Generated by All in One SEO v5.0.0.1, this is an llms.txt file, used by LLMs to index the site. # Booches.nl Connecting the world... ## Sitemaps - [XML Sitemap](https://www.booches.nl/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [ClearPass 6.12 EAP-TLS Authentication Issues – “No Suitable Signature Algorithm”](https://www.booches.nl/2026/02/clearpass-6-12-eap-tls-authentication-issues-no-suitable-signature-algorithm/) - After upgrading a ClearPass cluster from 6.11.11 to 6.12, multiple customers ran into an issue where a significant number of clients could no longer authenticate using EAP-TLS. The environment: Certificates distributed via Microsoft Intune WiFi profiles also deployed through Intune Clients previously authenticated without issues against ClearPass 6.11.11 Immediately after the upgrade to 6.12, authentication - [Aruba AOS 10 and Mesh Networking](https://www.booches.nl/2026/01/aruba-aos-10-and-mesh-networking/) - Mesh networking is not something you configure every day, but in certain scenarios it becomes the only viable solution. Typical reasons include locations where structured cabling is impossible, or—as in this case—when there is no physical connection available between two separate buildings. For this setup, I configured a dedicated AP group specifically for mesh access - [Deploy HPE 9106 gateways](https://www.booches.nl/2026/01/deploy-hpe-9106-gateways/) - Twice in the last couple of weeks I ran into issues while deploying HPE 9106 gateways with Central. In both cases, the gateways came out of the box running ArubaOS 8.13.1.0. I provisioned them using the enable-debug and static-activate commands. After configuring the required IP information, the gateway rebooted, contacted Activate and… nothing happened. The - [Troubleshooting: FortiGate and RADIUS](https://www.booches.nl/2025/12/troubleshooting-fortigate-and-radius/) - I recently encountered a strange case where RADIUS authentication on a FortiGate cluster was failing on the secondary node. The cluster uses multiple VDOMs configured in a vcluster, and each FortiGate has its own out-of-band management IP. Authentication had been working fine previously. On the secondary FortiGate, I enabled debugging to see if authentication requests - [Uninstalling the HPE Axis Connector on Ubuntu](https://www.booches.nl/2025/12/uninstalling-the-hpe-axis-connector-on-ubuntu/) - Why docker stop Fails (and how to fix it properly). At first glance, the HPE Axis Connector looks like a simple Docker-based agent. In reality, it installs a full local Kubernetes environment. This often causes confusion, especially during uninstallation. In this blog post I explain: Why the official HPE Axis uninstaller may report success but - [OpenSSL & Cygwin – Certificate Authority](https://www.booches.nl/2009/09/openssl-cygwin-certificate-authority/) - I am using OpenSSL in conjunction with Cygwin on my Windows laptop to generate Certificate Signing Request and other SSL certificate related issues. Today I configured my own Certificate Authority, using the following guideline. Preparations First I created some directories, like shown below: mkdir /home/sslCAcd /home/sslCAmkdir certs private newcerts Next I created a serial file - [MacOS Big Sur and SSLKEYFILELOG](https://www.booches.nl/2021/11/macos-big-sur-and-sslkeyfilelog/) - Today I had to decrypt SSL/TLS traffic from my browser. There are a lot of resource available to explain the steps necessary to capture traffic and decrypt the traffic, like How to Decrypt SSL with Wireshark – HTTPS Decryption Guide. However, I noticed that my ssl-keys.log file wasn't populated when starting Chrome of Firefox. The - [ClearPass, Azure AD, SSO and Object ID](https://www.booches.nl/2021/08/clearpass-azure-ad-sso-and-object-id/) - Single sign-on is nothing new and I am not going to tell you how to configure ClearPass to use SAML SSO with Azure AD. There is a lot of documentation available, like: Flomian Networking - ClearPass SSO with Azure ADClearPass Onboard Cloud Identity Providers This post is about an issue I was facing with the clearpass, azure, saml, sso, groups.link - [ClearPass - custom MPSK](https://www.booches.nl/2021/07/clearpass-custom-mpsk/) - Multiple PreShared Key (MPSK) is the ideal replace for the old-fashioned static PSK environments. MPSK provides the flexibility and scalability which traditional PSK networks are lacking. MPSK provides a per device pre shared key. Aruba ClearPass is the authentication server to verify the pre shared key entered on a device. To create a pre shared aruba, clearpass, mpsk, import, manual, psk - [Getting your AOS-CX switch in Central](https://www.booches.nl/2020/11/getting-your-aos-cx-switch-in-central/) - Everybody is talking about Cloud Management and since Aruba Central is upgraded to 2.5.2, there is the ability to manage your AOS-CX switch in Central via Template Groups. To get this done, it is necessary to get your switch connected to Central and this isn't always a matter of booting the switch, configure IP address, - [Cisco WLC - HA SSO upgrade](https://www.booches.nl/2017/02/cisco-wlc-ha-sso-upgrade/) - "Is the upgrade procedure for a high-availability pair of Cisco Wireless LAN Controllers the same as the procedure for a single Cisco WLC?" Several customers asked me this questions and the answer is YES. First you check the current and backup firmware image. (Cisco Controller) >show boot Primary Boot Image............................... 8.2.111.0 (default) (active) Backup Boot Image................................ - [phpIPAM - Azure and SAML authentication](https://www.booches.nl/2020/05/phpipam-azure-and-saml-authentication/) - What is easier than using your Azure credentials to log in to your web applications like phpIPAM? My daily job is networking, like routing, switching, wireless, and Wi-Fi, so I had to puzzle when I had to configure SAML2 authentication between phpIPAM and our company Azure infrastructure. I couldn't find a lot of information about - [User tunnel not operational](https://www.booches.nl/2020/01/user-tunnel-not-operation/) - HPE Aruba switches have the concept of user-based tunnelling. In short, the wired connections behave like a wireless connection. All traffic from the wired client is tunnelled to the central controller. This provides functions like central firewalling and micro-segmentation by blocking inter-user traffic. Yesterday I had a customer complaining that multiple clients weren't able to - [AOS - WireShark: remote capture](https://www.booches.nl/2019/10/aos-wireshark-remote-capture/) - AOS switches have the option to monitor / copy traffic from port A to port B. You also have the option to send the monitor traffic to a remote switch or even to a remote host. When the remote host is running WireShark, the monitored traffic can be analysed on the remote host. First you - [Migrate RAP from AOS 6.x to AOS 8.x](https://www.booches.nl/2019/05/migrate-rap-from-aos-6-x-to-aos-8-x/) - I guess something that many HPE Aruba wireless engineers have to do these days is migrating the "old" AOS 6.x environment to the new AOS 8.x with Mobility Masters. I am not going to explain what the differences between both are and what a Mobility Master does, but I have a tip when you need - [Downloadable User-Roles and NTP sync](https://www.booches.nl/2019/02/downloadable-user-roles-and-ntp-sync/) - The HPE Aruba switches have this cool feature called downloadable user-roles (DUR). DUR enables the switch to use a central ClearPass server to download user-roles to the switch for authenticated users. More and more customers want to implement wired authentication to strengthen the security level of their network. Via DUR the switches perform an HTTPS - [MacOS