<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Technical Insanity of JFINLEY</title>
	<atom:link href="http://www.jfinley.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.jfinley.com</link>
	<description>Just another TECH site</description>
	<lastBuildDate>Thu, 10 May 2012 18:41:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>ARP Cache Spoof detection in an appliance</title>
		<link>http://www.jfinley.com/2012/05/10/arp-cache-spoof-detection-in-an-appliance/</link>
		<comments>http://www.jfinley.com/2012/05/10/arp-cache-spoof-detection-in-an-appliance/#comments</comments>
		<pubDate>Thu, 10 May 2012 18:41:23 +0000</pubDate>
		<dc:creator>jfinley</dc:creator>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[arp]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.jfinley.com/?p=234</guid>
		<description><![CDATA[While slinking around on the Internet, I ran across this little appliance that shows to be a quick drop in solution. The device called &#8220;ArpDefender&#8221; can be found here and explained as: full-fledged LIDS (LAN IDS), tailored to what the best information security experts currently recommend for the LAN environment. ARPDefender serves to fill the [...]]]></description>
			<content:encoded><![CDATA[<p>While slinking around on the Internet, I ran across this little appliance that shows to be a quick drop in solution.  The device called &#8220;ArpDefender&#8221; can be found <a href="http://www.arpdefender.com/" title="http://www.arpdefender.com/" target="_blank">here</a> and explained as:</p>
<blockquote><p> full-fledged LIDS (LAN IDS), tailored to what the best information security experts currently recommend for the LAN environment. ARPDefender serves to fill the critical gaps left in your local network security by NIDS, HIDS, and NAC. Each ARPDefender unit reliably provides LAN security while allowing you to avoid false positive alerts.</p></blockquote>
<p>Check it out!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jfinley.com/2012/05/10/arp-cache-spoof-detection-in-an-appliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VMware Hacked; source code stolen?</title>
		<link>http://www.jfinley.com/2012/04/25/vmware-hacked-source-code-stolen/</link>
		<comments>http://www.jfinley.com/2012/04/25/vmware-hacked-source-code-stolen/#comments</comments>
		<pubDate>Wed, 25 Apr 2012 14:17:39 +0000</pubDate>
		<dc:creator>jfinley</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[source]]></category>
		<category><![CDATA[vmware]]></category>

		<guid isPermaLink="false">http://www.jfinley.com/?p=223</guid>
		<description><![CDATA[I am seeing reports from various sources that say VMware was hacked into and source code was stolen. Trying to confirm this. At any rate, make sure outside access to your VM Hosts are always challenged by VPN entry only. &#8211; Update: 4/25/12 Reported by TheHackerNews.com &#8211; Update: 4/27/12 PCMag has also weighed in on [...]]]></description>
			<content:encoded><![CDATA[<p>I am seeing reports from various sources that say VMware was hacked into and source code was stolen.  Trying to confirm this.  At any rate, make sure outside access to your VM Hosts are always challenged by VPN entry only.</p>
<p>&#8211; Update: 4/25/12 Reported by <a href="http://thehackernews.com/2012/04/vmware-source-code-leaked-by-anonymous.html" title="TheHackerNews.com" target="_blank">TheHackerNews.com</a></p>
<p>&#8211; Update: 4/27/12 PCMag has also weighed in on the breach.  VMware acknowledges hackers gain access, but is down playing the severity.  <a href="http://www.pcmag.com/article2/0,2817,2403626,00.asp" title="http://www.pcmag.com/article2/0,2817,2403626,00.asp" target="_blank">Read more here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jfinley.com/2012/04/25/vmware-hacked-source-code-stolen/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fortinet Wireless Webinar &#8211; interesting</title>
		<link>http://www.jfinley.com/2012/04/20/fortinet-wireless-webinar-interesting/</link>
		<comments>http://www.jfinley.com/2012/04/20/fortinet-wireless-webinar-interesting/#comments</comments>
		<pubDate>Fri, 20 Apr 2012 15:37:29 +0000</pubDate>
		<dc:creator>jfinley</dc:creator>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Wireless]]></category>
		<category><![CDATA[FortiAP]]></category>
		<category><![CDATA[fortinet]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://www.jfinley.com/?p=224</guid>
		<description><![CDATA[Attended a Fortinet Webinar on their Wireless initiative. Very interesting things coming soon, especially with FortiOS 5.0. Some features include: Bridging Client Side Wireless &#8211; traffic is not required to hit wireless controller if controller is remote Remote Wireless Controllers Receptionist Guest Provisioning The Receptionist Guest Provisioning and bridging local is something we could use [...]]]></description>
			<content:encoded><![CDATA[<p>Attended a Fortinet Webinar on their Wireless initiative.  Very interesting things coming soon, especially with FortiOS 5.0.  Some features include:</p>
<ol>
<li>Bridging</li>
<li>Client Side Wireless &#8211; traffic is not required to hit wireless controller if controller is remote</li>
<li>Remote Wireless Controllers</li>
<li>Receptionist Guest Provisioning</li>
</ol>
<p>The Receptionist Guest Provisioning and bridging local is something we could use today, but FortiOS is expected to be released summer 2012.  Can&#8217;t wait!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jfinley.com/2012/04/20/fortinet-wireless-webinar-interesting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Temporary outage&#8230;.  suuuurrray</title>
		<link>http://www.jfinley.com/2012/04/19/temporary-outage-suuuurrray/</link>
		<comments>http://www.jfinley.com/2012/04/19/temporary-outage-suuuurrray/#comments</comments>
		<pubDate>Fri, 20 Apr 2012 02:45:35 +0000</pubDate>
		<dc:creator>jfinley</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.jfinley.com/?p=220</guid>
		<description><![CDATA[A PHP update took place at my hoster causing some outage&#8230;.]]></description>
			<content:encoded><![CDATA[<p>A PHP update took place at my hoster causing some outage&#8230;.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jfinley.com/2012/04/19/temporary-outage-suuuurrray/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FlashBack Virus on MAC OSX</title>
		<link>http://www.jfinley.com/2012/04/11/flashback-virus-on-mac-osx/</link>
		<comments>http://www.jfinley.com/2012/04/11/flashback-virus-on-mac-osx/#comments</comments>
		<pubDate>Wed, 11 Apr 2012 22:04:52 +0000</pubDate>
		<dc:creator>jfinley</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[apple]]></category>

