices: By default Mettle SE does not log any passed traffic and logs all dropped traffic. This&lt;br /&gt;
is a practical setting as logging all passed traffic should rarely be done due to log levels generated. There&lt;br /&gt;
is a catch in this, blocked traffic cannot harm the network, but traffic that gets passed could be very&lt;br /&gt;
important log information to have if a system is compromised. After eliminating useless block noise as&lt;br /&gt;
described in the previous section, the remainder is of some value for pattern analysis purpose. If you are&lt;br /&gt;
seeing a significantly more or less log volume than usual, its probably good to investigate why. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Mettle SE Feature: Server Load Balancing * &lt;br /&gt;
&lt;br /&gt;
Server load balancing allows you to distribute traffic between multiple internal servers. It is commonly used&lt;br /&gt;
with web servers and SMTP servers though it can be used for any service that uses TCP. &lt;br /&gt;
&lt;br /&gt;
There are two portions of configuration for the server load balancer. Virtual server pools define the list of&lt;br /&gt;
servers to be used, which port they listen on, and monitoring method to be used. Virtual servers define the IP&lt;br /&gt;
address and port to listen on, and the appropriate pool to direct the incoming traffic to that IP address and&lt;br /&gt;
port. &lt;br /&gt;
&lt;br /&gt;
To configure Virtual server pools: &lt;br /&gt;
&lt;br /&gt;
1) Go to: Services --&amp;#62; Load Balancer --&amp;#62; Click + button to add a new pool. &lt;br /&gt;
2) Name --&amp;#62; Enter a name for the pool here. The name is referenced later when configuring virtual server. &lt;br /&gt;
3) Description --&amp;#62; You may enter an optional description here/ &lt;br /&gt;
4) Type --&amp;#62; Select 'Server' &lt;br /&gt;
5) Behaviour --&amp;#62; Select 'Load Balancing' &lt;br /&gt;
6) Port --&amp;#62; This is the port your servers are listening on internally. This can be different from the external&lt;br /&gt;
port. &lt;br /&gt;
7) Monitor --&amp;#62; Defines the type of monitoring to use. Selecting 'TCP' will make the balancer connect to the&lt;br /&gt;
port defined above, if it cannot connect, server is considered down. Choosing 'ICMP' will monitor the defined&lt;br /&gt;
servers by pinging them, and will be marked down if there is no ping response. &lt;br /&gt;
8) Monitor IP --&amp;#62; Not applicable with server load balancing &lt;br /&gt;
9) Server IP Address --&amp;#62; Fill in the IP address of the servers in the pool. &lt;br /&gt;
10) List --&amp;#62; Shows the list of servers you have added to this pool. You can remove a server from the pool by&lt;br /&gt;
clicking on its IP address and clicking remove from pool. &lt;br /&gt;
11) Click on 'Save' and proceed to configure virtual servers. &lt;br /&gt;
&lt;br /&gt;
To Configure virtual servers: &lt;br /&gt;
&lt;br /&gt;
1) Name --&amp;#62; Enter a name for the virtual server here, this is not parsed. &lt;br /&gt;
2) Description --&amp;#62; You may enter a long description here, its not parsed. &lt;br /&gt;
3) IP Address --&amp;#62; Enter the IP address that the virtual server will listen on. This is usually your WAN IP or&lt;br /&gt;
a Virtual IP on WAN interface. &lt;br /&gt;
4) Port --&amp;#62; This is the port the virtual server will listen on. It can be different from the port on your&lt;br /&gt;
servers are listening internally. &lt;br /&gt;
5) Virtual Server Pool --&amp;#62; Select the previously configured pool from the list. &lt;br /&gt;
&lt;br /&gt;
After configuring server pool and servers, you should create a firewall rule to allow the traffic to the&lt;br /&gt;
servers and the ports they are listening on. Please refer to our KB article for detailed information. &lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://kb.mettle.in/entry/51/&quot;&gt;http://kb.mettle.in/entry/51/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Case Study: Mettle SE at a Research and Education Institute in Kerala * &lt;br /&gt;
&lt;br /&gt;
Vertical: Education/Campus &lt;br /&gt;
Geography: Trivandrum, Kerala &lt;br /&gt;
&lt;br /&gt;
Client Profile: &lt;br /&gt;
&lt;br /&gt;
This client is an autonomous research institute, established in 1971, with an objective to promote research,&lt;br /&gt;
teaching and training in disciplines relevant to development. The institute is considered to be one of the&lt;br /&gt;
foremost development economics research centers in the country. The core activities of the institute are&lt;br /&gt;
research, teaching and training. They conduct programmes affiliated to Jawaharlal Nehru University. Institute&lt;br /&gt;
has gained recognition from the University of Kerala as a center for its doctoral studies. Institute is&lt;br /&gt;
supported financially by the Government of Kerala and Indian Council of Social Science and Research. &lt;br /&gt;
&lt;br /&gt;
Problems: &lt;br /&gt;
&lt;br /&gt;
Institute is served by a single high bandwidth WAN link. LAN networks is not secured from Virus attacks from&lt;br /&gt;
the Internet as they don't have a gateway antivirus installed in their network. Secure WiFi service was to be&lt;br /&gt;
made available in the campus. Content Filtering is to be implemented to filter out unacceptable Internet&lt;br /&gt;
content and services as a part of the acceptable usage policy laid down by the management. Internet access log&lt;br /&gt;
needs to be maintained for the campus. They have servers deployed in their local area network which has to be&lt;br /&gt;
made available to authorised users on the Internet. Few users need access to the campus servers remotely.&lt;br /&gt;
&lt;br /&gt;
Solution: &lt;br /&gt;
&lt;br /&gt;
Mettle SE was deployed at the campus to handle their IT infrastructure needs. Solutions provided by Mettle SE&lt;br /&gt;
can be grouped into the following sections: &lt;br /&gt;
&lt;br /&gt;
a) ISP Link Termination and Gateway Antivirus &lt;br /&gt;
b) Firewall and DMZ &lt;br /&gt;
c) NAT and PAT &lt;br /&gt;
d) VPN with RADIUS Server &lt;br /&gt;
e) Proxy Server and Content Scanning &lt;br /&gt;
&lt;br /&gt;
a) ISP Link Termination and Gateway Antivirus &lt;br /&gt;
&lt;br /&gt;
The Institute is served by a single ISP providing a high bandwidth link. Mettle SE is the terminating point&lt;br /&gt;
for the ISP link at the campus. Mettle SE is the gateway for all the computers and server on the campus&lt;br /&gt;
network. Mettle SE protects the LAN subnets and computers in the network from viruses, worms, trojans and&lt;br /&gt;
other malicious codes and threats from the Internet. Mettle SE updates its internal virus signature database&lt;br /&gt;
automatically over the Internet to provide maximum security for the campus network. &lt;br /&gt;
&lt;br /&gt;
b) Firewall and DMZ &lt;br /&gt;
&lt;br /&gt;
To provide optimum security to the computers in the campus, Mettle SE implements a security barricade. Campus&lt;br /&gt;
users are served by the campus LAN and WiFi subnets. Mettle SE Firewalls the LAN and WiFi subnets thus keeping&lt;br /&gt;
the computers connected to the Internet via Mettle SE safe and secured. &lt;br /&gt;
&lt;br /&gt;
A DMZ also has been setup where their public access servers are kept. The purpose of a DMZ is to add an&lt;br /&gt;
additional layer of security to the institute's LAN, an external attacker only has access to hosts in the DMZ,&lt;br /&gt;
rather than the whole of the network. The publicly accessible servers are hosted in the DMZ. This setup allows&lt;br /&gt;
servers in the DMZ to service both internal and external network, while keeping the LAN safe from possible&lt;br /&gt;
threats from the Internet. IP traffic between LAN and DMZ is monitored by Mettle SE, thus keeping out suspect&lt;br /&gt;
and unauthorised traffic out of the LAN. In the unlikely situation that security of DMZ is breached, Mettle SE&lt;br /&gt;
would keep the LAN and critical machines secured. &lt;br /&gt;
&lt;br /&gt;
c) NAT and PAT &lt;br /&gt;
&lt;br /&gt;
Mettle SE provides Internet connectivity for Desktops, Laptops and Servers hosted in the corporate network.&lt;br /&gt;
Mettle SE is configured as the gateway for the computers on the LAN subnets. Manual Network Address&lt;br /&gt;
Translation (NAT) is enabled in Mettle SE to provide Internet connectivity to computers which require direct&lt;br /&gt;
access to the Internet. Content Scanning is skipped for such computers which connect to the Internet via NAT.&lt;br /&gt;
Mettle SE is set as the proxy server for other computers, for which Internet connection needs to be monitored&lt;br /&gt;
and controlled. &lt;br /&gt;
&lt;br /&gt;
Port forwarding (PAT) is enabled in Mettle SE to allow an authorised user, to connect to a specific computer&lt;br /&gt;
in the LAN, over the Internet. Port forwarding transfers IP packets between the private IP addresses of the&lt;br /&gt;
computer on a particular port and a public IP address with a specific port. This ensures that a service in the&lt;br /&gt;
host computer can be accessed from the Internet but is secured. &lt;br /&gt;
&lt;br /&gt;
d) VPN with RADIUS Server &lt;br /&gt;
&lt;br /&gt;
A PPTP VPN service has been enabled in Mettle SE to allow authorised users to connect to the campus network&lt;br /&gt;
for administrative and academic purposes. Users are issued with  unique username and password combination with&lt;br /&gt;
which they can connect to Mettle SE from anywhere in the world. VPN user credentials are stored in a RADIUS&lt;br /&gt;
server which is linked with Mettle SE. VPN users trying to connect to Mettle SE is authorised against the user&lt;br /&gt;
credentials stored in the RADIUS server. Valid users are allowed to connect after verification. Mettle SE VPN&lt;br /&gt;
service also allows users to access campus resources irrespective of their location, without compromising&lt;br /&gt;
security. &lt;br /&gt;
&lt;br /&gt;
e) Proxy Server and Content Scanning &lt;br /&gt;
&lt;br /&gt;
Routing all IP traffic from the local subnets to the Internet via a proxy service has its advantages. A&lt;br /&gt;
research institute would like their students and faculty to use the Internet according to the acceptable usage&lt;br /&gt;
policy (AUP). Mettle SE helps the network administrator to enforce AUP with its Proxy Server and Content&lt;br /&gt;
scanning engines. The Internet usage policy is best if enforced at the point of presence of the ISP links,&lt;br /&gt;
which ensures that content is filtered before it is passed on to the LAN. &lt;br /&gt;
&lt;br /&gt;
Mettle SE has been serving the institute reliably and efficiently since its deployment, meeting the needs of&lt;br /&gt;
the management and the system administrators. Mettle SE has proved its Mettle once again, serving our client&lt;br /&gt;
reliably round the clock.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
We would like to receive feedback regarding the content of this newsletter and&lt;br /&gt;
request for articles. Please send in your valuable suggestions to&lt;br /&gt;
&lt;a href=&quot;mailto:&amp;#109;&amp;#x65;&amp;#116;&amp;#x74;&amp;#x6C;&amp;#x65;&amp;#110;&amp;#x65;&amp;#119;&amp;#115;&amp;#x40;&amp;#109;&amp;#x65;&amp;#116;&amp;#116;&amp;#108;&amp;#101;&amp;#x2E;&amp;#x69;&amp;#110;&quot;&gt;&amp;#109;&amp;#x65;&amp;#116;&amp;#x74;&amp;#x6C;&amp;#x65;&amp;#110;&amp;#x65;&amp;#119;&amp;#115;&amp;#x40;&amp;#109;&amp;#x65;&amp;#116;&amp;#116;&amp;#108;&amp;#101;&amp;#x2E;&amp;#x69;&amp;#110;&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
Mettle and Linuxense are trademarks of Linuxense Information Systems Pvt. Ltd.&lt;br /&gt;
Other trademarks belong to respective owners. 2008 (C) Linuxense Information&lt;br /&gt;
Systems Pvt. Ltd. All rights reserved.&lt;/p&gt;
    	&lt;!-- begin subscription_form_widget.tmpl --&gt; 



 

    &lt;form action=&quot;http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi&quot; method=&quot;post&quot;&gt;

 

&lt;fieldset&gt;
&lt;legend&gt;
 Subscribe/Unsubscribe  on Mettle News
&lt;/legend&gt;

 
    

    &lt;input type=&quot;hidden&quot; name=&quot;list&quot; value=&quot;mettlenewsletter&quot; /&gt;


&lt;p&gt;
&lt;label for=&quot;email&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot; &gt;
Email&amp;nbsp;Address: 
&lt;/label&gt;
&lt;input type=&quot;text&quot; name=&quot;email&quot; id=&quot;email&quot; value=&quot;&quot; /&gt; &lt;span class=&quot;error&quot;&gt;* Required&lt;/span&gt;
&lt;/p&gt;

 

    &lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

     
    
        &lt;p&gt;
        &lt;label for=&quot;name&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
        Name: 
        &lt;/label&gt;
        &lt;input type=&quot;text&quot; name=&quot;name&quot; id=&quot;name&quot; value=&quot;&quot;  /&gt;
        &lt;/p&gt;
    
    
     

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

 
    &lt;p&gt;
    &lt;label for=&quot;f_s&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
    Subscribe
    &lt;/label&gt;
    &lt;input type=&quot;radio&quot; name=&quot;f&quot; id=&quot;f_s&quot; value=&quot;subscribe&quot; checked=&quot;checked&quot; /&gt;
    &lt;/p&gt; 
    
    &lt;p&gt; 
    &lt;label for=&quot;f_u&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;Unsubscribe&lt;/label&gt; 
    &lt;input type=&quot;radio&quot; name=&quot;f&quot;  id=&quot;f_u&quot;  value=&quot;unsubscribe&quot;  /&gt;
    &lt;/p&gt;   