X](https://www.booches.nl/2019/02/macos-x/) - Useful things to know - [ClearPass - REST API](https://www.booches.nl/2018/06/clearpass-rest-api/) - Description: I created some Python scripts for ClearPass. The scripts can be found on Github. There are several directories: config: contains the parameters to authenticate against ClearPass and acquire an access token; general_scripts: some general configuration scripts, like a Password Generator script or Date/Time script; guests: scripts for adding or deleting guest accounts. I created a - [HPE AOS CLI command](https://www.booches.nl/2018/05/hpe-cli-command/) - Description: The script is used to execute a CLI command on one or multiple switches. The script use switches.txt as input file to login to one or multiple switches. When the scripts is executed the script asks for username and password and which command to execute. The status codes of the different sections is displayed - [FortiGate - OnDemand Token Timeout](https://www.booches.nl/2018/06/fortigate-ondemand-token-timeout/) - Today's customer is having a problem with OnDemand tokens on a FortiGate firewall. The FortiGate firewall uses RADIUS authentication for SSL VPN user authentication. FortiAuthenticator is used as RADIUS server. To strengthen the security levels, FortiAuthenticator is configured to demand two-factor authentication (2FA) for successful authentication. FortiAuthenticator has multiple options to demand 2FA from a - [Cygwin with OpenSSL for CSR generation](https://www.booches.nl/2008/09/cygwin-with-openssl-for-csr-generation/) - A lot of services, which are published to the Internet, are secured with SSL certificates. A lot of times we use SSL certificates to secure communications when implementing ISA reverse proxy servers, Citrix Secure Gateway servers and/or Cisco WebVPN portals. When you want to secure a connection with a SSL certificate you have to create - [FortiGate - backup via auto-script](https://www.booches.nl/2018/03/fortigate-backup-via-auto-script/) - One of the features I would like to see in a FortiGate is the ability to automatically create backups and copy them to offline storage. Of course, this can be accomplished by adding FortiManager to the solution, but why would I need FortiManager if I only have one FortiGate (cluster). Another option would be using scripts, - [Fortinet](https://www.booches.nl/2018/03/fortinet/) - FortiAnalyzer filter: policyid=: Search for policy ID in Log View, because Policy ID is not a standard filter FortiGate Config system auto-script: schedule and execute scripts, like automated backup Diagnose packet sniffer: Syntax to capture traffic from a network: diagnose sniffer packet any 'net 10.10.1.0/24' - [MobileIron - replace SSL certificate](https://www.booches.nl/2018/02/mobileiron-replace-ssl-certificate/) - Something completely different: changing the SSL certificate on MobileIron Core and Sentry. In total, I had to replace 5 certificates. 4 certificates are replaced via the Core web interface and 1 certificate needs to be replaced via the Sentry web interface. Core Within the Core web interface you have to change the certificated in two - [Problems provisioning AP324?](https://www.booches.nl/2018/01/problems-provisioning-ap324/) - I had to provision some AP324 APs on a standalone Aruba Mobility Controller. The controller runs AOS 8.2.0.2 code and functions as standalone controller. So what could be a problem when provisioning an AP324 via the GUI??? Well during the provisioning I couldn't choose the desired custom AP group. I can only choose from both - [Factory reset Mobility Controller managed by Mobility Master](https://www.booches.nl/2017/12/factory-reset-mobility-controller-managed-by-mobility-master/) - With the introduction of ArubaOS 8, HPE Aruba Networks introduced the Mobility Master appliance. A Mobility Master appliance takes care of all the control-plane features within your deployment. A Mobility Master provides better user experience, flexible deployment, simplified operations and enhanced performance. Mobility Controllers are added to the Mobility Master as regular controllers and all configuration for - [ClearPass and InTune Integration Guide](https://www.booches.nl/2017/12/clearpass-and-intune-integration-guide/) - Lately, I have been "playing" with the integration between ClearPass and Microsoft InTune. I found this very good integration guide at the AirHeads Community. I downloaded the Integration Guide and started clicking. In the end, I wasn't able to sync any attributes from InTune into the EndPoint database. I consulted Aruba TAC and they couldn't - [HPE switch and SSH filetransfer](https://www.booches.nl/2017/12/hpe-switch-and-ssh-filetransfer/) - Upgrading firmware on switches, routers and/or firewalls is a common task for network administrators. Normally I am used to downloading the new firmware from the console of the switch. I normally download the software from a (T)FTP server. While configuring a bunch of HPE 2930F switches for SSH access I noticed that I had the - [Aruba Airwave 8.2.4 and no CLI / shell access](https://www.booches.nl/2017/09/aruba-airwave-and-shell-access/) - BE AWARE: reading and applying this blog is at your own risk. Following the below procedure could affect the support validity on your Aruba AirWave appliance. All AirWave firmware versions prior to 8.2.4 gave you shell access to the CentOS operating system. Once you upgrade from 8.2.3 to 8.2.4 you receive the message that the - [ClearPass & Sophos Mobile Control](https://www.booches.nl/2017/08/clearpass-sophos-mobile-control/) - A lot of companies are using MDM to control and manage their (mobile) assets. By connecting the MDM solutions to HPE Aruba ClearPass an organization has the possibility for advanced context-aware access for a (mobile) device to the corporate network, wired and wireless. ClearPass supports multiple MDM solutions via built-in "External Context Servers", like Airwatch - [Cisco Catalyst 2960X keeps crashing](https://www.booches.nl/2017/07/cisco-catalyst-2960x-keeps-crashing/) - Yesterday evening I had to troubleshoot a Cisco Catalyst 2960X switch stack, which didn't return to normal after a reboot. The following error message was visible on the console: Error: ASIC/PHY POST failed. Cannot continue. %Software-forced reload This error message is listed as a bug (CSCut90593) at Cisco.com. Cisco describes a very "good" workaround: the switch - [AirWave & VMware Tools installation](https://www.booches.nl/2017/01/airwave-vmware-tools-installation/) - It is recommended to install the VMware Tools before running the AMP setup. After deploying the AMP ova file and starting the VM, you can interrupt the installation process via CTRL+C. This gives you access to the AMP shell. Use the following steps to install VMware Tools on a HPE Aruba AirWave Management Platform appliance: - [Useful command: netsh wlan](https://www.booches.nl/2015/10/useful-command-netsh-wlan/) - The management of wireless networks can be done via the Windows command "netsh wlan". This command is especially useful when using Windows 8. You can use other "netsh" subcommands to retrieve other system information, like "netsh lan" to get information about your Wired AutoConfig Service settings. The following table describes some options for "netsh wlan". Command - [Aruba ClearPass - Cisco Prime - TACACS+](https://www.booches.nl/2017/01/aruba-clearpass-cisco-prime-tacacs/) - When using Cisco Prime you have the option to configure authentication to a remote AAA server via RADIUS or TACACS+. Today I configured Cisco Prime to use HPE Aruba ClearPass as remote AAA server based on the TACACS+ protocol. The configuration of an AAA server in Cisco Prime is very straightforward. Configure the AAA Mode - [ClearPass - dual interface and routing](https://www.booches.nl/2017/02/clearpass-dual-interface-and-routing/) - When you are using both interfaces on a ClearPass server (MGMT and DATA) than ClearPass uses the DATA interface to connect to services, like LDAPS to Active Directory, SMTP delivery, Active Directory joining and more. ClearPass uses the DATA interface as default gateway if no specific route is available on the MGMT interface. That being - [Cisco FMC - Dashboard Widgets](https://www.booches.nl/2017/02/cisco-fmc-dashboard-widgets/) - Some widgets on the dashboard don't generate graphs after deploying a default configuration of Cisco FireSight Management Center. The first two widgets, Top Server Applications Seen and Top Operating Systems Seen, are generated after the configuration of a Network Discovery Profile. The configuration of the Network Discover Profile is done via Policies - Network Discovery - - [iPhone - Sleep Timer and playing music](https://www.booches.nl/2017/01/iphone-sleep-timer-and-playing-music/) - Something completely different in this blog post, so no technical stuff on networking. Last week I visited the Fortinet Global Partner Conference in Las Vegas, NV. Travelling from the Netherlands to Las Vegas and back in 5 days results in a big JET LAG for me!! Not only after the flight from the Netherlands to - [ClearPass & MobileIron - Error: not well-formed (invalid token)](https://www.booches.nl/2016/10/clearpass-mobileiron-error-not-well-formed-invalid-token/) - This post isn't going to describe what HPE Aruba ClearPass or MobileIron is. And neither will it describe the configuration steps necessary to add MobileIron to ClearPass, but I will give a short summary: Add the MobileIron VSP to ClearPass as Endpoint Context Server (CPPM - Administration - External Servers); The account on MobileIron needs - [FortiMail - Howto configure DLP](https://www.booches.nl/2016/10/fortimail-howto-configure-dlp/) - The previous post showed the steps necessary to enable DLP. This post describes the workflow to configure DLP. I needed DLP to relay outbound messages to a specific mail relay based on header information. At first I create a DLP rule to define the matching conditions. I match specific header information, which is added to a message - [FortiMail - Howto enable DLP](https://www.booches.nl/2016/10/fortimail-enable-dlp/) - FortiMail has the option to use Data Loss Prevention as enhanced security mechanism. This feature is introduced in firmware 5.3, according to the release notes. By default the DLP option is not visible on the GUI. DLP can be enabled via the CLI, but it is a well hidden feature. The option can be enabled - [ClearPass - concurrent session limit](https://www.booches.nl/2016/04/clearpass-concurrent-session-limit/) - I tried to configure a restriction to the concurrent number of active sessions a user can have on the wireless network. I found a great article on AirHeads Community "How to deny access for authentication requests based on session limit?" In short the article tells you to: Edit the Insight Repository Add more Filiters on - [SMTP Auth testing via CLI](https://www.booches.nl/2016/06/smtp-auth-testing-via-cli/) - Just a quick note to describe the procedure for SMTP auth testing via the command-line. At first you need to encode username and password in Base64. This can be done in several ways. The easiest way would be via https://www.base64encode.org/. Next you can use the following commando's via telnet to test SMTP AUTH. I always use - [Aruba: Split Tunnel with a RAP-5WN](https://www.booches.nl/2011/09/aruba-split-tunnel-with-a-rap-5wn/) - aruba,networks,rap5,rap5wn,split,tunnel,tunneling,session,user-role,user,profile,wired-ap-port,wired-ap-profile,ap-group - [AeroHive HMOL Redirector issue](https://www.booches.nl/2012/03/aerohive-hmol-redirector-issue/) - When using the HMOL solution from AeroHive, an access-point will discover the correct HiveManager by connecting to staging.aerohive.com. Within the HiveManager management interface you can see which access-points have been redirected to your HMOL. This can be down by checking the Device Access Control List within the Redirector configuration. Sometimes you will notice that not - [Aruba MAS - Tunneled node](https://www.booches.nl/2015/03/aruba-mas-tunneled-node/) - Today I played a bit with an Aruba Mobility Access Switch with Tunneled Node configuration to a Aruba Mobility Controller. More information on Tunneled Node can be found here. The configuration is straight forward. You need to configured a tunneled-node profile on the MAS and associate the access ports on the MAS to a VLAN, - [Flash clean-up](https://www.booches.nl/2015/12/flash-clean-up/) - Lately I upgraded a Aruba Networks wireless controller or at least I tried...... The upload of a new image to the controller has two steps. First the copy process from a TFTP server to the controller and second the actual writing of the new firmware image to flash (system partition). The second step kept showing - [ArubaOS 6.5.0.0](https://www.booches.nl/2016/06/arubaos-6-5-0-0/) - The Early Deployment release software from ArubaOS 6.5.0.0 has been released. I looked into the release notes and found some interesting new features. Cellular Handoff Assist is Configurable Per Virtual AP: The cellular handoff assist feature can help a dual-mode, 3G/4G-capable Wi-Fi device such as an iPhone, iPad, or Android client at the edge of - [FortiGate - IPSec with dynamic IP](https://www.booches.nl/2016/04/fortigate-ipsec-with-dynamic-ip/) - Site-to-site VPN connections are a common way to connect a branch office to the corporate network. In the Netherlands it is still common to have a internet connection at a branch office with a dynamic IP address. The usage of dynamic IP address is not ideal when configuring a site-to-site VPN connection, because the configuration almost always - [Cisco ASA: multiple context and capture](https://www.booches.nl/2016/04/cisco-asa-multiple-context-and-capture/) - Packet captures are very useful for troubleshooting purposes. The Cisco ASA supports packet captures even in multiple context mode. I normally configure packet captures on CLI level. This can be done by configuring an access-list to match the specific traffic you would like to capture. Add the access-list and the specific interface in a capture command. - [Cisco IOS-XE 16.x](https://www.booches.nl/2016/03/cisco-ios-xe-16-x/) - Cisco has release new IOS-XE software, called IOS-XE Denali 16.x. This software is available for Cisco ASR routers and Cisco Catalyst 3850/3650 switches. In the end IOS-XE Denali should be available for all switches. A good overview of Cisco Catalyst IOS XE Denali is explained in this Youtube video from Tech Field Day. Below you - [FortiClient SSLVPN - export profiles](https://www.booches.nl/2016/02/forticlient-sslvpn-export-profiles/) - I am using the FortiClient SSLVPN lightweight application for SSL VPN access to client networks. In the GUI you don't have options to export the configured profiles as you have with the full-featured FortiClient SSLVPN. The profiles for the lightweight version are stored in the registry, so you can export and import from there. The registry - [FortiAuthenticator - HA Clustering](https://www.booches.nl/2016/02/fortiauthenticator-ha-clustering/) - FortiAuthenticator can be used when adding strong authentication to a network. FortiAuthenticator has more options, like FSSO (FortiNet Single Sign-On) in conjuction with a FortiGate firewall. You can create a FortiAuthenticator cluster very easily. I normally configure a active/passive cluster and not a load-balancing cluster. When creating an active/passive cluster you should follow these guidelines: - [FortiGate - Outbound