		<guid isPermaLink="false">http://www.jfinley.com/?p=217</guid>
		<description><![CDATA[As Apple begins to penetrate into Microsoft&#8217;s dominance on the desktop, more and more &#8220;bad&#8221; guys will begin writing software to infiltrate your MAC. The latest is one called FlashBack; linked here to Apple &#8211; . Kaspersky has a website to find &#038; detection if your MAC is infected. Kudo&#8217;s to them for providing this [...]]]></description>
			<content:encoded><![CDATA[<p>As Apple begins to penetrate into Microsoft&#8217;s dominance on the desktop, more and more &#8220;bad&#8221; guys will begin writing software to infiltrate your MAC.  The latest is one called FlashBack; linked here to Apple &#8211; <a href="http://support.apple.com/kb/HT5244" title="http://support.apple.com/kb/HT5244"></a>.</p>
<p>Kaspersky has a website to find &#038; detection if your MAC is infected.  Kudo&#8217;s to them for providing this free tool  <a href="http://www.flashbackcheck.com/">Click here for the link</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jfinley.com/2012/04/11/flashback-virus-on-mac-osx/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fortigate Uptime</title>
		<link>http://www.jfinley.com/2012/03/28/fortigate-uptime/</link>
		<comments>http://www.jfinley.com/2012/03/28/fortigate-uptime/#comments</comments>
		<pubDate>Thu, 29 Mar 2012 01:14:20 +0000</pubDate>
		<dc:creator>jfinley</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[fortinet]]></category>

		<guid isPermaLink="false">http://www.jfinley.com/?p=214</guid>
		<description><![CDATA[So I logged into a clients Fortigate and noticed the following below. I love uptime. Uptime 493 day(s) 2 hour(s) 23 min(s) System Time Wed Mar 28 21:04:23 2012 [Change]]]></description>
			<content:encoded><![CDATA[<p>So I logged into a clients Fortigate and noticed the following below.  I love uptime.</p>
<blockquote><p>Uptime	493 day(s) 2 hour(s) 23 min(s)<br />
System Time	Wed Mar 28 21:04:23 2012 [Change]</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.jfinley.com/2012/03/28/fortigate-uptime/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RFC 1918 &amp; IPSEC Tunnels</title>
		<link>http://www.jfinley.com/2012/03/05/rfc-1918-ipsec-tunnels/</link>
		<comments>http://www.jfinley.com/2012/03/05/rfc-1918-ipsec-tunnels/#comments</comments>
		<pubDate>Tue, 06 Mar 2012 02:41:48 +0000</pubDate>
		<dc:creator>jfinley</dc:creator>
				<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[RFC918]]></category>

		<guid isPermaLink="false">http://www.jfinley.com/?p=210</guid>
		<description><![CDATA[Do you add the necessary blocks for RFC 1918 on your EGRESSING ports? You should. Playing around the other day, I wanted to find out what would happen if taking a VPN route out. Using Route-Based IPSEC Tunnels on a Fortigate I placed a FW Policy with an address group on all internal -> egressing [...]]]></description>
			<content:encoded><![CDATA[<p>Do you add the necessary blocks for RFC 1918 on your EGRESSING ports?  You should.  Playing around the other day, I wanted to find out what would happen if taking a VPN route out.  Using Route-Based IPSEC Tunnels on a Fortigate I placed a FW Policy with an address group on all internal -> egressing interfaces; placed at the top.  I removed the static route, low and behold I see my counters going up on the DENY statement.  </p>
<p>Now, will your ISP deny or block RFC-1918 traffic, sure&#8230;but what about the bleeding traffic exiting &#8211; could it be recorded?  Sure&#8230;lesson?  Block RFC-1918 traffic exiting your WANS.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jfinley.com/2012/03/05/rfc-1918-ipsec-tunnels/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SSL Clients accessing remote networks</title>
		<link>http://www.jfinley.com/2012/02/04/ssl-clients-accessing-remote-networks/</link>
		<comments>http://www.jfinley.com/2012/02/04/ssl-clients-accessing-remote-networks/#comments</comments>
		<pubDate>Sat, 04 Feb 2012 23:06:20 +0000</pubDate>
		<dc:creator>jfinley</dc:creator>
				<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[vpn]]></category>