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

&lt;p style=&quot;text-align:right;display:block&quot;&gt;
&lt;input type=&quot;submit&quot; value=&quot;Submit Your Information&quot; class=&quot;processing&quot; /&gt;
&lt;/p&gt; 


 

    &lt;p style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;&lt;a href=&quot;http://dadamailproject.com&quot; target=&quot;_blank&quot; style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;Powered by Dada Mail 3.0.0 Mailing List Manager&lt;/a&gt;&lt;/p&gt;

 




&lt;/fieldset&gt;
&lt;/form&gt; 



  
&lt;!-- end subscription_form_widget.tmpl --&gt; 
     
    </content>
  </entry>

 

  <entry>
    <title>Mettle News March, 2010</title>
    <link rel="alternate" href="http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi/archive/mettlenewsletter/20100331162336/"/>
    <id>tag:newsletter.mettlenetworks.com,2010-03-31:%2Fcgi-bin%2Fmail.cgi%2Farchive%2Fmettlenewsletter%2F20100331162336%2F</id>
    
    <published>2010-03-31T16:23:36Z</published>
    <updated>2010-03-31T16:23:36Z</updated>
    <content type="html">&lt;p&gt;&lt;br /&gt;
&lt;br /&gt;
METTLE NEWS&lt;br /&gt;
[News letter on Mettle(tm) brand of products; Industry updates, Tips and Case&lt;br /&gt;
studies]&lt;br /&gt;
&lt;br /&gt;
March 2010 &lt;br /&gt;
Volume 3, Issue 3 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In this issue:&lt;br /&gt;
&lt;br /&gt;
* Editorial &lt;br /&gt;
* IT Industry news: Websites that can take a punch! &lt;br /&gt;
* Tip of the month:  Firewall States&lt;br /&gt;
* Mettle SE feature: RRD Graphs &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Editorial &lt;br /&gt;
&lt;br /&gt;
Greetings!&lt;br /&gt;
&lt;br /&gt;
We are at the closing of one more financial year. The year passing by was both exciting and troublesome for&lt;br /&gt;
many. But the year ahead seems very promising in the soaring economy. We wish all of our clients a prosperous&lt;br /&gt;
year ahead and hope to strengthen our relationships further!&lt;br /&gt;
&lt;br /&gt;
This issue's Industry News examines how MIT succeeded in preparing Web sites can stand an attack.&lt;br /&gt;
&lt;br /&gt;
Tip of the month this month features &amp;#147;Firewall States&amp;#148; in Mettle SE. Feature of the month column introduces&lt;br /&gt;
RRD Graphs in Mettle SE.&lt;br /&gt;
&lt;br /&gt;
Once again all at Linuxense wish readers a prosperous year ahead!&lt;br /&gt;
&lt;br /&gt;
Yours truly,&lt;br /&gt;
Editor, Mettle News&lt;br /&gt;
(&lt;a href=&quot;mailto:&amp;#109;&amp;#x65;&amp;#116;&amp;#116;&amp;#x6C;&amp;#x65;&amp;#x6E;&amp;#101;&amp;#119;&amp;#x73;&amp;#x40;&amp;#109;&amp;#101;&amp;#x74;&amp;#x74;&amp;#x6C;&amp;#101;&amp;#x2E;&amp;#x69;&amp;#x6E;&quot;&gt;&amp;#109;&amp;#x65;&amp;#116;&amp;#116;&amp;#x6C;&amp;#x65;&amp;#x6E;&amp;#101;&amp;#119;&amp;#x73;&amp;#x40;&amp;#109;&amp;#101;&amp;#x74;&amp;#x74;&amp;#x6C;&amp;#101;&amp;#x2E;&amp;#x69;&amp;#x6E;&lt;/a&gt;)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* IT Industry News: Websites that can take a punch! &lt;br /&gt;
&lt;br /&gt;
The recent, well-publicised cyber attack on Google was just the latest skirmish in a long war. And like most&lt;br /&gt;
long wars, this one features an arms race, as hackers seek out new security holes, and web site administrators&lt;br /&gt;
try to close them. &lt;br /&gt;
&lt;br /&gt;
When a web site is under attack, its only viable defence may be to take its servers offline, which in the&lt;br /&gt;
short term can cost  them money in lost revenue and productivity and, in the long term, could hurt its&lt;br /&gt;
credibility. Indeed knocking a site offline may be an attackers&amp;#146; sole intention. &lt;br /&gt;
&lt;br /&gt;
MIT researchers have developed a system to keep web servers or any Internet-connected computers running even&lt;br /&gt;
when they&amp;#146;re under attack. The work was funded largely by the U.S. Defence Department. In a pair of tests&lt;br /&gt;
whose thoroughness is unusual in academia, DARPA hired a group of computer security professionals outside MIT&lt;br /&gt;
to try to bring down a test network protected by the new system. In both tests the system exceeded all the&lt;br /&gt;
performance criteria that DARPA set for it, says Martin Rinard the professor of electrical engineering and&lt;br /&gt;
computer science who led the research. &lt;br /&gt;
&lt;br /&gt;
The MIT system during its operation, monitors the programs running on an Internet-connected computer to&lt;br /&gt;
determine their normal range of behaviour, and during an attack, it simply refuses to let them wander outside&lt;br /&gt;
that range. Suppose that a program running on a web server routinely stores data in one of two memory&lt;br /&gt;
locations - A and B. During an attack, malicious code tries to trick the program into storing data at location&lt;br /&gt;
C instead. The MIT system won't let that operation happen,it sends the data to either location A or location B. &lt;br /&gt;
&lt;br /&gt;
Of course, the data may not be of a type that belongs at either of those locations. And the system will modify&lt;br /&gt;
behaviours that could be even more disruptive than data storage. At sites with large banks of servers the MIT&lt;br /&gt;
system gets several chances to find the best response to an attack. If storing at location A causes one server&lt;br /&gt;
in the bank to crash, the MIT system will tell the other servers to store it at location B, instead. &lt;br /&gt;
&lt;br /&gt;
&amp;#34;The idea is that you've got hundreds of machines out there,&amp;#34; Rinard says. &amp;#34;We're saying, 'Okay, fine, you can&lt;br /&gt;
take out six or 10 of my 200 machines.'&amp;#34; But, he adds, &amp;#34;by observing what happens with the executions of those&lt;br /&gt;
six or 10 machines, we'll be able to deploy patches out to protect the rest of the machines.&amp;#34; The entire&lt;br /&gt;
process of recognizing an attack, testing a number of countermeasures and deploying the most effective ones&lt;br /&gt;
can take a matter of seconds. &lt;br /&gt;
&lt;br /&gt;
Read the complete article at: &lt;br /&gt;
&lt;a href=&quot;http://web.mit.edu/newsoffice/2010/web-attacks-0317.html&quot;&gt;http://web.mit.edu/newsoffice/2010/web-attacks-0317.html&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Tip of the month: Firewall States&lt;br /&gt;
&lt;br /&gt;
Mettle SE has a stateful firewall and uses one state to track each connection to and from the system. These&lt;br /&gt;
states may be viewed in the web interface. &lt;br /&gt;
&lt;br /&gt;
To view the states go to Diagnostics --&amp;#62; States. Here  you will see the protocol for each connection, its&lt;br /&gt;
Source, Router, Destination and its connection state. When viewing NAT entries the three entries in the center&lt;br /&gt;
column represent the system which made the connection, the IP address and port Mettle SE is using for NAT&lt;br /&gt;
connection and the remote system to which the connection has been made. &lt;br /&gt;
&lt;br /&gt;
Individual states may be removed by clicking the 'X' button at the end of each row. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Mettle SE Feature: RRD Graphs&lt;br /&gt;
&lt;br /&gt;
RRD graphs are a useful set of data provided by Mettle SE. It keeps track of various sets of data and how the&lt;br /&gt;
system performs and stores this data in RRD files. To view RRD graphs go to: Status --&amp;#62; RRD Graphs. &lt;br /&gt;
&lt;br /&gt;
Some graphs can be viewed in 'Inverse style' or 'Absolute style'. In the Inverse style the graph is split in&lt;br /&gt;
the middle horizontally, incoming traffic is shown as going up and outgoing traffic is shown as going down. In&lt;br /&gt;
the Absolute style graph is superimposed. Each graph is available in several time span and each of these is&lt;br /&gt;
averaged over a different period of time based on how much time is being covered in each graph. Each graph&lt;br /&gt;
will have a legend and summarisation of the data being shown. &lt;br /&gt;
&lt;br /&gt;
There are six tabs on the RRD graphs page: System, Traffic, Packets, Quality, Queues and Settings. &lt;br /&gt;
&lt;br /&gt;
a) System graph: This shows a general overview of the system utilisation, including CPU usage, total&lt;br /&gt;
throughput and firewall states. &lt;br /&gt;
&lt;br /&gt;
b) Processor Graph: This shows the CPU usage for user and system processes, interrupts and the number of&lt;br /&gt;
running processes. &lt;br /&gt;
&lt;br /&gt;
c) Throughput Graph: Shows the incoming and outgoing traffic totalled up for all interfaces. &lt;br /&gt;
&lt;br /&gt;
d) States Graph: Shows the system states but breaks down the value in several ways. It shows the filter states&lt;br /&gt;
from firewall rules, NAT states from NAT rules and the count of unique active source and destination IP&lt;br /&gt;
addresses and the number of state changes per second. &lt;br /&gt;
&lt;br /&gt;
e) Traffic Graphs: Shows the amount of bandwidth used on each available interface in bits per second. There is&lt;br /&gt;
an 'All graphs' choice which will show all of the graphs in a single page. &lt;br /&gt;
&lt;br /&gt;
f) Packet Graphs: This works like traffic graphs but instead of reporting based on bandwidth used it reports&lt;br /&gt;
the number of packets per second (pps) passed. &lt;br /&gt;
&lt;br /&gt;
g) Quality Graph: This graph tracks the quality of WAN interfaces with gateways specified. Response time from&lt;br /&gt;
the gateway in milliseconds and percentage of lost packets is reported in this graph. Any loss on graph&lt;br /&gt;
indicates connectivity issues or times of excessive bandwidth  use. &lt;br /&gt;
&lt;br /&gt;
h) Queue Graphs: If traffic shaping is enabled queue graphs will show a composite of each traffic shaper&lt;br /&gt;
queue. Each queue will be shown represented by a unique colour. You can view either the graph of all queues or&lt;br /&gt;
the graph representing the drops from all queues. &lt;br /&gt;
&lt;br /&gt;
RRD Graph Settings: &lt;br /&gt;
&lt;br /&gt;
RRD graphs can be customised to suit your preferences. Its possible to turn of RRD graphing is you prefer to&lt;br /&gt;
use third party external graphing solution. Remember to click on 'Save' when you're finished. &lt;br /&gt;
&lt;br /&gt;
a) Enable Graphing: Check the box to turn ON RRD graphing. Uncheck the box to turn OFF RRD graphing. &lt;br /&gt;
&lt;br /&gt;
b) Default Category: This option selects the tab to be displayed as default when you visit RRD Graphs page. &lt;br /&gt;
&lt;br /&gt;
c) Default Style: This option selects which style of graph to be displayed by default, Inverse or Absolute. &lt;br /&gt;
&lt;br /&gt;
d) Save the settings when finished. &lt;br /&gt;
&lt;br /&gt;
KB Article: &lt;a href=&quot;http://kb.mettle.in/entry/50/&quot;&gt;http://kb.mettle.in/entry/50/&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
We would like to receive feedback regarding the content of this newsletter and&lt;br /&gt;
request for articles. Please send in your valuable suggestions to&lt;br /&gt;
&lt;a href=&quot;mailto:&amp;#109;&amp;#x65;&amp;#116;&amp;#116;&amp;#x6C;&amp;#x65;&amp;#x6E;&amp;#101;&amp;#119;&amp;#x73;&amp;#x40;&amp;#109;&amp;#101;&amp;#x74;&amp;#x74;&amp;#x6C;&amp;#101;&amp;#x2E;&amp;#x69;&amp;#x6E;&quot;&gt;&amp;#109;&amp;#x65;&amp;#116;&amp;#116;&amp;#x6C;&amp;#x65;&amp;#x6E;&amp;#101;&amp;#119;&amp;#x73;&amp;#x40;&amp;#109;&amp;#101;&amp;#x74;&amp;#x74;&amp;#x6C;&amp;#101;&amp;#x2E;&amp;#x69;&amp;#x6E;&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
Mettle and Linuxense are trademarks of Linuxense Information Systems Pvt. Ltd.&lt;br /&gt;
Other trademarks belong to respective owners. 2008 (C) Linuxense Information&lt;br /&gt;
Systems Pvt. Ltd. All rights reserved.&lt;/p&gt;
    	&lt;!-- begin subscription_form_widget.tmpl --&gt; 



 

    &lt;form action=&quot;http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi&quot; method=&quot;post&quot;&gt;

 

&lt;fieldset&gt;
&lt;legend&gt;
 Subscribe/Unsubscribe  on Mettle News
&lt;/legend&gt;

 
    

    &lt;input type=&quot;hidden&quot; name=&quot;list&quot; value=&quot;mettlenewsletter&quot; /&gt;


&lt;p&gt;
&lt;label for=&quot;email&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot; &gt;
Email&amp;nbsp;Address: 
&lt;/label&gt;
&lt;input type=&quot;text&quot; name=&quot;email&quot; id=&quot;email&quot; value=&quot;&quot; /&gt; &lt;span class=&quot;error&quot;&gt;* Required&lt;/span&gt;
&lt;/p&gt;

 

    &lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

     
    
        &lt;p&gt;
        &lt;label for=&quot;name&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
        Name: 
        &lt;/label&gt;
        &lt;input type=&quot;text&quot; name=&quot;name&quot; id=&quot;name&quot; value=&quot;&quot;  /&gt;
        &lt;/p&gt;
    
    
     