OSPF filtering](https://www.booches.nl/2015/11/fortigate-outbound-ospf-filtering/) - Just a quick post on filtering outbound OSPF advertisements. I had some struggle with this config today. config router prefix-list edit "filter-outbound" config rule edit 1 set prefix 10.10.0.0 255.255.0.0 unset ge unset le next edit 2 set prefix 10.20.0.0 255.255.0.0 unset ge unset le next edit 3 set action deny set prefix any - [NetScaler VPX - upgrade firmware](https://www.booches.nl/2015/10/netscaler-vpx-upgrade-firmware/) - Upgrade NetScaler VPX firmware via CLI - [NetScaler VPX - management certificate](https://www.booches.nl/2015/10/netscaler-vpx-management-certificate/) - I would like to upgrade my current NetScaler VPX Express configuration via GUI. For some security reason Internet Explorer and FireFox aren't able to access the GUI. They return the error message that the NetScaler is using a wrong SSL certificate. The default SSL self-signed certificate is installed on the appliance. I have uploaded a - [VMware: upgrade VMware Tools and Virtual Hardware for Microsoft ISA array](https://www.booches.nl/2010/06/vmware-upgrade-vmware-tools-and-virtual-hardware-for-microsoft-isa-array/) - Today I have been troubleshooting problems with a Microsoft ISA array. The array didn’t function anymore after moving the Configuration Storage Server and one array member from a VMware 3.5 environment to a VMware 4.0 environment. After moving the array member the VMware Tools were upgraded and also the Virtual Hardware was upgraded. After rebooting - [Export StartTLS certificate from SMTP server](https://www.booches.nl/2015/05/export-starttls-certificate-from-smtp-server/) - While configuring Office365 as the messaging (SMTP) server within Aruba ClearPass, I needed to upload the certificate from the StartTLS session to the certificate trust list from ClearPass. I had to export the certificate for smtp.office365.com via the following OpenSSL command: openssl s_client -showcerts -starttls smtp -crlf -connect smtp.office365.com:587 After running the command, you will see - [Provision Aruba AP via CLI](https://www.booches.nl/2015/03/provision-aruba-ap-via-cli/) - Below you will find the necessary commands to provision an Aruba access-point via CLI. The commands add the access-point to the AP whitelist and provision the AP in the correct ap-group. Adding the AP to the whitelist is necessary when using control-plane security. whitelist-db cpsec add mac-address "94:b4:0f:c4:7e:98" description "ap01" whitelist-db cpsec modify mac-address "94:b4:0f:c4:7e:98" - [ProCurve - Secure Management](https://www.booches.nl/2015/02/procurve-secure-management/) - Managing networking components is possible via a web interface or via a command-line interface. It doesn't matter which method you prefer, but it does matter that the connection should be secure. If you use telnet (cli) or http (web interface) the management traffic is send clear-text across the network. I still notice that a lot of - [FortiGate - debug flow](https://www.booches.nl/2015/02/fortigate-debug-flow/) - You can use the diagnose debug flow commands to do a policy simulation. An example of the output: fw01 (root) # diagnose debug enable fw01 (root) # diagnose debug flow show console enable show trace messages on console fw01 (root) # diagnose debug flow filter addr 10.10.1.25 fw01 (root) # diagnose debug flow trace start - [Cisco WLC and pre-download software to AP](https://www.booches.nl/2015/02/cisco-wlc-and-pre-download-software-to-ap/) - A simple post, because I always forget the CLI commands to TFTP the software to the controller. I also added the command to predownload the new firmware to all access-points. This dramatically speeds up the upgrade process of the access-points. You need to set the TFTP parameters first. (Cisco Controller) >transfer download datatype code (Cisco - [ClearPass - mail validation](https://www.booches.nl/2015/01/clearpass-mail-validation/) - If you would like to restrict or validate mail addresses during guest registration, you can use simply restrict domains. An example of a mail validation for the provided user and sponsor mail address is. user mail validation (the mail address should not be a company mail address) array ( 'deny' => array ( 0 => - [Huh? Interface SSLVPN-VIF0?](https://www.booches.nl/2010/03/huh-interface-sslvpn-vifo/) - While checking interface statistics on a Cisco 3845, I noticed the following layer 3 interfaces. Interface IP-Address OK? Method Status Protocol GigabitEthernet0/0 74.124.155.67 YES NVRAM up up GigabitEthernet0/1 10.10.10.1 YES NVRAM up up GigabitEthernet0/0/0 unassigned YES NVRAM administratively down down SSLVPN-VIF0 unassigned NO unset up up Tunnel0 192.168.255.2 YES NVRAM up up I can explain - [Policy NAT on Cisco router](https://www.booches.nl/2009/01/policy-nat-on-cisco-router/) - A colleague of mine had to implement an IPSec VPN tunnel from a customer to a supplier. The customer has a Cisco router for connecting to the Internet, so nothing special. The router is already setup and in production. Configuring an extra IPSec VPN tunnel isn't very hard, the most important part is the negotiation - [HP Virtual Connect Manager](https://www.booches.nl/2012/01/hp-virtual-connect-manager/) - While change the configuration of within a HP Virtual Connect Manager I noticed that I didn’t have any options to delete server profiles, Ethernet Networks or Shared Uplink Sets within the web browser. I needed to change the configuration dramatically from an active / standby configuration to an active / active configuration. I also needed - [Cisco cable-diagnostics with TDR](https://www.booches.nl/2013/08/cisco-cable-diagnostics-with-tdr/) - Some Cisco switches have a way to check the condition of copper cables. This can be done via de command test cable-diagnostics tdr. TDR stands for Time Domain Reflector. More information about Time Domain Reflector can be found at the Cisco Support Community. The command can be very useful for basic layer 1 troubleshooting. core01#test - [LDAP and eSafe Gateway](https://www.booches.nl/2008/04/ldap-and-esafe-gateway/) - eSafe Gateway can be used for scanning incoming and outgoing SMTP connections for virusses and SPAM. Normally eSafe Gateway doesn't check incoming mail addresses against a directory like Active Directory or Novell Directory Services. This means that all mail addresses for a trusted domain are forwarded to the internal mail server. In the most ideal - [McAfee Firewall – NAT mapping](https://www.booches.nl/2011/12/mcafee-firewall-nat-mapping/) - While testing a McAfee Enterprise Firewall running software 8.2.0, I had some problems with the creation of a NAT mapping. The firewall is configured as standalone firewall. All (NAT / access rule) configuration on the firewall is done using Access Control Rules. McAfee uses two types of NAT mapping: NAT: mostly used to translate a - [Sophos UTM - An unsupported mechanism](https://www.booches.nl/2013/02/sophos-utm-an-unsupported-mechanism/) - I got some strange issues / problems while testing a Sophos UTM appliance with 9.004-34 software. The Web Security feature is filtering requests and using client authentication. The proxy is using Standard Mode with Active Directory SSO authentication. I testing the proxy by changing the proxy settings on a Citrix server. Everything was working without - [Citrix Secure Gateway via https-only](https://www.booches.nl/2013/02/citrix-secure-gateway-via-https-only/) - Configuring a Citrix Secure Gateway (CSG) server is simple, but provides a powerful solution to access resource from remote locations. CSG is an application installed on a DMZ server. Mostly I also configure the Citrix WebInterface on the same server. The CSG instance