		<guid isPermaLink="false">http://www.jfinley.com/?p=205</guid>
		<description><![CDATA[Came across the need to allow SSL VPN clients access to remote networks beyond the SPOKE Firewall. In this instance, we have an IPSEC LAN-2-LAN VPN Tunnel between two points, we&#8217;ll use the name HQ &#038; Sister-Company. A remote user accessing the HQ Firewall needs access to the Sister-Company file server. Instead of configuring another [...]]]></description>
			<content:encoded><![CDATA[<p>Came across the need to allow SSL VPN clients access to remote networks beyond the SPOKE Firewall.  In this instance, we have an IPSEC LAN-2-LAN VPN Tunnel between two points, we&#8217;ll use the name HQ &#038; Sister-Company.  A remote user accessing the HQ Firewall needs access to the Sister-Company file server.  Instead of configuring another instance of a user on the Sister-Company firewall or another instance in the SSL VPN Client, we can allow access from the HQ Firewall.</p>
<p>HQ Fortigate LAN2LAN VPN MUST be configured in interface/route mode.  SSL_VPN clients connect to the HUB FGATE ie. HQ</p>
<p>FW-Policy(s):</p>
<p>* ssl.root:(source subnet) -> VPN_Interface:(destination subnet)<br />
* WAN:(source subnet) -> VPN_Interface:(destination subnet)  (ACTION) SSL-VPN (identify &#8220;interesting traffic&#8221; on the SSL Client.  Make sure to set the group access under this policy.</p>
<p>Route(s):</p>
<p>* Destination_Network:VPN_Interface</p>
<p>Connect using the SSL_Client and ping a host on the far side and see if your COUNT SEND/Receive increment with each ping on the SSL VPN Client.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jfinley.com/2012/02/04/ssl-clients-accessing-remote-networks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SOPA needs to be stopped</title>
		<link>http://www.jfinley.com/2012/01/14/sopa-needs-to-be-stopped/</link>
		<comments>http://www.jfinley.com/2012/01/14/sopa-needs-to-be-stopped/#comments</comments>
		<pubDate>Sat, 14 Jan 2012 22:29:30 +0000</pubDate>
		<dc:creator>jfinley</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[GOV]]></category>
		<category><![CDATA[SOPA]]></category>

		<guid isPermaLink="false">http://www.jfinley.com/?p=200</guid>
		<description><![CDATA[While I carry heavy conviction on politics, one area I do not like our US Gov involved in is the Internet. Stop Online Piracy Act is yet another intrusion into it&#8217;s citizens lives. You may hear this only affects non-citizens, think again. You give an inch, they, the US GOV will take more than a [...]]]></description>
			<content:encoded><![CDATA[<p>While I carry heavy conviction on politics, one area I do not like our US Gov involved in is the Internet.  Stop Online Piracy Act is yet another intrusion into it&#8217;s citizens lives.  You may hear this only affects non-citizens, think again.  You give an inch, they, the US GOV will take more than a mile.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jfinley.com/2012/01/14/sopa-needs-to-be-stopped/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FortiOS 4.3.4 is out</title>
		<link>http://www.jfinley.com/2012/01/14/fortios-4-3-4-is-out/</link>
		<comments>http://www.jfinley.com/2012/01/14/fortios-4-3-4-is-out/#comments</comments>
		<pubDate>Sat, 14 Jan 2012 22:25:49 +0000</pubDate>
		<dc:creator>jfinley</dc:creator>
				<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[fortinet]]></category>
		<category><![CDATA[fortios]]></category>

		<guid isPermaLink="false">http://www.jfinley.com/?p=198</guid>
		<description><![CDATA[Upgraded a test system to review the features/fixes, but it&#8217;s been getting some complaints from other admins that the IPSengine is consuming mass amounts of memory again. I&#8217;d recommend waiting for 4.3.5.]]></description>
			<content:encoded><![CDATA[<p>Upgraded a test system to review the features/fixes, but it&#8217;s been getting some complaints from other admins that the IPSengine is consuming mass amounts of memory again.  I&#8217;d recommend waiting for 4.3.5.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jfinley.com/2012/01/14/fortios-4-3-4-is-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