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

 
    &lt;p&gt;
    &lt;label for=&quot;f_s&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
    Subscribe
    &lt;/label&gt;
    &lt;input type=&quot;radio&quot; name=&quot;f&quot; id=&quot;f_s&quot; value=&quot;subscribe&quot; checked=&quot;checked&quot; /&gt;
    &lt;/p&gt; 
    
    &lt;p&gt; 
    &lt;label for=&quot;f_u&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;Unsubscribe&lt;/label&gt; 
    &lt;input type=&quot;radio&quot; name=&quot;f&quot;  id=&quot;f_u&quot;  value=&quot;unsubscribe&quot;  /&gt;
    &lt;/p&gt;   

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

&lt;p style=&quot;text-align:right;display:block&quot;&gt;
&lt;input type=&quot;submit&quot; value=&quot;Submit Your Information&quot; class=&quot;processing&quot; /&gt;
&lt;/p&gt; 


 

    &lt;p style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;&lt;a href=&quot;http://dadamailproject.com&quot; target=&quot;_blank&quot; style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;Powered by Dada Mail 3.0.0 Mailing List Manager&lt;/a&gt;&lt;/p&gt;

 




&lt;/fieldset&gt;
&lt;/form&gt; 



  
&lt;!-- end subscription_form_widget.tmpl --&gt; 
     
    </content>
  </entry>

 

  <entry>
    <title>Mettle News February, 2010</title>
    <link rel="alternate" href="http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi/archive/mettlenewsletter/20100223130244/"/>
    <id>tag:newsletter.mettlenetworks.com,2010-02-23:%2Fcgi-bin%2Fmail.cgi%2Farchive%2Fmettlenewsletter%2F20100223130244%2F</id>
    
    <published>2010-02-23T13:02:44Z</published>
    <updated>2010-02-23T13:02:44Z</updated>
    <content type="html">&lt;p&gt;&lt;br /&gt;
&lt;br /&gt;
METTLE NEWS&lt;br /&gt;
[News letter on Mettle(tm) brand of products; Industry updates, Tips and Case&lt;br /&gt;
studies]&lt;br /&gt;
&lt;br /&gt;
February 2010&lt;br /&gt;
Volume 3, Issue 2&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In this issue:&lt;br /&gt;
* IT Industry news: Hacker attacks from China&lt;br /&gt;
* Tip of the month: Traffic Graph&lt;br /&gt;
* Mettle SE feature:  Time-based Firewall Rules&lt;br /&gt;
* Case Study&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Greetings,&lt;br /&gt;
&lt;br /&gt;
Presenting you yet another edition of Mettle News with more tips, news and case studies. &lt;br /&gt;
&lt;br /&gt;
To thank your patronage and to celebrate the completion of one year of Mettle News, we are giving out&lt;br /&gt;
Mettle(tm) goodies to Mettle News readers. To get yours, just send an email to &lt;a href=&quot;mailto:&amp;#x67;&amp;#x6F;&amp;#111;&amp;#100;&amp;#x69;&amp;#101;&amp;#115;&amp;#x40;&amp;#109;&amp;#x65;&amp;#x74;&amp;#x74;&amp;#108;&amp;#x65;&amp;#x2E;&amp;#105;&amp;#x6E;&quot;&gt;&amp;#x67;&amp;#x6F;&amp;#111;&amp;#100;&amp;#x69;&amp;#101;&amp;#115;&amp;#x40;&amp;#109;&amp;#x65;&amp;#x74;&amp;#x74;&amp;#108;&amp;#x65;&amp;#x2E;&amp;#105;&amp;#x6E;&lt;/a&gt; saying hello.&lt;br /&gt;
&lt;br /&gt;
This edition presents you a Mettle SE tip that explains how to use the traffic graph facility to troubleshoot&lt;br /&gt;
and analyse WAN/Internet traffic in real time.&lt;br /&gt;
&lt;br /&gt;
Time-based firewall rules are handy when it comes to transparent enforcement of organisational policies.&lt;br /&gt;
Feature of the month explains how to do this in Mettle SE.&lt;br /&gt;
&lt;br /&gt;
Case study of the month explains how Mettle SE helped a premier University in the country to secure and manage&lt;br /&gt;
their fairly complex campus LAN using Mettle SE.&lt;br /&gt;
&lt;br /&gt;
As usual, we expect your feed back and suggestions to improve Mettle News. Requests for HTML version of this&lt;br /&gt;
news letter is being considered. Soon you will have the option of opting HTML version if you like it.&lt;br /&gt;
&lt;br /&gt;
Yours truly,&lt;br /&gt;
Editor, Mettle News&lt;br /&gt;
(&lt;a href=&quot;mailto:&amp;#109;&amp;#x65;&amp;#116;&amp;#x74;&amp;#x6C;&amp;#x65;&amp;#110;&amp;#101;&amp;#x77;&amp;#x73;&amp;#64;&amp;#109;&amp;#101;&amp;#116;&amp;#x74;&amp;#108;&amp;#x65;&amp;#x2E;&amp;#105;&amp;#110;&quot;&gt;&amp;#109;&amp;#x65;&amp;#116;&amp;#x74;&amp;#x6C;&amp;#x65;&amp;#110;&amp;#101;&amp;#x77;&amp;#x73;&amp;#64;&amp;#109;&amp;#101;&amp;#116;&amp;#x74;&amp;#108;&amp;#x65;&amp;#x2E;&amp;#105;&amp;#110;&lt;/a&gt;)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* IT Industry News: Hacker Attacks from China *&lt;br /&gt;
&lt;br /&gt;
Last month Google announced that it had been the target of a highly sophisticated hack attack against its&lt;br /&gt;
corporate infrastructure. Google said that hackers had stolen intellectual property and gained access to the&lt;br /&gt;
email accounts of human rights activists. This attack, according to Google, originated from China.&lt;br /&gt;
&lt;br /&gt;
It has been reported that Google managed to gain access to a computer in Taiwan that was suspected of being&lt;br /&gt;
the source of the attacks. Probing inside that machine Google engineers found evidence of attacks not only at&lt;br /&gt;
Google but also at 33 other companies including Adobe Systems and Juniper Networks. Adobe acknowledged in a&lt;br /&gt;
blog post that it discovered on 2nd January that it had also been the target of a &amp;#147;sophisticated, coordinated&lt;br /&gt;
attack against corporate network systems managed by Adobe and other companies.&amp;#148;&lt;br /&gt;
&lt;br /&gt;
The attackers used a dozen pieces of malware and several levels of encryption to burrow deep into the bowels&lt;br /&gt;
of corporate networks and obscure their activity. The encryption was supposedly highly successful in obscuring&lt;br /&gt;
the attack and avoiding common detection methods. Even though China has denied that it has anything to do with&lt;br /&gt;
the hacker attacks, experts believe that the attack might have been supported by Chinese Government agencies.&lt;br /&gt;
&lt;br /&gt;
Once the attackers were in systems they siphoned off data to command-and-control servers in Illinois, Texas&lt;br /&gt;
and Taiwan. Alperovitch, VP of threat research at McAfee, wouldn&amp;#146;t identify the systems in the United States&lt;br /&gt;
that were involved in the attack but reports indicate that Rackspace, a hosting firm in Texas, was used by&lt;br /&gt;
hackers. Rackspace disclosed on their blog that they inadvertently played a very small part in the attack.&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.nytimes.com/2010/02/19/technology/19china.html?em&quot;&gt;http://www.nytimes.com/2010/02/19/technology/19china.html?em&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.wired.com/threatlevel/2010/01/operation-aurora/#ixzz0frmLPVlU&quot;&gt;http://www.wired.com/threatlevel/2010/01/operation-aurora/#ixzz0frmLPVlU&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Tip Of The Month: Traffic Graphs *&lt;br /&gt;
&lt;br /&gt;
Mettle SE provides you with a solution to view network traffic on any of the Interfaces in real time. Traffic&lt;br /&gt;
graphs in SVG (Scalable Vector Graphics) format is being rendered constantly live showing the traffic flow of&lt;br /&gt;
the selected network interface.&lt;br /&gt;
&lt;br /&gt;
To view Traffic Graph go to: Status --&amp;#62; Traffic Graph&lt;br /&gt;
&lt;br /&gt;
Choose which interface to view from the Interface drop down list. When you select an interface, the page will&lt;br /&gt;
automatically refresh and start displaying the graph. Traffic graph is a quick tool that helps to analyse the&lt;br /&gt;
network speed and find out if any link is showing unexpected traffic.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Mettle SE feature: Time-based Firewall Rules *&lt;br /&gt;
&lt;br /&gt;
Time-based rules allow to set up firewall rules that come into effect only on specified days and/or time&lt;br /&gt;
period. The schedule determines when to apply the rules specified. &lt;br /&gt;
&lt;br /&gt;
To configure a Schedule go to:&lt;br /&gt;
&lt;br /&gt;
1) Firewall --&amp;#62; Schedules --&amp;#62; Click on the '+' (Add) button&lt;br /&gt;
2) Enter a Schedule Name of your choice containing only letters and digits&lt;br /&gt;
&lt;br /&gt;
Now specify schedule:&lt;br /&gt;
&lt;br /&gt;
3) A schedule can apply to specific days of a month or days of the week&lt;br /&gt;
4) To select any given day within the year, choose month from the drop down list and click on specific days on&lt;br /&gt;
   the calendar.&lt;br /&gt;
5) To select for any day regardless of the month click on Mon, Tue, Wed, Thu etc. This will make the schedule&lt;br /&gt;
   active for Mondays, Tuesdays, Wednesdays etc.&lt;br /&gt;
&lt;br /&gt;
Defining Time Range:&lt;br /&gt;
&lt;br /&gt;
6) Select the Schedule start and end time in Hours and Minutes from the drop down box.&lt;br /&gt;
7) You may enter a Time Range Description for ease of understanding.&lt;br /&gt;
8) Click 'Add Time' once time range has been selected.&lt;br /&gt;
9) You can add more than one time ranges. You may use same time range for identical days and another time&lt;br /&gt;
   range for each day with different times (For e.g. Working hours on Monday to Tuesday might be from 9Am to&lt;br /&gt;
   5Pm and on Saturdays it might be from 9Am to 2Pm).&lt;br /&gt;
10) Save the changes once defining Schedule has been completed.&lt;br /&gt;
&lt;br /&gt;
Using the Schedule in a Firewall Rule:&lt;br /&gt;
&lt;br /&gt;
11) Create a Firewall Rule as you would normally create to allow or deny particular traffic.&lt;br /&gt;
12) Inside Firewall Rule editing page you can find the 'Schedule' heading and a drop down list box next to it.&lt;br /&gt;
13) Select the Schedule you have created from this drop box.&lt;br /&gt;
14) Configure the rest of the Firewall settings and Save the configuration.&lt;br /&gt;
&lt;br /&gt;
The Firewall Rule you have now created would be active during the Schedule you have defined.&lt;br /&gt;
&lt;br /&gt;
See the Mettle Knowledge article: &lt;a href=&quot;http://kb.mettle.in/entry/49/&quot;&gt;http://kb.mettle.in/entry/49/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Case Study *&lt;br /&gt;
&lt;br /&gt;
Vertical: Education/Campus&lt;br /&gt;
Geography: Trivandrum, Kerala&lt;br /&gt;
&lt;br /&gt;
Client Profile:&lt;br /&gt;
&lt;br /&gt;
This client is the oldest University in the state of Kerala, established in the year of 1937 in the then&lt;br /&gt;
Travancore state. The University has sixteen faculties and 41 departments of teaching and research and there&lt;br /&gt;
are around 157 affiliated colleges under the wings of the university. The University Departments offer a wide&lt;br /&gt;
range of teaching and research at post-graduate and higher levels.&lt;br /&gt;
&lt;br /&gt;
Problems to be solved:&lt;br /&gt;
&lt;br /&gt;
Campus is connected to the Internet by multiple ISP links to satiate the demand for high bandwidth&lt;br /&gt;
necessitated by large number of computers requiring Internet connectivity. Unequal bandwidth ISP links are&lt;br /&gt;
deployed at the campus. Load balancing two ISP links is to be implemented taking care not to over saturate the&lt;br /&gt;
link with lower bandwidth. College campus network was not secured from Internet borne virus attacks and&lt;br /&gt;
threats since they do not have a gateway anti virus solution. To keep the campus network from offensive and&lt;br /&gt;
inappropriate content, content filtering is to be implemented. Students and faculties rely upon video feeds as&lt;br /&gt;
a part of their curriculum and such content has to be accessed from the campus network. Servers hosted in the&lt;br /&gt;
campus running public services have to be made accessible from the Internet.&lt;br /&gt;
&lt;br /&gt;
Solutions built up with Mettle SE are classified into the following sections:&lt;br /&gt;
&lt;br /&gt;
a. Terminating redundant  ISP links with fail over and load balancing&lt;br /&gt;
b. Firewall, Gateway Anti-virus  and Content Filtering&lt;br /&gt;
c. Port Forwarding&lt;br /&gt;
&lt;br /&gt;
a. Redundant  ISP links&lt;br /&gt;
&lt;br /&gt;
Internet connection to the campus is provided by two ISP links. These two links are of unequal bandwidth, one a&lt;br /&gt;
higher bandwidth link and the other comparatively lower in bandwidth. Both links are terminated at Mettle SE&lt;br /&gt;
and configured in a load balanced set up. ISP links being of different bandwidth, Mettle SE has been&lt;br /&gt;
configured to pass proportionately more traffic through the broader link and direct less traffic through the&lt;br /&gt;
narrow bandwidth link. Load balancing is set at a ratio of 4:1. Such a set up has been implemented to ensure&lt;br /&gt;
the best possible utilisation of the links.&lt;br /&gt;
&lt;br /&gt;
With load balancing enabled, automatic fail over mode is also active. If an ISP link goes down Internet&lt;br /&gt;
traffic is diverted over to the active link. Though browsing speed will be proportionately lower one of the&lt;br /&gt;
link goes down, Mettle SE will keep the campus connected without interruption. Once the ISP link is back up&lt;br /&gt;
Mettle SE adds it back into the load balancing pool.&lt;br /&gt;
&lt;br /&gt;
b. Firewall, Gateway Anti-virus  and Content Filtering&lt;br /&gt;
&lt;br /&gt;
Campus network at the time of deployment did not have an effective gateway anti-virus system, firewall and&lt;br /&gt;
content filtering service. With Mettle SE the the aim was to provide maximum security for the campus network&lt;br /&gt;
with Mettle SE's inbuilt Firewall, Gateway Anti-virus system and Content Filtering services. Campus LAN is&lt;br /&gt;
divided into two different subnets based on the security and management requirements. Main network is the&lt;br /&gt;
campus LAN and the smaller network is the DMZ network.&lt;br /&gt;
&lt;br /&gt;
Mettle SE's firewall secures the LAN from unauthorised access from other networks. Firewall rules combined&lt;br /&gt;
with Aliases feature in Mettle SE enables restricting unauthorised access to resources hosted in the LAN and&lt;br /&gt;
DMZ network with ease. Public servers are hosted behind Mettle SE's Firewall to protect them from Internet&lt;br /&gt;
borne threats and attacks.&lt;br /&gt;
&lt;br /&gt;
Mettle SE has an inbuilt Gateway Anti virus engine which filters all viruses and worms coming from the Internet&lt;br /&gt;
before it reaches the local area network. The Gateway Anti-virus engine inside Mettle SE automatically&lt;br /&gt;
maintains an up-to-date virus definition without user intervention. This helps to identify and quarantine most&lt;br /&gt;
viruses propagating over the Internet. Thus Mettle SE Gateway Anti-virus goes a long way in keeping the campus&lt;br /&gt;
network safer from viruses and malicious codes.&lt;br /&gt;
&lt;br /&gt;
University wished to implement an Acceptable Usage Policy (AUP) with the aim of enforcing effective Internet&lt;br /&gt;
usage in the campus. Best way to enforce such a policy is to enforce it at the point of presence of ISP links,&lt;br /&gt;
which helps to filter out content before it reaches the local network. With Mettle SE implementing AUP was&lt;br /&gt;
made easy. Mettle SE was configured to block certain types of web sites and web resources that goes against&lt;br /&gt;
University's general policies and websites which allow Internet users to circumvent usage policy. Mettle SE's&lt;br /&gt;
White List and Grey List feature allows complete exclusion and partial exclusions of web sites respectively.&lt;br /&gt;
If a particular website is white listed, it will not be scanned and thus the website access will be faster for&lt;br /&gt;
the user. If a website is Grey listed then the website will be scanned and if that website content falls&lt;br /&gt;
within the AUP it shall be allowed. Black listing a website is possible and doing so those websites will be&lt;br /&gt;
blocked.&lt;br /&gt;
&lt;br /&gt;
c. Mettle SE for Port Forwarding&lt;br /&gt;
&lt;br /&gt;
The institution hosts several servers in the local network which needs to be accessed from the Internet by&lt;br /&gt;
authorised users and general public. These servers are hosted behind Mettle SE and protected from hacker&lt;br /&gt;
attacks and viruses. To make these servers available on the Internet Mettle SE uses port forwarding which&lt;br /&gt;
translates the the local IP address assigned to the servers to a public IP address for a specific port or set&lt;br /&gt;
of ports.&lt;br /&gt;
&lt;br /&gt;
Conclusion:&lt;br /&gt;
&lt;br /&gt;
Mettle SE enabled the University to provide high quality Internet and Internet enabled services in the campus.&lt;br /&gt;
Mettle SE is the secure gateway for their connections to public networks and secures the servers and computers&lt;br /&gt;
in the local networks. Mettle SE does bandwidth aggregation of two unequal bandwidth WAN links with load&lt;br /&gt;
balancing providing the campus with high bandwidth and redundancy.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
We would like to receive feedback regarding the content of this newsletter and&lt;br /&gt;
request for articles. Please send in your valuable suggestions to&lt;br /&gt;
&lt;a href=&quot;mailto:&amp;#109;&amp;#x65;&amp;#116;&amp;#x74;&amp;#x6C;&amp;#x65;&amp;#110;&amp;#101;&amp;#x77;&amp;#x73;&amp;#64;&amp;#109;&amp;#101;&amp;#116;&amp;#x74;&amp;#108;&amp;#x65;&amp;#x2E;&amp;#105;&amp;#110;&quot;&gt;&amp;#109;&amp;#x65;&amp;#116;&amp;#x74;&amp;#x6C;&amp;#x65;&amp;#110;&amp;#101;&amp;#x77;&amp;#x73;&amp;#64;&amp;#109;&amp;#101;&amp;#116;&amp;#x74;&amp;#108;&amp;#x65;&amp;#x2E;&amp;#105;&amp;#110;&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
Mettle and Linuxense are trademarks of Linuxense Information Systems Pvt. Ltd.&lt;br /&gt;
Other trademarks belong to respective owners. 2008 (C) Linuxense Information&lt;br /&gt;
Systems Pvt. Ltd. All rights reserved.&lt;/p&gt;
    	&lt;!-- begin subscription_form_widget.tmpl --&gt; 