listens on TCP/443 and the WI instance listens on TCP/80. To improve - [Aruba WPA2 with MAC authentication](https://www.booches.nl/2012/12/aruba-wpa2-with-mac-authentication/) - Configuring an SSID with WPA2 Pre-Shared key or Enterprise authentication and encryption is very common. Sometimes you would like to add an extra authentication method. Although this method isn’t very secure, MAC authentication is still used as an extra method to strengthen the level of security of a wireless or wired network. These days I - [Cisco DHCP server & VRF](https://www.booches.nl/2012/12/cisco-dhcp-server-vrf/) - I had some issues while configuring some VRF’s on a Cisco router and using that router as a DHCP server. First of all the router wasn’t binding any DHCP request. The DHCP server configuration is defined below. ip dhcp pool guest vrf vrf-guest network 10.10.0.0 255.255.252.0 default-router 10.10.0.1 domain-name internet-only.nl dns-server 208.67.222.222 208.67.220.222 The configuration - [Sophos UTM – WebAdmin access via proxy and IE9](https://www.booches.nl/2012/11/sophos-utm-webadmin-access-via-proxy-and-ie9/) - I just configured a Sophos UTM cluster based on software version 9. I was able to configure the appliance via WebAdmin and I could access the User Portal without any problems. The customer is using a Citrix based environment with Internet Explorer 9. IE9 is configured to use the Sophos UTM cluster as proxy server. - [Aruba RAP in bridge mode with remote access](https://www.booches.nl/2012/10/aruba-rap-in-bridge-mode-with-remote-access/) - The Aruba Networks Remote Access Points is a nice feature for branch offices or home workers. I use a RAP5WN at home and I configured different SSID’s on the RAP. The SSID’s are in tunnel mode, split-tunnel mode or bridge mode. The bridge mode connections are for my home devices, like my girls iPad and - [Wireless controllers – the discussion continues](https://www.booches.nl/2012/10/wireless-controllers-the-discussion-continues/) - There is already a lot said and written about wireless controllers and it’s architectures. During my recent holiday my thoughts were wandering about this subject. At the beginning we had the stand-alone access-points, which were all configured as unique identities. Choosing the correct channel and power level could be a challenge in dense environments, so - [Weathermap error message](https://www.booches.nl/2012/08/weathermap-error-message/) - After upgrading CactiEZ from 0.8.7.c to 0.8.7h with PIA 3.1 I received an error message with viewing the Weathermap plugin. Notice: Undefined index: action in /var/www/html/plugins/weathermap/setup.php on line 84 After surfing some time on the internet I found the solution. I change the syntax on line 84. The change is displayed below. Old syntax if($_REQUEST["action"] - [SecurEnvoy: debug logging](https://www.booches.nl/2012/07/securenvoy-debug-logging/) - To get more logging from SecurEnvoy SecurAccess on a Windows server you have to add the following line to the file local.ini. Debug_admin=True A log file will be created with detailed logging. The log file is created under C:\Debug\admin.txt. - [Cacti – PA 3.0 wrong path for plugins](https://www.booches.nl/2012/07/cacti-pa-3-0-wrong-path-for-plugins/) - After upgrading a CactiEZ installation to cacti 0.8.7h including PA 3.0, I had some problems with the different plugins. The default path for the plugins was configured incorrectly. The plugins were looking in the wrong directory for their images. In the httpd error log I see the following errors. [root@localhost html]# tail -90f /etc/httpd/logs/error_log [Wed - [Upgrade Juniper SA cluster](https://www.booches.nl/2010/01/upgrade-juniper-sa-cluster/) - Add On: This procedure also works for the new Juniper MAG appliances. But keep in mind during the upgrade of the second host (and also the first): BE PATIENT!! A Juniper SA cluster can be configured as active/active or active/standby cluster. An active/active cluster uses an external load balancer or DNS round-robin to enable load-sharing - [HP A4800G – DHCP relay](https://www.booches.nl/2012/06/hp-a4800g-dhcp-relay/) - This article isn’t very difficult and spectacular. It is just for me as a quick note to configure DHCP relaying on a HP A4800G switch. The configuration of this type of switch is a little different compared to Cisco and/or legacy HP ProCurve switches. The following steps are required to configure DHCP relaying: system-view System - [AeroHive – access to MyHive landing page](https://www.booches.nl/2012/02/aerohive-access-to-myhive-landing-page/) - The AeroHive user, which is created by default, gets a landing page, when logging into https://myhive.aerohive.com. The user can choose between the HiveManager Online and the Redirector. When the users chooses the HiveManager Online or the Redirector, the user has the option to return to landing page by choosing the MyHive option in the upper - [Cisco WLC – Upgrade FUS image](https://www.booches.nl/2012/02/cisco-wlc-upgrade-fus-image/) - Today I upgraded a FUS image on a Cisco WLC 5500 controller, because I also upgrade the WLC software to 7.2.103.0. The FUS upgrade is straightforward and comparable to a regular software update. The only difference is that you need console access to perform the upgrade. The FUS image upgrades the following components: Field Recovery - [Cisco Spanning Tree Scalability](https://www.booches.nl/2012/01/cisco-spanning-tree-scalability/) - A colleague (Twitter: @Toonieh) mentioned spanning-tree scalability in a Cisco network. He had an article about this matter. All the credits on this post go to him. I found the article on internet and post it here to be able to find it quickly.. In a Layer 2 looped topology design, spanning tree processing instances - [CactiEZ – configuration basics](https://www.booches.nl/2011/12/cactiez-configuration-basics/) - Every time I install CactiEZ or Cacti on another platform, I am searching for the commands to basically install the most common parameters, like static IP addressing, NTP sync and time zones. Several times I thought about writing a simple article with the necessary commands and final I had time to create it. Networking netconfig - [AeroHive Spectrum Analysis](https://www.booches.nl/2011/11/aerohive-spectrum-analysis/) - One cool feature about AeroHive is the build-in Spectrum Analysis feature, which is enabled by default from HiveOS 4 and higher. Spectrum analysis is very useful to get a view of the RF environment near an access-point. This is especially useful when troubleshooting bad connections (high volume of retransmissions) or other problems related to the - [Microsoft UAG – Invalid External Port bug](https://www.booches.nl/2011/11/microsoft-uag-invalid-external-port-bug/) - Last week I have installed a Microsoft UAG array. I installed Microsoft ForeFront Unified Access Gateway 2010 including Service Pack 1. When using an array configuration you have to deploy Microsoft’s Network Load Balancing (NLB) for redundancy and load balancing purposes. I configured NLB with multicast and IGMP support. I had configured some HTTPS trunks - [Cisco ASA – Reset TCP connection](https://www.booches.nl/2011/08/cisco-asa-reset-tcp-connection/) - “Normal” TCP applications use a three-way handshake to establish a session. After data has been send the session is closed. Some legacy applications don’t always close a TCP session. They keep the session open, even when the session is idle for a long time (+ 2 hours). When the session is idle and a client - [Cisco 888G with KPN 3G connection](https://www.booches.nl/2011/08/cisco-888g-with-kpn-3g-connection/) - Something I don’t see and don’t do very often is the configuration of a router including a 3G connection. So