 

    &lt;form action=&quot;http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi&quot; method=&quot;post&quot;&gt;

 

&lt;fieldset&gt;
&lt;legend&gt;
 Subscribe/Unsubscribe  on Mettle News
&lt;/legend&gt;

 
    

    &lt;input type=&quot;hidden&quot; name=&quot;list&quot; value=&quot;mettlenewsletter&quot; /&gt;


&lt;p&gt;
&lt;label for=&quot;email&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot; &gt;
Email&amp;nbsp;Address: 
&lt;/label&gt;
&lt;input type=&quot;text&quot; name=&quot;email&quot; id=&quot;email&quot; value=&quot;&quot; /&gt; &lt;span class=&quot;error&quot;&gt;* Required&lt;/span&gt;
&lt;/p&gt;

 

    &lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

     
    
        &lt;p&gt;
        &lt;label for=&quot;name&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
        Name: 
        &lt;/label&gt;
        &lt;input type=&quot;text&quot; name=&quot;name&quot; id=&quot;name&quot; value=&quot;&quot;  /&gt;
        &lt;/p&gt;
    
    
     

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

 
    &lt;p&gt;
    &lt;label for=&quot;f_s&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
    Subscribe
    &lt;/label&gt;
    &lt;input type=&quot;radio&quot; name=&quot;f&quot; id=&quot;f_s&quot; value=&quot;subscribe&quot; checked=&quot;checked&quot; /&gt;
    &lt;/p&gt; 
    
    &lt;p&gt; 
    &lt;label for=&quot;f_u&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;Unsubscribe&lt;/label&gt; 
    &lt;input type=&quot;radio&quot; name=&quot;f&quot;  id=&quot;f_u&quot;  value=&quot;unsubscribe&quot;  /&gt;
    &lt;/p&gt;   

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

&lt;p style=&quot;text-align:right;display:block&quot;&gt;
&lt;input type=&quot;submit&quot; value=&quot;Submit Your Information&quot; class=&quot;processing&quot; /&gt;
&lt;/p&gt; 


 

    &lt;p style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;&lt;a href=&quot;http://dadamailproject.com&quot; target=&quot;_blank&quot; style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;Powered by Dada Mail 3.0.0 Mailing List Manager&lt;/a&gt;&lt;/p&gt;

 




&lt;/fieldset&gt;
&lt;/form&gt; 



  
&lt;!-- end subscription_form_widget.tmpl --&gt; 
     
    </content>
  </entry>

 

  <entry>
    <title>Mettle News January, 2010</title>
    <link rel="alternate" href="http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi/archive/mettlenewsletter/20100128122215/"/>
    <id>tag:newsletter.mettlenetworks.com,2010-01-28:%2Fcgi-bin%2Fmail.cgi%2Farchive%2Fmettlenewsletter%2F20100128122215%2F</id>
    