this blog post helps me during the process of configuring future connections. For todays configuration I am using the Dutch carrier KPN to establish the 3G connection. As hardware I am using a Cisco 888G - [Cacti: corrupt database](https://www.booches.nl/2011/06/cacti-corrupt-database/) - After rebooting a Cacti server, the customer complained that no new graphs were drawn by the server. I tried to run the poller.php script with the –-force option and noticed the following output: 06/16/2011 10:34:48 AM - SPINE: Poller[0] ERROR: SQL Failed! Error:'145', Message:'Table './cacti/poller_output' is marked as crashed and should be repaired', SQL Fragment:'INSERT - [Cisco ASA – Full recovery](https://www.booches.nl/2011/05/cisco-asa-full-recovery/) - While trying to perform a password recovery on a Cisco ASA, I noticed that the password recovery feature was disabled on the appliance. Without the password recovery feature enabled, you can recover the Cisco ASA, but the file system will be wiped completely. During the boot of the Cisco ASA you need to press ESC - [ISA Server 2006 array – renew certificate](https://www.booches.nl/2011/05/isa-server-2006-array-renew-certificate/) - When configuring a Microsoft ISA Server 2006 array you have two options for authentication and communication between the Microsoft ISA 2006 Configuration Storage Server and the array members. Windows Authentication: Choose this option if ISA server and the Configuration Storage server are in the same domain, or in different domains with a trust relationship between - [Windows CA template – web server and private key export](https://www.booches.nl/2011/05/windows-ca-template-web-server-and-private-key-export/) - Creating a web server certificate request is very easy when using a Windows CA server. There is one disadvantage. The requested certificate is directly stored in the user store (by default) or the local computer store, if specified during the request. The disadvantage is that you cannot export the requested certificate including the private keys. - [Juniper SSG to Cisco ASA VPN with overlapping subnets](https://www.booches.nl/2011/03/juniper-ssg-to-cisco-asa-vpn-with-overlapping-subnets/) - I needed to configure a site-to-site VPN connection between a Juniper SSG firewall and a Cisco ASA firewall. The configuration of a VPN connection is very straightforward, but this time the networks behind the firewalls are overlapping. I have configured the Cisco ASA multiple times in such scenario, but the configuration of the Juniper SSG - [OpenSSL for testing TLS](https://www.booches.nl/2011/02/openssl-for-testing-tls/) - I was looking for a way to test the TLS configuration of a secure mail server and stumbled across a website called “OpenSSL Command-Line HOWTO”. This websites explains how to test a TLS connection using OpenSSL. The s_client and s_server options provide a way to launch SSL-enabled command-line clients and servers. There are other examples - [NBAR and smart filtering](https://www.booches.nl/2011/02/nbar-and-smart-filtering/) - NBAR (Network Based Application Recognition) is a cool Cisco tool to identify and classify content flowing through a router. You can identify applications as mission critical, business-related, non-critical or unwanted. Once these mission critical applications are classified they can be guaranteed a minimum amount of bandwidth, policy routed, and marked for preferential treatment. Non-critical applications - [Cisco ASA remote management via VPN](https://www.booches.nl/2011/02/cisco-asa-remote-management-via-vpn/) - By default, remote access VPN users aren’t able to manage a Cisco ASA firewall on the inside interface using any kind of management protocol (SSH, telnet, HTTPS). You can enable remote management by specifying the management-access interface. You can specify the interface via the CLI or via the Cisco Adaptive Security Device Manager (ASDM). Both - [XS4ALL, Cisco 877 and IPv6](https://www.booches.nl/2011/02/xs4all-cisco-877-and-ipv6/) - A while ago my ISP XS4ALL started with the distribution of IPv6 prefixes to their customers. So as a network engineer I wanted to have my own /48 prefix. Sadly I didn’t had time to start testing at the beginning of the IPv6 “launch”. Last week I found some time to start my testing. I - [Policy-based routing in a nutshell](https://www.booches.nl/2010/10/policy-based-routing-in-a-nutshell/) - Lately I received some questions about routing decisions and how to influence the routing decisions via access control lists. The following example shows a simple configuration for policy-based routing. The example uses the following logical setup: I configured two routers and connected each router to two PVC’s on the same ATM interface. I configured one - [Cisco ASA NPE image](https://www.booches.nl/2011/01/cisco-asa-npe-image/) - I got complains from a customer who wasn’t able to configure 3DES or AES encryption for a VPN tunnel. Sounds familiar with a problem I had a couple of weeks ago. So I gave the customer the advice to upgrade and activate the VPN-3DES-AES feature. He tried but that didn’t solve this problem. I remotely - [PIX Failover not working](https://www.booches.nl/2008/06/pix-failover-not-working/) - Today I received the question why a PIX failover configuration wasn't working. The customer accidentally disconnected the power cable from the primary PIX firewall. The secondary PIX firewall became the active one, but multiple DMZ segments weren't working anymore. After rebooting the PIX firewall and making that the primary one again, the DMZ segments were - [XenServer and Multicast with IGMP support](https://www.booches.nl/2010/12/xenserver-and-multicast-with-igmp-support/) - Today I tried to add a virtual Terminal Server within a XenServer to a NLB cluster. The current NLB cluster contained only physical servers. When adding the virtual server to the NLB cluster with the NLB manager, the server lost all IP communication. It isn’t possible to connect to or from the server. Together with - [Upgrading Cisco switch stack](https://www.booches.nl/2010/12/upgrading-cisco-switch-stack/) - I always upgrade a switch stack with one single command. Last week I received a call from a customer with the question about the upgrade procedure for a switch stack. The customer wanted to upload the image separately to every single switch. I told him that he could upgrade all switches at once. Since I - [Cisco CSC-SSM-20 notes](https://www.booches.nl/2010/11/cisco-ssm-20-notes/) - The Cisco CSC-SSM-20 modules provide advanced scanning technologies within the Cisco ASA firewall. During installations of these modules I created some quick notes, which I would like to share with you. Initial configuration After inserting the Cisco CSC-SSM modules into the Cisco ASA firewall, you have two ways to configure the initial configuration. The first - [Cisco stack: version mismatch](https://www.booches.nl/2010/12/cisco-stack-version-mismatch/) - When adding a new switch to an existing stack, the new switch should have the same software image as the existing stack member switches. If the new switch has different software, the switch isn’t capable of joining the stack. Switch/Stack Mac Address : 588d.0918.3100 H/W Current Switch# Role Mac Address Priority Version State ---------------------------------------------------------- *1 - [Cisco ASA: web interface not working](https://www.booches.nl/2010/12/cisco-asa-web-interface-not-working/) - I had to troubleshoot a Cisco ASA today, where the client wasn’t able to connect to the management web interface anymore via https. The customer didn’t install ASDM locally, but always starts the Java-based version. After upgrading the Cisco ASA to software version 8.2(1) and a