    <published>2010-01-28T12:22:15Z</published>
    <updated>2010-01-28T12:22:15Z</updated>
    <content type="html">&lt;p&gt;&lt;br /&gt;
&lt;br /&gt;
METTLE NEWS&lt;br /&gt;
[News letter on Mettle(tm) brand of products; Industry updates, Tips and Case&lt;br /&gt;
studies]&lt;br /&gt;
&lt;br /&gt;
January 2010&lt;br /&gt;
Volume 3, Issue 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In this issue:&lt;br /&gt;
&lt;br /&gt;
* Editorial&lt;br /&gt;
* IT Industry news: Scraping the bottom of IPv4 barrel!&lt;br /&gt;
* Tip of the month: Configuration History&lt;br /&gt;
* Mettle SE feature: DHCP Server&lt;br /&gt;
* Case Study:  e-Governance Kerala State Department&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Editorial *&lt;br /&gt;
&lt;br /&gt;
Wish you a happy new year!&lt;br /&gt;
&lt;br /&gt;
Hope you had a great year behind. Let us look forward to an exciting year ahead!&lt;br /&gt;
&lt;br /&gt;
This new year begins with a warning on IPv4 address space run out. So regional NICs are going to be stringent&lt;br /&gt;
on terms to release new IP address blocks and in turn ISPs are going to put cap on free IP address pool they&lt;br /&gt;
provide. This months Industry News takes a look at this scenario and the proposed solution of IPv6.&lt;br /&gt;
&lt;br /&gt;
Tip of the Month this issue shows a cool way to keep track the configuration changes in your Mettle SE. This&lt;br /&gt;
is handy when you want to revert a change that you made or want to do a forensic analysis.&lt;br /&gt;
&lt;br /&gt;
In the Feature of the Month section, it is an in-depth view of the DHCP service that is available in Mettle SE.&lt;br /&gt;
&lt;br /&gt;
As always, we appreciate your feedback, suggestions and brickbats. Enjoy!&lt;br /&gt;
&lt;br /&gt;
Once again, wish you a Happy New Year!&lt;br /&gt;
&lt;br /&gt;
Yours truly,&lt;br /&gt;
Editor, Mettle News&lt;br /&gt;
(&lt;a href=&quot;mailto:&amp;#x6D;&amp;#x65;&amp;#x74;&amp;#116;&amp;#x6C;&amp;#101;&amp;#x6E;&amp;#x65;&amp;#x77;&amp;#x73;&amp;#x40;&amp;#109;&amp;#101;&amp;#116;&amp;#116;&amp;#x6C;&amp;#x65;&amp;#x2E;&amp;#105;&amp;#x6E;&quot;&gt;&amp;#x6D;&amp;#x65;&amp;#x74;&amp;#116;&amp;#x6C;&amp;#101;&amp;#x6E;&amp;#x65;&amp;#x77;&amp;#x73;&amp;#x40;&amp;#109;&amp;#101;&amp;#116;&amp;#116;&amp;#x6C;&amp;#x65;&amp;#x2E;&amp;#105;&amp;#x6E;&lt;/a&gt;)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* IT Industry News &amp;#150; Scraping the bottom of IPv4 barrel *&lt;br /&gt;
&lt;br /&gt;
We are facing an IP address crunch and at the rate we are using the current IPv4 addresses and we will soon&lt;br /&gt;
extinguish the available supply in a few more years! We used up 1370 million IPv4 addresses in this past&lt;br /&gt;
decade and we have only 722 million left!&lt;br /&gt;
&lt;br /&gt;
Of the 3,706,650,624 IPv4 addresses, approximately 1615 million, 44 percent of the pool, were in use on&lt;br /&gt;
January 1 2000 and 2092 million were still available. Fast forward to the present 81 percent of the pool,&lt;br /&gt;
approximately around 2985 million, IPv4 addresses are in use and 722 million are available. So its only a&lt;br /&gt;
matter of time before you have to get into the IPv6 way of addressing.&lt;br /&gt;
&lt;br /&gt;
IANA allocates blocks of 16,777,216 addresses called &amp;#34;/8s&amp;#34; to the five Regional Internet Registries - AfriNIC,&lt;br /&gt;
APNIC, ARIN, LACNIC and the RIPE NCC - which in turn supply address space to ISPs and end-user organizations.&lt;br /&gt;
At the end of 2008, IANA held 34 unused /8s and the RIRs together held 371.91 million unused addresses.&lt;br /&gt;
&lt;br /&gt;
IANA global pool was only reduced by 8/8s, but the RIRs collectively reduced their working inventory by&lt;br /&gt;
another 5/8s, bringing total reduction of the free address space 13/8s, or 203.4 million IPv4 addresses, to be&lt;br /&gt;
exact. 2009 is the first year since 1992 that the number of IPv4 addresses given out has been more than 200&lt;br /&gt;
million.&lt;br /&gt;
&lt;br /&gt;
If IANA goes back to giving out 12/8s to the RIRs per year, IANA will be giving out the fifth-to-last /8&lt;br /&gt;
somewhere in 2011 and then automatically also the other four. APNIC's Geoff Huston predicts September 14, 2011&lt;br /&gt;
as the day the IANA global pool runs out, and November 1, 2012, as the day we last scrape the bottom of the&lt;br /&gt;
IPv4 barrel.&lt;br /&gt;
&lt;br /&gt;
Source: &lt;a href=&quot;http://arstechnica.com/tech-policy/news/2010/01/dont-publish-the-decade-in-ipv4-addresses.ars&quot;&gt;http://arstechnica.com/tech-policy/news/2010/01/dont-publish-the-decade-in-ipv4-addresses.ars&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Mettle SE tip of the month: Configuration History *&lt;br /&gt;
&lt;br /&gt;
Backup/Restore screen allows you to easily take backup of your Mettle SE running configuration or allows you&lt;br /&gt;
to load a saved configuration and make it active. But for minor problems you may use Mettle SE internal&lt;br /&gt;
backups to revert to a previous configuration, sort of like an 'undo' feature. Previous 30 configurations are&lt;br /&gt;
stored along with current running configuration.&lt;br /&gt;
&lt;br /&gt;
1.  Diagnostics --&amp;#62; Backup/Restore&lt;br /&gt;
2.  Select tab 'Config History'&lt;br /&gt;
3.  Listed are the previous 30 configurations along with the current running configuration.&lt;br /&gt;
4.  To make a previous config active click on the '+' button next to it.&lt;br /&gt;
5.  To delete a stored config click on the 'x' button next to it.&lt;br /&gt;
&lt;br /&gt;
Please note that Mettle SE will not automatically reboot if required. Minor changes may not need a reboot, but&lt;br /&gt;
recovering some major changes will need a reboot.&lt;br /&gt;
&lt;br /&gt;
(Best practice is to always take the backup of the running configuration into an admin PC on the LAN before&lt;br /&gt;
you make any major changes to Mettle SE).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Mettle SE feature: DHCP Server *&lt;br /&gt;
&lt;br /&gt;
DHCP server assigns IP addresses and related configuration options to client PCs on your network. It is&lt;br /&gt;
enabled by default on the LAN interface with the default IP range of 192.168.1.10 through 192.168.1.199. In&lt;br /&gt;
its default configuration Mettle SE assigns its LAN IP as the gateway and DNS server if DNS forwarder is&lt;br /&gt;
enabled.&lt;br /&gt;
&lt;br /&gt;
To configure DHCP server go to Services --&amp;#62; DHCP server. On the DHCP configuration page there is a tab for&lt;br /&gt;
each non-WAN interface and each interface has its own separate DHCP configuration and they may be enabled and&lt;br /&gt;
configured independently of each other.&lt;br /&gt;
&lt;br /&gt;
1.  Check 'Enable DHCP Server' to enable DHCP on an Interface.&lt;br /&gt;
2.  Check 'Deny unknown clients' to deny DHCP lease to clients except for those which are defined with static&lt;br /&gt;
    mapping.&lt;br /&gt;
3.  Range - Enter the start IP address and the finish IP address for use as DHCP pool. DHCP range must be&lt;br /&gt;
    contained within the subnet of the interface being configured.&lt;br /&gt;
4.  WINS Servers -  Enter the IP address of WINS servers if you use WINS servers. They need not be on the same&lt;br /&gt;
    network but proper routing and firewall rules should be in place.&lt;br /&gt;
5.  DNS Servers - Depending on your LAN setup you may or may not fill in the DNS servers. Leaving the fields&lt;br /&gt;
    blank and if you enable DNS forwarder in Mettle SE, mettle SE will assign itself as the DNS forwarder for&lt;br /&gt;
    client PCs. If the fields are left blank and if DNS forwarder is disabled Mettle SE will pass on the DNS&lt;br /&gt;
    server assigned in System --&amp;#62; General Setup. If you wish to use your own DNS servers instead of automatic&lt;br /&gt;
    choices, enter the IP addresses of the DNS servers here.&lt;br /&gt;
6.  Gateway - If LAN is using Mettle SE as the default gateway, the field can be left blank. If not enter the&lt;br /&gt;
    IP address of your gateway.&lt;br /&gt;
7.  Default and Maximum  Lease Time - Value to be entered in 'seconds'. It control the life of the DHCP lease.&lt;br /&gt;
    Default lease time is supplied by Metle SE when the client does not request for a specific lease time.&lt;br /&gt;
    Maximum lease time will control how long lease will last even if the client asks for a longer lease time.&lt;br /&gt;
8.  Fail-over Peer IP - If Mettle SE is setup in a failover stack enter the IP address of the slave Mettle SE&lt;br /&gt;
    here.&lt;br /&gt;
9.  Static ARP - If enabled Mettle SE will deny DHCP lease to unknown MAC addresses and also restrict any&lt;br /&gt;
    unknown client from communicate with Mettle SE. Before enabling static ARP make sure that clients which&lt;br /&gt;
    need to communicate with Mettle SE are listed inside static mapping list, especially the machine you need&lt;br /&gt;
    to access Mettle SE web interface from.&lt;br /&gt;
10. Dynamic DNS - Click on 'Advanced' button to go to Dynamic DNS settings. Check the check box to enable it.&lt;br /&gt;
    If using Mettle SEs DNS forwarder you can leave this blank and configure it inside DNS forwarder setup.&lt;br /&gt;
11. NTP Servers - Click on the 'Advanced' button to enter NTP server IP addresses.&lt;br /&gt;
12. Enable Network Booting - Click 'Advanced' button to view or enable network booting settings. Check the box&lt;br /&gt;
    to enable it. Enter the IP address of the 'Network boot server' and the 'File name of the boot image'.&lt;br /&gt;
13. After changes have been made click on 'Save' to save settings. This must be done before creating static&lt;br /&gt;
    mappings.&lt;br /&gt;
14. Static Mappings - This allows you to provide specific IP addresses to specific clients inside the LAN.&lt;br /&gt;
    To set static mapping click on '+' button and you will be forwarded to a new page. Here you will need to&lt;br /&gt;
    enter the MAC address of the particular client PC in the 'MAC Address' field and enter the IP address in&lt;br /&gt;
    the 'IP address' field. 'Host name' and 'Description' is not parsed so you may enter it or not. Please&lt;br /&gt;
    note that IP addresses issued for static mapping must be outside of the DHCP pool. Save the changes before&lt;br /&gt;
    navigating away from the page.&lt;br /&gt;
&lt;br /&gt;
KB Article: &lt;a href=&quot;http://kb.mettle.in/entry/4/&quot;&gt;http://kb.mettle.in/entry/4/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Case Study *&lt;br /&gt;
&lt;br /&gt;
Vertical: Government/e-Governance&lt;br /&gt;
Geography: Kerala, India&lt;br /&gt;
&lt;br /&gt;
Client profile:&lt;br /&gt;
&lt;br /&gt;
Department of the State of Kerala.&lt;br /&gt;
&lt;br /&gt;
Requirements &amp;#38; Solution:&lt;br /&gt;
&lt;br /&gt;
Their district head quarters are spread across the state and the Head Office (H.O) is stationed at&lt;br /&gt;
Thiruvananthapuram. Remote offices need to connect to the e-Governance application located at H.O,&lt;br /&gt;
Thiruvananthapuram. Also the servers which run the e-Governance applications at the H.O require protection from&lt;br /&gt;
unauthorised access from the Internet. Secondly Desktop computers at HO need to be protected from viruses,&lt;br /&gt;
Internet threats, malicious codes and offensive content.&lt;br /&gt;
&lt;br /&gt;
Mettle SE was deployed at the H.O as the solution to satisfy all the connectivity and security requirements.&lt;br /&gt;
They can be categorised into:&lt;br /&gt;
&lt;br /&gt;
a. VPN Solution&lt;br /&gt;
b. Port Forwarding&lt;br /&gt;
c. Firewall and Routing&lt;br /&gt;
d. Gateway Anti-virus and Content Scanning &lt;br /&gt;
&lt;br /&gt;
a. VPN Solution.&lt;br /&gt;
&lt;br /&gt;
Mettle SE made it possible to connect district offices and range offices spread across the 14 districts of&lt;br /&gt;
Kerala to the H.O through SSL-VPN. Remote VPN users on different operating systems seamlessly connect to the&lt;br /&gt;
H.O using and can reliably access servers according to their user privileges.&lt;br /&gt;
&lt;br /&gt;
b. Port Forwarding&lt;br /&gt;
&lt;br /&gt;
Certain servers hosted at the H.O to be accessible over the Internet. Mettle SE provided port address&lt;br /&gt;
translation service to the servers that has to be accessed from a public network. Mettle SE has made it&lt;br /&gt;
possible to map internal servers to public IP addresses and they can be accessed from the Internet for users&lt;br /&gt;
with valid credentials.&lt;br /&gt;
&lt;br /&gt;
c. Firewall and Routing&lt;br /&gt;
&lt;br /&gt;
For extended security, PCs and servers are deployed in two different local networks: User-LAN and  Server-LAN.&lt;br /&gt;
Firewall rules specified in Mettle SE controls the access to the computers in the User-LAN, servers in&lt;br /&gt;
Server-LAN and secure publicly accessible servers. Remote users access to servers in the H.O is strictly&lt;br /&gt;
controlled based on their requirement. Mettle SE blocks all unspecified traffic from reaching the HO network.&lt;br /&gt;
&lt;br /&gt;
There are two routable LAN segments in the network. Servers are placed in a secured Server LAN subnet to&lt;br /&gt;
separate them from  User LAN traffic. Mettle SE routes users on  User-LAN to the server network when they&lt;br /&gt;
access their servers.&lt;br /&gt;
&lt;br /&gt;
b. Content Scanning and Gateway Antivirus&lt;br /&gt;
&lt;br /&gt;
Mettle SE is the terminating point for the ISP link at the H.O. Mettle SE is the Gateway for desktop computers&lt;br /&gt;
and servers. Mettle SE protects the local network from viruses and worms from the Internet with its built-in&lt;br /&gt;
Gateway Antivirus service. Mettle SE updates virus signature database automatically with the latest anti-virus&lt;br /&gt;
definitions available so as to block any new virus.&lt;br /&gt;
&lt;br /&gt;
Internet traffic is filtered by Mettle SE's proxy Server. Web sites and services that violate Internet usage&lt;br /&gt;
policy are blocked preventing users from accessing it. Mettle SE keeps a log of the Websites users visit on&lt;br /&gt;
the Internet; and the Web services they use like, instant messengers or download clients. Mettle SE keeps the&lt;br /&gt;
Internet content distribution in the H.O, clean and safe.&lt;br /&gt;
&lt;br /&gt;
Conclusion:&lt;br /&gt;
&lt;br /&gt;
Mettle SE has been serving the  department for many years since its deployment. Mettle SE team is happy to&lt;br /&gt;
report that Mettle SE is working flawlessly ever since satisfying the requirement of the department.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
We would like to receive feedback regarding the content of this newsletter and&lt;br /&gt;
request for articles. Please send in your valuable suggestions to&lt;br /&gt;
&lt;a href=&quot;mailto:&amp;#x6D;&amp;#x65;&amp;#x74;&amp;#116;&amp;#x6C;&amp;#101;&amp;#x6E;&amp;#x65;&amp;#x77;&amp;#x73;&amp;#x40;&amp;#109;&amp;#101;&amp;#116;&amp;#116;&amp;#x6C;&amp;#x65;&amp;#x2E;&amp;#105;&amp;#x6E;&quot;&gt;&amp;#x6D;&amp;#x65;&amp;#x74;&amp;#116;&amp;#x6C;&amp;#101;&amp;#x6E;&amp;#x65;&amp;#x77;&amp;#x73;&amp;#x40;&amp;#109;&amp;#101;&amp;#116;&amp;#116;&amp;#x6C;&amp;#x65;&amp;#x2E;&amp;#105;&amp;#x6E;&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
Mettle and Linuxense are trademarks of Linuxense Information Systems Pvt. Ltd.&lt;br /&gt;
Other trademarks belong to respective owners. 2008 (C) Linuxense Information&lt;br /&gt;
Systems Pvt. Ltd. All rights reserved.&lt;/p&gt;
    	&lt;!-- begin subscription_form_widget.tmpl --&gt; 



 

    &lt;form action=&quot;http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi&quot; method=&quot;post&quot;&gt;

 

&lt;fieldset&gt;
&lt;legend&gt;
 Subscribe/Unsubscribe  on Mettle News
&lt;/legend&gt;

 
    

    &lt;input type=&quot;hidden&quot; name=&quot;list&quot; value=&quot;mettlenewsletter&quot; /&gt;


&lt;p&gt;
&lt;label for=&quot;email&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot; &gt;
Email&amp;nbsp;Address: 
&lt;/label&gt;
&lt;input type=&quot;text&quot; name=&quot;email&quot; id=&quot;email&quot; value=&quot;&quot; /&gt; &lt;span class=&quot;error&quot;&gt;* Required&lt;/span&gt;
&lt;/p&gt;

 

    &lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

     
    
        &lt;p&gt;
        &lt;label for=&quot;name&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
        Name: 
        &lt;/label&gt;
        &lt;input type=&quot;text&quot; name=&quot;name&quot; id=&quot;name&quot; value=&quot;&quot;  /&gt;
        &lt;/p&gt;
    
    
     

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

 
    &lt;p&gt;
    &lt;label for=&quot;f_s&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
    Subscribe
    &lt;/label&gt;
    &lt;input type=&quot;radio&quot; name=&quot;f&quot; id=&quot;f_s&quot; value=&quot;subscribe&quot; checked=&quot;checked&quot; /&gt;
    &lt;/p&gt; 
    
    &lt;p&gt; 
    &lt;label for=&quot;f_u&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;Unsubscribe&lt;/label&gt; 
    &lt;input type=&quot;radio&quot; name=&quot;f&quot;  id=&quot;f_u&quot;  value=&quot;unsubscribe&quot;  /&gt;
    &lt;/p&gt;   

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

&lt;p style=&quot;text-align:right;display:block&quot;&gt;
&lt;input type=&quot;submit&quot; value=&quot;Submit Your Information&quot; class=&quot;processing&quot; /&gt;
&lt;/p&gt; 


 

    &lt;p style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;&lt;a href=&quot;http://dadamailproject.com&quot; target=&quot;_blank&quot; style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;Powered by Dada Mail 3.0.0 Mailing List Manager&lt;/a&gt;&lt;/p&gt;

 




&lt;/fieldset&gt;
&lt;/form&gt; 



  
&lt;!-- end subscription_form_widget.tmpl --&gt; 
     
    </content>
  </entry>

 

  <entry>
    <title>Mettle News May 2009</title>
    <link rel="alternate" href="http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi/archive/mettlenewsletter/20090515083711/"/>
    <id>tag:newsletter.mettlenetworks.com,2009-05-15:%2Fcgi-bin%2Fmail.cgi%2Farchive%2Fmettlenewsletter%2F20090515083711%2F</id>
    
    <published>2009-05-15T08:37:11Z</published>
    <updated>2009-05-15T08:37:11Z</updated>
    <content type="html">&lt;p&gt;&lt;br /&gt;
&lt;br /&gt;
METTLE NEWS&lt;br /&gt;
[News letter on Mettle(tm) brand of products; Industry updates, Tips and Case&lt;br /&gt;
studies]&lt;br /&gt;
&lt;br /&gt;
May 2009&lt;br /&gt;
Volume 2, Issue 5&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In this issue:&lt;br /&gt;
&lt;br /&gt;
 * Editorial&lt;br /&gt;
 * IT industry news: Mega Botnet Discovered *&lt;br /&gt;
 * Mettle SE feature: Port Forwarding *&lt;br /&gt;
 * Tip of the month: Package Updates *&lt;br /&gt;
 * Case study: Mettle SE at a prestigious private engineering college *&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Editorial *&lt;br /&gt;
&lt;br /&gt;
Greetings,&lt;br /&gt;
&lt;br /&gt;
Welcome to another edition of Mettle News!&lt;br /&gt;
&lt;br /&gt;
Bots are software robots, which are usually part of a large network of bots, which infect&lt;br /&gt;
a computer and lets the botnet controller to control the PC remotely. This month's&lt;br /&gt;
industry news is about a extensive botnet which has infected atleast 1.95 million PCs&lt;br /&gt;
around the world.&lt;br /&gt;
&lt;br /&gt;
In this edition of Mettle News we will familiarise you with Mettle SE's Port Forwarding&lt;br /&gt;
feature. Port forwarding makes a specified port of a computer inside LAN accessible to a&lt;br /&gt;
user from a public network. Tip section explains the process of updating installed&lt;br /&gt;
packages in Mettle SE as and when updates are available.&lt;br /&gt;
&lt;br /&gt;
This edition of Mettle News brings you the case study of the deployment of Mettle SE at a&lt;br /&gt;
famous private Engineering college at Kanjirapally, Kottayam. Mettle SE helped the college&lt;br /&gt;
streamline and manage their IT operations and computer lab facilities for engineering&lt;br /&gt;
students.&lt;br /&gt;
&lt;br /&gt;
Shoot us your comments and feedback as usual!&lt;br /&gt;
&lt;br /&gt;
Yours truly,&lt;br /&gt;
&lt;br /&gt;
Editor, Mettle News&lt;br /&gt;
(&lt;a href=&quot;mailto:&amp;#109;&amp;#101;&amp;#x74;&amp;#116;&amp;#108;&amp;#x65;&amp;#x6E;&amp;#x65;&amp;#119;&amp;#115;&amp;#x40;&amp;#x6D;&amp;#x65;&amp;#116;&amp;#116;&amp;#x6C;&amp;#x65;&amp;#x2E;&amp;#x69;&amp;#110;&quot;&gt;&amp;#109;&amp;#101;&amp;#x74;&amp;#116;&amp;#108;&amp;#x65;&amp;#x6E;&amp;#x65;&amp;#119;&amp;#115;&amp;#x40;&amp;#x6D;&amp;#x65;&amp;#116;&amp;#116;&amp;#x6C;&amp;#x65;&amp;#x2E;&amp;#x69;&amp;#110;&lt;/a&gt;)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Industry News: Mega botnet discovered *&lt;br /&gt;
&lt;br /&gt;
At least 1.95 million computers world wide have come under undetected control of a newly&lt;br /&gt;
discovered mega botnet. The discovery was made by researchers at Finjan Internet Security&lt;br /&gt;
Company based in San Jose, CA. Finjan, noted on its blog that the number of infected&lt;br /&gt;
computers it detects is rising every year. Only four out of 39 antivirus products it&lt;br /&gt;
tested were able to detect the bots.&lt;br /&gt;
&lt;br /&gt;
Botnet is a term for a collection of codes referred as software robots, or bots, which run&lt;br /&gt;
autonomously and automatically. The term is often associated with malicious software but&lt;br /&gt;
it can also refer to the network of computers using distributed computing software. While&lt;br /&gt;
the term &amp;#34;botnet&amp;#34; can be used to refer to any group of bots, this word is generally used&lt;br /&gt;
to refer to a collection of compromised computers (called Zombie computers), under a&lt;br /&gt;
common command-and-control center, running malicious software usually installed via worms,&lt;br /&gt;
Trojan horses, or backdoors. The largest known botnet, Conficker, has infected over 10&lt;br /&gt;
million computers.&lt;br /&gt;
&lt;br /&gt;
The new botnet has infected machines from approximately 77 govt owned domains out of which&lt;br /&gt;
51 are US government domains. Finjan revealed that the Botnet is controlled by a 6 member&lt;br /&gt;
hacker group based out of Ukraine. Around 45 percent of the bots are in the U.S., and the&lt;br /&gt;
machines are Windows XP. Nearly 80 percent run Internet Explorer; 15 percent, Firefox; 3&lt;br /&gt;
percent, Opera; and 1 percent Safari. Finjan says the bots were found in banks, large&lt;br /&gt;
corporations and as well as consumer machines.&lt;br /&gt;
&lt;br /&gt;
Aside from its massive size and scope, what is also striking about the botnet is what its&lt;br /&gt;
malware can do to an infected machine. The bot malware lets an attacker read the victim's&lt;br /&gt;
email, communicate via HTTP in the botnet, inject code into other processes, visit&lt;br /&gt;
Websites without the user knowing, and register as a background service on the infected&lt;br /&gt;
machine, for instance. The bots communicate with their command and control systems via&lt;br /&gt;
HTTP.&lt;br /&gt;
&lt;br /&gt;
It appears that the botnet operators may be buying and selling bots or portions of their&lt;br /&gt;
botnet based on a communique Finjan discovered on an underground black-hat hacker forum in&lt;br /&gt;
Russia.&lt;br /&gt;
&lt;br /&gt;
For further reading please check the link below:&lt;br /&gt;
&lt;a href=&quot;http://www.finjan.com/MCRCblog.aspx?EntryId=2237&quot;&gt;http://www.finjan.com/MCRCblog.aspx?EntryId=2237&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* A Mettle SE feature: Port Forwarding *&lt;br /&gt;
&lt;br /&gt;
Port forwarding, sometimes referred to as port mapping, is the act of forwarding an&lt;br /&gt;
external network address and port to an internal network address and port. When you have&lt;br /&gt;
port forwarding rules set up, Mettle SE takes the data off of the external IP address:port&lt;br /&gt;
number and sends that data to an internal IP address:port number. This technique can allow&lt;br /&gt;
an external user to reach a port on a private IP address (inside a LAN) from the outside&lt;br /&gt;
via a NAT-enabled router.&lt;br /&gt;
&lt;br /&gt;
Following instructions will help you set up a port forwarding rule in your Mettle SE.&lt;br /&gt;
&lt;br /&gt;
1. Go to Firewall --&amp;#62; NAT&lt;br /&gt;
2. Select the tab 'Port Forwarding'&lt;br /&gt;
3. Interface --&amp;#62; Choose the interface to use. Normally the WAN interface.&lt;br /&gt;
4. External Address --&amp;#62; Choose the external address to use for Port Forwarding. Choosing&lt;br /&gt;
   'Interface Address' will use the WAN IP address. To use a different public IP address&lt;br /&gt;
   create a Virtual IP address.&lt;br /&gt;
5. Protocol --&amp;#62; Choose the protocol, TCP/UDP in most cases.&lt;br /&gt;
6. External Port Range --&amp;#62; Give the external port range to be used. Use Alias feature if&lt;br /&gt;
   multiple ports are to be used.&lt;br /&gt;
7. NAT IP --&amp;#62; Enter the LAN IP address which is the target IP address for port forwarding.&lt;br /&gt;
8. Local Port --&amp;#62; Enter the port which is the port forwarding target port of the LAN&lt;br /&gt;
   computer. Usually this is the same port as the external port.&lt;br /&gt;
9. Description --&amp;#62; Enter a description for this port forwarding rule.&lt;br /&gt;
10. Tick the check box which says 'Auto-add a firewall rule to permit traffic through this&lt;br /&gt;
    NAT rule'.&lt;br /&gt;
11. Click on Save and Apply Changes.&lt;br /&gt;
&lt;br /&gt;
If your ISP has allocated you with a block of IP addresses you can use a different public&lt;br /&gt;
IP address from that block instead of your WAN IP address for Port Forwarding. This way&lt;br /&gt;
you don't have to reveal the actual WAN IP address of Mettle SE to port forward users. For&lt;br /&gt;
doing that you need to define a virtual IP address in Mettle SE.&lt;br /&gt;
&lt;br /&gt;
KB article for port forwarding: &lt;a href=&quot;http://kb.mettle.in/entry/20/&quot;&gt;http://kb.mettle.in/entry/20/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Tip of the month: Package Updates *&lt;br /&gt;
&lt;br /&gt;
Updates are made available to packages running inside Mettle SE on a periodic basis. To&lt;br /&gt;
update the packages installed in Mettle SE follow the steps below.&lt;br /&gt;
&lt;br /&gt;
1. Go to System --&amp;#62; Packages&lt;br /&gt;
2. To see the installed packages click the tab 'Installed Packages'.&lt;br /&gt;
3. There will be three buttons next to each installed package - 'x' to remove that&lt;br /&gt;
   package, 'pkg' to re-install the package and 'xml' to re-install the GUI components of&lt;br /&gt;
   the package.&lt;br /&gt;
4. In the column marked 'Package Version' you can see the version number of the latest&lt;br /&gt;
   available package and the installed package.&lt;br /&gt;
5. To update a package click on the 'pkg' button.&lt;br /&gt;
&lt;br /&gt;
KB article is here: &lt;a href=&quot;http://kb.mettle.in/entry/45/&quot;&gt;http://kb.mettle.in/entry/45/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Case Study: Mettle SE at a prestigious private engineering college *&lt;br /&gt;
&lt;br /&gt;
Vertical: Education/Campus&lt;br /&gt;
Geography: Kottayam, Kerala&lt;br /&gt;
&lt;br /&gt;
Client Profile:&lt;br /&gt;
&lt;br /&gt;
Our client featured in this month's Mettle SE case study is one of the very prestigious&lt;br /&gt;
private engineering colleges in Kerala. Located at Kanjirapally, Kottayam is a large&lt;br /&gt;
complex with a built up area of around 6lac square feet on the Kanjirapally - Sabarimala&lt;br /&gt;
state highway. The engineering college has nine departments and provide higher education&lt;br /&gt;
in domains of Electrical, Electronics, Computer Science, Information Technology,&lt;br /&gt;
Mechanical and Civil. Students are provided with a large computer lab facility and is&lt;br /&gt;
allowed free Internet access inside the campus. The college is one of the first private&lt;br /&gt;
engineering colleges in Kerala to be accredited by AICTE.&lt;br /&gt;
&lt;br /&gt;
Problems:&lt;br /&gt;
&lt;br /&gt;
College LAN subnets are not secured from Virus attacks from the Internet as they don't&lt;br /&gt;
have Gateway Antivirus installed in their network. Content Filtering is to be implemented&lt;br /&gt;
to filter out offensive content as a part of the acceptable usage policy laid down by the&lt;br /&gt;
management. Students Internet access needs to be controlled and time wasting services&lt;br /&gt;
like Orkut and chat should be banned. Internet access log needs to be maintained for the&lt;br /&gt;
campus. College requires a WAN link management solution for implementing a failover link&lt;br /&gt;
for the Internet. Access to other subnets should be restricted for some users, whereas few&lt;br /&gt;
privileged users should be able to access hosts on other subnets.&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
A Mettle SE 3700 was deployed at the campus to handle their total IT infrastructure.&lt;br /&gt;
Solutions built up with Mettle SE are classified into the following sections:&lt;br /&gt;
&lt;br /&gt;
 a. Redundant WAN link with failover&lt;br /&gt;
 b. Firewalling &amp;#38; Routing&lt;br /&gt;
 c. Content Scanning &amp;#38; Gateway Antivirus&lt;br /&gt;
&lt;br /&gt;
a. Redundant WAN link with failover&lt;br /&gt;
&lt;br /&gt;
College is served by two different ISP links so as to provide a stable Internet connection&lt;br /&gt;
with failover. Both WAN links are of different bandwidth, one is a very high bandwidth&lt;br /&gt;
link and the other is a relatively lower throughput link. Both links are terminated at&lt;br /&gt;
Mettle SE. Due to unequal bandwidth available for the campus Mettle SE has configured the&lt;br /&gt;
links to be in failover mode. The primary WAN uplink is the one with the higher bandwidth&lt;br /&gt;
and the secondary failover link duty is assigned to the link with lower bandwidth. Such a&lt;br /&gt;
setup has been implemented at the campus to provide best browsing speeds to web users&lt;br /&gt;
since all Internet traffic will be sent via the higher bandwidth link. If the high&lt;br /&gt;
bandwidth link goes down at the ISP's end, Mettle SE will switch over to the backup WAN&lt;br /&gt;
uplink. Browsing speed will be comparatively lower while the main link is down but still&lt;br /&gt;
Mettle SE keeps the campus connected to the Internet. Once the primary WAN link is up&lt;br /&gt;
Mettle SE will automatically switch over to it.&lt;br /&gt;
&lt;br /&gt;
b. Firewalling &amp;#38; Routing&lt;br /&gt;
&lt;br /&gt;
College campus LAN is divided into 4 different subnets based on their needs and&lt;br /&gt;
activities. The firewall engine in Mettle SE secure each local subnet from unauthorised&lt;br /&gt;
access from other subnets and from the Internet. Inter LAN routing enables authorised&lt;br /&gt;
users from other LAN subnets access to hosts in another subnets. One of the prime&lt;br /&gt;
requirements of our client was to prohibit students from using chat services in college&lt;br /&gt;
campus, to accomplish this the Firewall blocks access to the ports and IP addresses of the&lt;br /&gt;
most commonly used chat servers of the most popular chat services. It is implemented in a&lt;br /&gt;
manner that does not restrict the users from checking their webmail accounts but will&lt;br /&gt;
prohibit the chat service from working.&lt;br /&gt;
&lt;br /&gt;
c. Content Scanning &amp;#38; Gateway Antivirus&lt;br /&gt;
&lt;br /&gt;
As an educational institution responsible for the activities of it's students it was in&lt;br /&gt;
their agenda to block certain web services and web resources available on the Internet.&lt;br /&gt;
Such a policy decision has been taken by the management for the benefit and the betterment&lt;br /&gt;
of their students. It was decided by the management that certain groups of users should&lt;br /&gt;
have an unfiltered access to the Internet and while certain other user groups should have&lt;br /&gt;
limited filtered access to the Internet.&lt;br /&gt;
&lt;br /&gt;
To help implement this access policy, different groups of users are created in Mettle SE&lt;br /&gt;
and users are added into these groups based on their IP addresses. Each group has a set of&lt;br /&gt;
filter rules associated with them. Internet content is served to the users in the&lt;br /&gt;
respective groups according to the filter rules set for each group. Students are put in&lt;br /&gt;
the filtered group where objectionable content is blocked. Mettle SE provides the system&lt;br /&gt;
administrator with a detailed web usage report containing the websites visited and amount&lt;br /&gt;
of data downloaded by a user, identified by the IP address, for each date in a neat&lt;br /&gt;
tabular form.&lt;br /&gt;
&lt;br /&gt;
To further secure the campus LAN subnets from Internet borne threats and viruses, Mettle&lt;br /&gt;
SE with its in built antivirus engine actively monitors the content passing through&lt;br /&gt;
the gateway. Virus codes and other threats are identified and blocked from gaining access&lt;br /&gt;
to host machines inside campus LAN subnets. The virus definition database in Mettle SE is&lt;br /&gt;
always kept updated by Mettle SE automatically.&lt;br /&gt;
&lt;br /&gt;
Mettle SE team is happy to report that the Mettle SE 3700 deployed at the campus has been&lt;br /&gt;
working flawlessly ever since meeting the needs of the college management and the system&lt;br /&gt;
administrators.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
We would like to receive feedback regarding the content of this newsletter and&lt;br /&gt;
request for articles. Please send in your valuable suggestions to&lt;br /&gt;
&lt;a href=&quot;mailto:&amp;#109;&amp;#101;&amp;#x74;&amp;#116;&amp;#108;&amp;#x65;&amp;#x6E;&amp;#x65;&amp;#119;&amp;#115;&amp;#x40;&amp;#x6D;&amp;#x65;&amp;#116;&amp;#116;&amp;#x6C;&amp;#x65;&amp;#x2E;&amp;#x69;&amp;#110;&quot;&gt;&amp;#109;&amp;#101;&amp;#x74;&amp;#116;&amp;#108;&amp;#x65;&amp;#x6E;&amp;#x65;&amp;#119;&amp;#115;&amp;#x40;&amp;#x6D;&amp;#x65;&amp;#116;&amp;#116;&amp;#x6C;&amp;#x65;&amp;#x2E;&amp;#x69;&amp;#110;&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
Mettle and Linuxense are trademarks of Linuxense Information Systems Pvt. Ltd.&lt;br /&gt;
Other trademarks belong to respective owners. 2008 (C) Linuxense Information&lt;br /&gt;
Systems Pvt. Ltd. All rights reserved.&lt;/p&gt;
    	&lt;!-- begin subscription_form_widget.tmpl --&gt; 