reboot, the client wasn’t able to connect to the - [Cisco Connect – Software Download Entitlement Controls](https://www.booches.nl/2010/12/cisco-connect-software-download-entitlement-controls/) - I read about it on the internet and last week I received the “official” mail from the Cisco Partner Channel about the changes regarding the Software Download Centre Entitlement Controls. The e-mail (in Dutch) can be found below. I have different feelings about the changes regarding the software entitlements. It isn’t possible anymore to just - [Port-channel Cisco vs. VMware ESX](https://www.booches.nl/2008/04/port-channel-cisco-vs-vmware-esx/) - I have had different discussions with different customers about the load-balancing algorithms between a Cisco switch, configured with a port-channel and a VMware ESX server using multiple NICs. Our VMware consultants always choose Route based on IP hashes as load-balancing algorithm. This means that load-balancing happens on layer 3 of the OSI model (source-destination-IP). In - [QoS matching for VoIP](https://www.booches.nl/2008/04/qos-matching-for-voip/) - Voice over IP is, as you know for sure, very time-sensitive traffic. That is why VoIP signaling and payload traffic should receive enough bandwidth and as less jitter and delay as possible. QoS is an important tool to assign VoIP traffic more preference over "normal" traffic. Important for QoS tools to function correctly is placing - [www.booches.nl on a Synology DS107+](https://www.booches.nl/2008/05/wwwboochesnl-on-a-synology-ds107/) - I wanted to buy a new USB disc for backing up all my files, but I didn't know what to buy. A storage consultant told me about the Synology products. Together with some colleagues, we started to look at the different products. At the end we narrowed our search to the Synology DS107+. This is - [BGP Multihoming](https://www.booches.nl/2008/04/bgp-multihoming/) - Today I have been playing with configuring BGP and multihoming. I configured a simple test environment where one customer router (local AS 100) connects to two ISP routers from the same ISP (remote AS 200). I configure some kind of load-sharing amongst the two links to the ISP. Important when configuring BGP is the concept - [AutoQos error while generating commands](https://www.booches.nl/2010/12/autoqos-error-while-generating-commands/) - First of all, the post isn’t about explaining QoS. Configuring AutoQos on Cisco switches should be very easy. At least, that is what all the Cisco documentation tells you. I always thought that the statements about configuration AutoQos were true, but a few days ago I would disagree. I was configuring multiple switches, Cisco Catalyst - [OpenVPN ALS](https://www.booches.nl/2010/11/openvpn-als/) - A few days ago I installed and configured the SSL VPN solution OpenVPN ALS, which is a direct descendant of Adito, which has a fork of SSL-Explorer. OpenVPN ALS is a simple to use SSL VPN solution to publish multiple services via browser-based portal. OpenVPN uses Java to publish multiple services. OpenVPN ALS isn’t an - [Cisco IOS Authentication Proxy](https://www.booches.nl/2008/06/cisco-ios-authentication-proxy/) - Today I have been playing a little with my router at home. I was looking at different websites and stumbled on a Cisco website about Cisco IOS Firewall Authentication Proxy. So I thought by myself, lets give it a try. Cisco IOS Authentication Proxy is a feature with the following discription: "The Cisco IOS Firewall - [TrendMicro IWSVA – Built-in groups and policies](https://www.booches.nl/2010/11/trendmicro-iwsva-built-in-groups-and-policies/) - While configuring a TrendMicro IMSVA appliance I tried to configure different URL filtering policies using built-in Windows Active Directory groups, like “Domain Users” in conjunction with user/group name authentication. Configuring policies with built-in groups weren’t functioning properly. The policies just weren’t matched, while I knew for sure that the user is a member of the - [TrendMicro IMSVA – reject unknown recipients via LDAP](https://www.booches.nl/2010/10/trendmicro-imsva-reject-unknown-recipients-via-ldap/) - With the configuration and implementation of an anti-virus, anti-spam solution, I always check if the security appliance has the option to block unknown recipients via LDAP. This prevents unnecessary e-mail from being sent to the backend servers. While configuring a TrendMicro IMSVA 8.0 I noticed that the LDAP option was available, as shown below. The - [Citrix Web Interface 5.3: An error occurred while making the requested connection](https://www.booches.nl/2010/03/citrix-web-interface-5-3-an-error-occurred-while-making-the-requested-connection/) - I tried to configure a Citrix Web Interface 5.3 server in conjunction with Citrix Presentation Server / XenApp 4.0 and a NetScaler. It is possible to login, but I cannot launch an application. When trying to launch an application I receive the following error message: An error occurred while making the requested connection I found - [Citrix WebInterface 5.3 on IIS7](https://www.booches.nl/2010/09/citrix-webinterface-5-3-on-iis7/) - While configuring a Citrix NetScaler 9.2 in conjunction with WebInterface 5.3 I received the following error message when executing a published application. An error occurred while trying to access the requested resource. I thought to myself….no problemo, since I blogged about this problem before (source). This solution didn’t help. After changing the RequireLaunchReference value I - [Tunneling sessions via Plink](https://www.booches.nl/2010/08/tunneling-sessions-via-plink/) - Plink stands for PuTTY Link and is a command-line connection tool similar to Unix ssh. As a networking consultant I often need to support customers from remote locations. Access to their networking equipment is mostly blocked from unknown locations. Sometimes it is allowed to directly access networking equipment, like a company firewall, from a known - [Cacti – Superlinks not working](https://www.booches.nl/2010/08/cacti-superlinks-not-working/) - After upgrading Cacti, like shown in the previous post, the Superlinks plugin stopped working correctly. When opening a Superlink tab I got a blank page in Google Chrome or a half page in Internet Explorer and Opera, like shown below. After some Googling I found the solution for this problem on a Cacti forum. The - [Upgrade Cacti 0.8.x](https://www.booches.nl/2010/08/upgrade-cacti-0-8-x/) - A lot of people use the CactiEZ virtual appliance to install a running Cacti environment. The latest CactiEZ virtual appliance (CactiEZ v0.6) uses Cacti v0.8.7c with Plugin Architecture 2.2. Of course a lot of people are developing Cacti and the latest stable version is Cacti v0.8.7g with Plugin Architecture 2.8. I always have trouble with - [STP successor - CiscoNL](https://www.booches.nl/2010/08/stp-successor-cisconl/) - I just watched a online movie on the CiscoNL – Technology site about the successor for Spanning Tree Protocol in the near future. The movie can be found here (language: Dutch). - [Cisco Virtual Com](https://www.booches.nl/2010/07/cisco-virtual-com/) - It took some time, but Cisco started to migrate from the blue RJ-45 based console cable to an USB based console cable. The latest types of routers and switches are equipped with both types of connections or only with the USB based connection, like the new IBM blade switches. The picture below shows the console - [Catalyst 3750X licensing](https://www.booches.nl/2010/07/catalyst-3750x-licensing/) - While making a kit list for a network design with Cisco Catalyst 3750X switches, I got confused while looking at the different licensing features. The Cisco Catalyst 3750X switches are available with multiple licensing