 

    &lt;form action=&quot;http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi&quot; method=&quot;post&quot;&gt;

 

&lt;fieldset&gt;
&lt;legend&gt;
 Subscribe/Unsubscribe  on Mettle News
&lt;/legend&gt;

 
    

    &lt;input type=&quot;hidden&quot; name=&quot;list&quot; value=&quot;mettlenewsletter&quot; /&gt;


&lt;p&gt;
&lt;label for=&quot;email&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot; &gt;
Email&amp;nbsp;Address: 
&lt;/label&gt;
&lt;input type=&quot;text&quot; name=&quot;email&quot; id=&quot;email&quot; value=&quot;&quot; /&gt; &lt;span class=&quot;error&quot;&gt;* Required&lt;/span&gt;
&lt;/p&gt;

 

    &lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

     
    
        &lt;p&gt;
        &lt;label for=&quot;name&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
        Name: 
        &lt;/label&gt;
        &lt;input type=&quot;text&quot; name=&quot;name&quot; id=&quot;name&quot; value=&quot;&quot;  /&gt;
        &lt;/p&gt;
    
    
     

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

 
    &lt;p&gt;
    &lt;label for=&quot;f_s&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
    Subscribe
    &lt;/label&gt;
    &lt;input type=&quot;radio&quot; name=&quot;f&quot; id=&quot;f_s&quot; value=&quot;subscribe&quot; checked=&quot;checked&quot; /&gt;
    &lt;/p&gt; 
    
    &lt;p&gt; 
    &lt;label for=&quot;f_u&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;Unsubscribe&lt;/label&gt; 
    &lt;input type=&quot;radio&quot; name=&quot;f&quot;  id=&quot;f_u&quot;  value=&quot;unsubscribe&quot;  /&gt;
    &lt;/p&gt;   

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

&lt;p style=&quot;text-align:right;display:block&quot;&gt;
&lt;input type=&quot;submit&quot; value=&quot;Submit Your Information&quot; class=&quot;processing&quot; /&gt;
&lt;/p&gt; 


 

    &lt;p style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;&lt;a href=&quot;http://dadamailproject.com&quot; target=&quot;_blank&quot; style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;Powered by Dada Mail 3.0.0 Mailing List Manager&lt;/a&gt;&lt;/p&gt;

 




&lt;/fieldset&gt;
&lt;/form&gt; 



  
&lt;!-- end subscription_form_widget.tmpl --&gt; 
     
    </content>
  </entry>

 

  <entry>
    <title>Mettle News April 2009</title>
    <link rel="alternate" href="http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi/archive/mettlenewsletter/20090415143641/"/>
    <id>tag:newsletter.mettlenetworks.com,2009-04-15:%2Fcgi-bin%2Fmail.cgi%2Farchive%2Fmettlenewsletter%2F20090415143641%2F</id>
    
    <published>2009-04-15T14:36:41Z</published>
    <updated>2009-04-15T14:36:41Z</updated>
    <content type="html">&lt;p&gt;&lt;br /&gt;
&lt;br /&gt;
METTLE NEWS&lt;br /&gt;
[News letter on Mettle(tm) brand of products; Industry updates, Tips and Case&lt;br /&gt;
studies]&lt;br /&gt;
&lt;br /&gt;
April 2009&lt;br /&gt;
Volume 2, Issue 4&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In this issue:&lt;br /&gt;
&lt;br /&gt;
 * Editorial&lt;br /&gt;
 * IT industry news: Routers owned by Botnet *&lt;br /&gt;
 * Mettle SE feature: Packet Capture *&lt;br /&gt;
 * Tip of the month: Traceroute *&lt;br /&gt;
 * Case study: Mettle SE at Kerala's leading share broking company *&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Editorial *&lt;br /&gt;
&lt;br /&gt;
Greetings,&lt;br /&gt;
&lt;br /&gt;
This is the first time Internet sees the break out of a worm that is targeted to routers&lt;br /&gt;
and DSL modems. This pose a very different type of security issues. This month's industry&lt;br /&gt;
news explains the story of &amp;#34;psyb0t&amp;#34;.&lt;br /&gt;
&lt;br /&gt;
Case study of the month explains how a stock broking company owned by Kerala-based&lt;br /&gt;
conglomerate built their IT infrastructure around Mettle SE. This is yet another success&lt;br /&gt;
story of Mettle SE in the Financial Services sector.&lt;br /&gt;
&lt;br /&gt;
Regular &amp;#34;Tip of the month&amp;#34; and &amp;#34;Feature of the month&amp;#34; columns included with information&lt;br /&gt;
useful for day-to-day practice.&lt;br /&gt;
&lt;br /&gt;
As usual, we request you to continue sending your feedback which help us to improve this&lt;br /&gt;
newsletter.&lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;
Yours truly,&lt;br /&gt;
Editor, Mettle News&lt;br /&gt;
(&lt;a href=&quot;mailto:&amp;#x6D;&amp;#x65;&amp;#116;&amp;#x74;&amp;#108;&amp;#x65;&amp;#110;&amp;#101;&amp;#119;&amp;#115;&amp;#x40;&amp;#x6D;&amp;#x65;&amp;#116;&amp;#116;&amp;#108;&amp;#101;&amp;#46;&amp;#105;&amp;#x6E;&quot;&gt;&amp;#x6D;&amp;#x65;&amp;#116;&amp;#x74;&amp;#108;&amp;#x65;&amp;#110;&amp;#101;&amp;#119;&amp;#115;&amp;#x40;&amp;#x6D;&amp;#x65;&amp;#116;&amp;#116;&amp;#108;&amp;#101;&amp;#46;&amp;#105;&amp;#x6E;&lt;/a&gt;)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Industry News: Routers Owned by Botnet *&lt;br /&gt;
&lt;br /&gt;
Security researchers at DroneBL have spotted a stealthy router-based botnet worm targeting&lt;br /&gt;
Routers and DSL modems. The worm, called &amp;#34;psyb0t&amp;#34;, has been circulating since at least&lt;br /&gt;
January this year, infecting vulnerable embedded Linux mipsel devices. Once the malware&lt;br /&gt;
takes hold, it locks legitimate users out of the device by blocking telnet, sshd, and web&lt;br /&gt;
access. It then makes the devices part of a botnet. The researchers said they first&lt;br /&gt;
learned of the worm while investigating DDoS attacks that hit DroneBL's infrastructure two&lt;br /&gt;
weeks ago.&lt;br /&gt;
&lt;br /&gt;
The &amp;#34;psyb0t&amp;#34; worm is believed to be the first piece of malware to target home networking&lt;br /&gt;
gear. It has already infiltrated an estimated 100,000 hosts. According to DroneBL, the&lt;br /&gt;
worm can infect any Linux mipsel routing device (including openwrt/dd-wrt devices)&lt;br /&gt;
configured with a weak username/password and has a router administration interface or sshd&lt;br /&gt;
or telnetd in a DMZ. It has been used to carry out DDoS, or distributed denial of service,&lt;br /&gt;
attacks and is also believed to use deep-packet inspection to harvest user names and&lt;br /&gt;
passwords. The worm also helps to identify exploitable phpMyAdmin and MySQL servers.&lt;br /&gt;
&lt;br /&gt;
DroneBL researchers in their blog says, &amp;#34;This technique is one to be extremely concerned&lt;br /&gt;
about because most end users will not know their network has been hacked, or that their&lt;br /&gt;
router is exploited,&amp;#34;. &amp;#34;This means that in the future, this could be an attack vector for&lt;br /&gt;
the theft of personally identifying information. This technique is not going away.&amp;#34;&lt;br /&gt;
&lt;br /&gt;
Below listed are few peculiar characteristics of psyb0t worm:&lt;br /&gt;
&lt;br /&gt;
 * It is the first botnet worm to target routers and DSL modems&lt;br /&gt;
 * It contains shellcode for many mipsel devices&lt;br /&gt;
 * It is not targeting PCs or servers&lt;br /&gt;
 * It uses multiple strategies for exploitation, including brute force username and&lt;br /&gt;
   password combinations&lt;br /&gt;
 * It can harvest user names and passwords through deep packet inspection&lt;br /&gt;
 * It can scan for exploitable phpMyAdmin and MySQL servers&lt;br /&gt;
&lt;br /&gt;
To disinfect the psyb0t worm, reset/power cycle your device, update to the latest&lt;br /&gt;
firmware, and use an unique admin user name with secure password to lock it down.&lt;br /&gt;
&lt;br /&gt;
Read more about psyb0t here &lt;a href=&quot;http://www.dronebl.org/blog/8&quot;&gt;http://www.dronebl.org/blog/8&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* A Mettle SE feature: Packet Capture *&lt;br /&gt;
&lt;br /&gt;
Packet Capture is a tool bundled with Mettle SE which will help the administrator to&lt;br /&gt;
better diagnose networking problems. With packet Capture Mettle SE administrators will be&lt;br /&gt;
able to diagnose connection issues by analysing packets captured with this tool. Packets&lt;br /&gt;
passing through specific interface to/from a particular IP address and/or port can be&lt;br /&gt;
filtered and captured for analysis. Using Packet Capture is simple but should you need&lt;br /&gt;
help, instructions below will help you.&lt;br /&gt;
&lt;br /&gt;
a) Go to Diagnostics --&amp;#62; Packet Capture&lt;br /&gt;
b) Interface --&amp;#62; From the drop down list you can choose the Interface on which the Packets&lt;br /&gt;
   are to be captured.&lt;br /&gt;
c) Host Address --&amp;#62; This value is either Source or Destination IP address. This allows you&lt;br /&gt;
   to capture packets addressed to or coming from a specific host.&lt;br /&gt;
d) Port --&amp;#62; The port can be either source or destination port. This allows you to capture&lt;br /&gt;
   packets intended for a specific port. If it is left blank packets to all ports would be&lt;br /&gt;
   captured.&lt;br /&gt;
e) Packet length --&amp;#62; The Packet length is the number of bytes packet capture will capture&lt;br /&gt;
   for each payload. For most scenarios default value would suffice.&lt;br /&gt;
f) Count --&amp;#62; This is the number of packets the packet capture will grab. Enter 0 for no&lt;br /&gt;
   count limit.&lt;br /&gt;
g) Level of Detail --&amp;#62; This is the level of detail that will be displayed after hitting&lt;br /&gt;
   'Stop' when the packets have been captured. This option does not affect the level of&lt;br /&gt;
   detail when downloading the packet capture. Choose from Normal, Medium, High or Full.&lt;br /&gt;
h) Reverse DNS Lookup --&amp;#62; This check box will cause the packet capture to perform a&lt;br /&gt;
   reverse DNS lookup associated with all IP addresses. This will slow down the packet&lt;br /&gt;
   capture because of DNS resolution time.&lt;br /&gt;
i) Start --&amp;#62; Click on Start Button to start Packet Capture process.&lt;br /&gt;
j) Download --&amp;#62; Captured packets will be downloaded into your computer as a &amp;#34;*.cap&amp;#34; file.&lt;br /&gt;
&lt;br /&gt;
The KB article can be found here &lt;a href=&quot;http://kb.mettle.in/entry/43/&quot;&gt;http://kb.mettle.in/entry/43/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Tip of the month: Traceroute *&lt;br /&gt;
&lt;br /&gt;
Traceroute is a network diagnostics utility used to determine the route taken by packets&lt;br /&gt;
across an IP network. By showing a list of routers traversed, it allows the user to&lt;br /&gt;
identify the path taken to reach a particular destination on the network. This can help&lt;br /&gt;
identify routing problems or firewalls that may be blocking access to a destination.&lt;br /&gt;
&lt;br /&gt;
a) Go to Diagnostics --&amp;#62; Traceroute&lt;br /&gt;
b) Host --&amp;#62; Enter the IP address or the fully qualified domain name of the target.&lt;br /&gt;
c) Maximum Number of Hops --&amp;#62; Enter the maximum number of hops allowed before the packet&lt;br /&gt;
   is dropped. Default is 18, maximum allowed is 64. If destination is not reached with in&lt;br /&gt;
   default number of hops you may increase the hop number.&lt;br /&gt;
d) Use ICMP --&amp;#62; Check the box to do ICMP traceroute. Default is UDP. If default traceroute&lt;br /&gt;
   doesn't take you to the destination, try with ICMP.&lt;br /&gt;
e) Traceroute --&amp;#62; Click on this button to begin traceroute.&lt;br /&gt;
&lt;br /&gt;
The KB article can be found at &lt;a href=&quot;http://kb.mettle.in/entry/44/&quot;&gt;http://kb.mettle.in/entry/44/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Case study: Mettle SE at Kerala's leading share broking company *&lt;br /&gt;
&lt;br /&gt;
Vertical: Financial, Shares&lt;br /&gt;
Geography: Pan India, HO at Cochin&lt;br /&gt;
&lt;br /&gt;
Our client is a major business house with pan-India presence and diverse products with a&lt;br /&gt;
thrust in the financial sector and share market. With the client's sustained efforts to&lt;br /&gt;
emerge as a financial supermarket for its diverse customers, the group now makes its foray&lt;br /&gt;
into securities trading space making it a natural progression on the company's substantial&lt;br /&gt;
presence in  Wealth Management Services.&lt;br /&gt;
&lt;br /&gt;
The Group has emerged as one of the India's largest financial group of its kind with&lt;br /&gt;
business interests in Seventeen diverse fields, a network of over a thousand branches&lt;br /&gt;
nationwide, with more than Ten thousand employees serving millions of customers across the&lt;br /&gt;
country. The client with their pan-Indian presence and varied bouquet of products serves&lt;br /&gt;
over Forty thousand customers every day.&lt;br /&gt;
&lt;br /&gt;
The client's Corporate Head Office is the hub of all activities and coordinating things&lt;br /&gt;
that go on at different parts of the country. To provide high availability to their&lt;br /&gt;
services, provide security to their IT operations and make available the resources to&lt;br /&gt;
authorised users across the world, the following solutions were proposed.&lt;br /&gt;
&lt;br /&gt;
 * Link load balancing&lt;br /&gt;
 * Mettle SE active failover stack&lt;br /&gt;
 * Firewall &amp;#38; DMZ&lt;br /&gt;
 * Gateway Antivirus&lt;br /&gt;
 * Routing&lt;br /&gt;
 * VPN&lt;br /&gt;
 * NAT &amp;#38; PAT&lt;br /&gt;
&lt;br /&gt;
* Link Load Balancing&lt;br /&gt;
&lt;br /&gt;
To run a high availability network system it is mandatory to have a minimum of two WAN&lt;br /&gt;
links at the least. The corporate office has two WAN links provided by two different ISPs&lt;br /&gt;
and Mettle SEs job is to aggregate the links and provide a load balanced WAN link with&lt;br /&gt;
failover. If for any reason a WAN link goes down, Mettle SE re-routes the traffic via the&lt;br /&gt;
active WAN link, to provide access to the Internet. Total bandwidth would be reduced when&lt;br /&gt;
a link goes down but still the servers would be accessible.&lt;br /&gt;
&lt;br /&gt;
* Mettle SE active failover stack&lt;br /&gt;
&lt;br /&gt;
The client's business is focussed on money management, shares and finance, since this is&lt;br /&gt;
an ever changing market the systems should be up and running all the time so as to keep up&lt;br /&gt;
with the developments. For such a high availability requirement the client have chosen to&lt;br /&gt;
go with a high availability setup using two Mettle SE 3700. These two Mettle SE devices&lt;br /&gt;
are configured in an active/standby failover mode where one is the Master device and the&lt;br /&gt;
other a Slave device. If in the unlikely event that the master Mettle SE fails the slave&lt;br /&gt;
Mettle SE will take over and take care of the network without affecting work done by&lt;br /&gt;
users. This ensures that the computer network is up and running all the time without fail&lt;br /&gt;
even if a device fails.&lt;br /&gt;
&lt;br /&gt;
* Firewall &amp;#38; DMZ&lt;br /&gt;
&lt;br /&gt;
To provide optimum security to the host machines at the corporate office Mettle SE&lt;br /&gt;
implements a security barricade. Firewalling the private network which has the host&lt;br /&gt;
computers are placed helps keep the machines safe and secured. A DMZ also has been created&lt;br /&gt;
where all of their public access servers are kept. This setup allows servers in the DMZ to&lt;br /&gt;
service both internal and external network, while keeping the LAN safe from possible&lt;br /&gt;
threats from the Internet. Traffic into LAN and DMZ is monitored by Mettle SE allowing&lt;br /&gt;
traffic that is implicitly allowed by the firewall rules. This keeps out suspect and&lt;br /&gt;
unauthorised traffic out of the LAN. In the unlikely situation that security of DMZ is&lt;br /&gt;
breached, Mettle SE would keep the LAN and critical machines secured.&lt;br /&gt;
&lt;br /&gt;
* Gateway Antivirus&lt;br /&gt;
&lt;br /&gt;
The most common entry point for viruses into a corporate LAN is through the Internet. To&lt;br /&gt;
curb the virus infection on a LAN with Internet access it is ideal to implement a gateway&lt;br /&gt;
antivirus system that will detect, disinfect or quarantine a threat before it enters the&lt;br /&gt;
LAN. Mettle SE has such a gateway antivirus system built in. Mettle SE's Gateway antivirus&lt;br /&gt;
engine filters all viruses and worms that come from the Internet before it reach the LAN&lt;br /&gt;
subnet. Mettle SE's antivirus engine automatically keeps its virus definitions updated to&lt;br /&gt;
identify and quarantine even the latest virus that is out on the Internet. A huge risk of&lt;br /&gt;
virus infections of the host machines are thus protected by Mettle SE.&lt;br /&gt;
&lt;br /&gt;
* Routing&lt;br /&gt;
&lt;br /&gt;
Corporate office of the client has two local networks the LAN subnet and the DMZ subnet.&lt;br /&gt;
Routing is implemented in Mettle SE which enables the host machines placed in the LAN to&lt;br /&gt;
access the servers kept in DMZ. Routing is enabled for the VPN clients which will enable&lt;br /&gt;
the remote clients to gain access to the resources available in the corporate local&lt;br /&gt;
network.&lt;br /&gt;
&lt;br /&gt;
* VPN&lt;br /&gt;
&lt;br /&gt;
The corporate office uses PPTP VPN service provided by Mettle SE to help connect the road&lt;br /&gt;
warriors to office base. Other VPN services provided by Mettle SE are IPsec VPN and&lt;br /&gt;
OpenVPN, but the administrator have chosen to use PPTP because of it's user friendliness&lt;br /&gt;
and tight integration with Windows operating systems. Executives while on the move can now&lt;br /&gt;
connect to the corporate network from anywhere in the world from his/her Laptop. As the&lt;br /&gt;
clients connect to Mettle SE they are routed to the right part of the corporate network&lt;br /&gt;
that they are allowed to access. Accessing resources other than which is authorised by the&lt;br /&gt;
administrator is blocked by the firewall which ensures that the security is not&lt;br /&gt;
compromised.&lt;br /&gt;
&lt;br /&gt;
* 1to1 NAT and Port Forwarding&lt;br /&gt;
&lt;br /&gt;
Our client has servers which are hosted in the DMZ and they need to be available on the&lt;br /&gt;
Internet with it's own public IP address. Such servers which are hosted in the DMZ are&lt;br /&gt;
assigned with a public IP addresses using 1:1 NAT. In this scheme, each private host has a&lt;br /&gt;
direct and fixed mapping to a public IP address. Port forwarding allow remote computers to&lt;br /&gt;
connect to a specific computer within a private LAN. In Mettle SE port forwarding (PAT) is&lt;br /&gt;
enabled to allow an authorised user from the Internet to connect to a specific computer&lt;br /&gt;
within the private LAN for administrative purposes or special requirements. Port&lt;br /&gt;
forwarding transfers IP packets between the private IP addresses of the computer on a&lt;br /&gt;
particular port and a public IP address with a specific port. This ensures that a service&lt;br /&gt;
in the host computer can be accessed from the Internet but is secured.&lt;br /&gt;
&lt;br /&gt;
Mettle SE has proved its Mettle in demanding situations such as this; serving our client&lt;br /&gt;
reliably round the clock.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
We would like to receive feedback regarding the content of this newsletter and&lt;br /&gt;
request for articles. Please send in your valuable suggestions to&lt;br /&gt;
&lt;a href=&quot;mailto:&amp;#x6D;&amp;#x65;&amp;#116;&amp;#x74;&amp;#108;&amp;#x65;&amp;#110;&amp;#101;&amp;#119;&amp;#115;&amp;#x40;&amp;#x6D;&amp;#x65;&amp;#116;&amp;#116;&amp;#108;&amp;#101;&amp;#46;&amp;#105;&amp;#x6E;&quot;&gt;&amp;#x6D;&amp;#x65;&amp;#116;&amp;#x74;&amp;#108;&amp;#x65;&amp;#110;&amp;#101;&amp;#119;&amp;#115;&amp;#x40;&amp;#x6D;&amp;#x65;&amp;#116;&amp;#116;&amp;#108;&amp;#101;&amp;#46;&amp;#105;&amp;#x6E;&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
--&lt;br /&gt;
Mettle and Linuxense are trademarks of Linuxense Information Systems Pvt. Ltd.&lt;br /&gt;
Other trademarks belong to respective owners. 2008 (C) Linuxense Information&lt;br /&gt;
Systems Pvt. Ltd. All rights reserved.&lt;/p&gt;
    	&lt;!-- begin subscription_form_widget.tmpl --&gt; 



 

    &lt;form action=&quot;http://newsletter.mettlenetworks.com/cgi-bin/mail.cgi&quot; method=&quot;post&quot;&gt;

 

&lt;fieldset&gt;
&lt;legend&gt;
 Subscribe/Unsubscribe  on Mettle News
&lt;/legend&gt;

 
    

    &lt;input type=&quot;hidden&quot; name=&quot;list&quot; value=&quot;mettlenewsletter&quot; /&gt;


&lt;p&gt;
&lt;label for=&quot;email&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot; &gt;
Email&amp;nbsp;Address: 
&lt;/label&gt;
&lt;input type=&quot;text&quot; name=&quot;email&quot; id=&quot;email&quot; value=&quot;&quot; /&gt; &lt;span class=&quot;error&quot;&gt;* Required&lt;/span&gt;
&lt;/p&gt;

 

    &lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

     
    
        &lt;p&gt;
        &lt;label for=&quot;name&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
        Name: 
        &lt;/label&gt;
        &lt;input type=&quot;text&quot; name=&quot;name&quot; id=&quot;name&quot; value=&quot;&quot;  /&gt;
        &lt;/p&gt;
    
    
     

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

 
    &lt;p&gt;
    &lt;label for=&quot;f_s&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;
    Subscribe
    &lt;/label&gt;
    &lt;input type=&quot;radio&quot; name=&quot;f&quot; id=&quot;f_s&quot; value=&quot;subscribe&quot; checked=&quot;checked&quot; /&gt;
    &lt;/p&gt; 
    
    &lt;p&gt; 
    &lt;label for=&quot;f_u&quot; style=&quot;width: 7em;float: left;text-align: right;margin-right: 0.5em;display: block&quot;&gt;Unsubscribe&lt;/label&gt; 
    &lt;input type=&quot;radio&quot; name=&quot;f&quot;  id=&quot;f_u&quot;  value=&quot;unsubscribe&quot;  /&gt;
    &lt;/p&gt;   

 

&lt;hr style=&quot;border-top: 1px solid black;&quot; /&gt; 

&lt;p style=&quot;text-align:right;display:block&quot;&gt;
&lt;input type=&quot;submit&quot; value=&quot;Submit Your Information&quot; class=&quot;processing&quot; /&gt;
&lt;/p&gt; 


 

    &lt;p style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;&lt;a href=&quot;http://dadamailproject.com&quot; target=&quot;_blank&quot; style=&quot;font-size:10px;font-family:Verdana,Arial,sans-serif;&quot;&gt;Powered by Dada Mail 3.0.0 Mailing List Manager&lt;/a&gt;&lt;/p&gt;

 




&lt;/fieldset&gt;
&lt;/form&gt; 



  
&lt;!-- end subscription_form_widget.tmpl --&gt; 
     
    </content>
  </entry>

 


</feed> 