options, which can be upgraded. A new switch can be ordered with two licensing options. These are LAN Base (Enhanced Intelligent - [Outlook 2010 and Google Calendar Sync](https://www.booches.nl/2010/06/outlook-2010-and-google-calendar-sync/) - I replaced my Outlook 2007 with Outlook 2010. Since I am using Google Calendar, I would like to sync my calendar with Outlook. With Outlook 2007 you can use the Google Calendar Sync application. After installing Outlook 2010 the synchronization of the calendar didn’t function anymore. While synchronizing you will receive the following error message. - [Restore RSA 7.1 primary database and RADIUS config](https://www.booches.nl/2010/06/restore-rsa-7-1-primary-database-and-radius-config/) - A few days ago I was troubleshooting a problem with an ISA array after upgrading the VMware environment as you can read in this article. I had a same kind of problem with a RSA environment. After upgrading the VMware Tools and the Virtual Hardware, the RSA database didn’t start anymore. RSA noticed to much - [Windows LDAPS expired](https://www.booches.nl/2010/06/windows-ldaps-expired/) - A lot of appliances and/or security solutions use LDAP to synchronize users from an Active Directory or an eDirectory environment. Active Directory is LDAP enabled by default. If you would like to harden your network, you would like to use LDAPS. LDAPS is a term to refer to LDAP communication over SSL. Intercepted LDAPS traffic - [Microsoft ISA publishing – it’s all in the “path”](https://www.booches.nl/2010/06/microsoft-isa-publishing-its-all-in-the-path/) - I have installed multiple reverse proxy servers based on Microsoft ISA 2006. These reverse proxy servers are mainly deployed to publish services like Outlook WebAccess, PDA synchronization, SharePoint or regular websites. Services like Outlook WebAccess are published using secure session protected by SSL certificates. Microsoft ISA server uses “Listeners” to match and intercept traffic from - [ISDN Backup - still alive?](https://www.booches.nl/2010/05/isdn-backup-still-alive/) - Nowadays everybody wants redundancy within their network, especially when using remote sites. Customers are using multiple ISP’s for redundancy and/or configure BGP solutions. In the old days (hear me talking with my 27 years) ISDN was often used for backup purposes and I still use it sometimes as redundancy mechanism. Everybody knows that bandwidth is - [CB-WFQ Bandwidth Allocation](https://www.booches.nl/2010/01/cb-wfq-bandwidth-allocation/) - When configuring Quality of Service with CB-WFQ I am always puzzling to get the correct classes. When configuring CB-WFQ it is important to remember that the router does not allow the class queues to consume more than 75% of the total interface bandwidth. The remaining 25% are used for the default class as well as - [Juniper SA & GroupWise WebAcc SSO](https://www.booches.nl/2009/05/juniper-sa-groupwise-webacc-sso/) - While configuring a Juniper SA2500 in conjunction with Novell GroupWise WebAccess, the customers wanted single sign on (SSO) configured. The default Novell GroupWise WebAccess login page uses FBA (Forms Based Authentication). So it should be possible to push the correct POST parameters to enable SSO for GroupWise WebAccess. I started with looking at the page - [RSA AM 7.1SP3 Token Delivery](https://www.booches.nl/2010/04/rsa-am-7-1sp3-token-delivery/) - Using two-factor authentication is common when publishing remote services to the internet with components like Citrix NetScaler or Juniper SA appliances. RSA is a well-known provider of two-factor authentication mechanism. Beginning with RSA Authentication Manager 7.1 people have the ability to use the On-Demand feature. This feature enables the delivery of token codes via SMS - [Citrix NetScaler: Protocol Driver Error](https://www.booches.nl/2010/04/citrix-netscaler-protocol-driver-error/) - Today I have been troubleshooting a Citrix NetScaler configuration, where some clients received the Protocol Driver Error message when executing a published application. This error message is mostly related to a wrong configuration of the Security Ticket Authorities (STA’s). I spent a lot of time troubleshooting this issue and focused on the STA configuration. I - [Upgrade CS MARS](https://www.booches.nl/2009/10/upgrade-cs-mars/) - A customer was running CS MARS with version 4.3.6. Lately the Cisco IPS sensor was upgraded to version 7.x. This version wasn’t supported anymore by CS MARS version 4.3.6. That is why the CS MARS needed to be upgraded to 6.x. I don’t have a lot of experience with CS MARS and I couldn’t find - [PacketShaper Traffic Discovery and Citrix Session Reliability](https://www.booches.nl/2010/04/packetshaper-traffic-discovery-and-citrix-session-reliability/) - While troubleshooting some performance issues with Citrix sessions between headquarters and sub locations, I decided to take a closer look at the PacketShaper. The PacketShaper is positioned at the headquarter and does outbound shaping to the sub locations. The PacketShaper is using older software (7.2x), which isn’t necessarily a problem. I deleted the class for - [User expiration with RSA AM 7.1](https://www.booches.nl/2010/04/user-expiration-with-rsa-am-7-1/) - I noticed some differences in the user expiration between RSA Authentication Manager 7.1 and RSA Authentication Manager 7.1 SP2. When assigning a token to an user in RSA AM7.1, the user automatically gets an expiration date set on its user account. The default expiration date is one year. I cannot reproduce this same symptom with - [The Death of CiscoBlog.com](https://www.booches.nl/2010/04/the-death-of-ciscoblog-com/) - CiscoBlog.com is a website often used by myself to find useful information on network related issues. Today I read the following article on the website. Well, after 5 fun years of running CiscoBlog.com, Cisco “agents” have come. I was contacted by Cisco a couple weeks ago stating that CiscoBlog.com violates their trademark. Being that CiscoBlog.com - [Citrix Access Gateway: duplicate STA ID](https://www.booches.nl/2010/03/citrix-access-gateway-duplicate-sta-id/) - I received complains from a customers who wasn’t able to add two new Citrix servers to his Citrix Access Gateway configuration. He could successfully add the first Citrix server, but he couldn’t add the second Citrix server, because the first was overwritten by the second. I looked at the problem and noticed that both Citrix - [RADIUS Authentication](https://www.booches.nl/2008/04/radius-authentication/) - I am sure that many of you would like to do the same thing and many of you successfully configured it. I am trying to configure RADIUS Authentication on my Cisco 877W. I have two different RADIUS policies, the first for privilege level 1 and the second for privilege level 15. I am using Microsoft - [Problem running ISA en IAS on the same server](https://www.booches.nl/2010/03/problem-running-isa-en-ias-on-the-same-server/) - Today I had some problems running ISA 2004 en IAS on the same server. At the beginning the customer was running ISA 2000 and IAS on the same server without any problems. By incident, the customer was forced to upgrade his ISA. They had a 2004 license, so ISA 2004 it was. I noticed that - [Geotrust 2048 bit Root Migration](https://www.booches.nl/2010/03/geotrust-2048-bit-root-migration/) - Today I read about Geotrust upgrading their public root certificate from 1024-bit to 2048-bit. Geotrust is upgrading the root certificate with the following reason. This change is in line with industry best practices that GeoTrust follows to ensure the highest level of security for customers. The move to 2048-bit root keys is an industry-wide initiative. - [Funny bug in Cisco Cat. 3750 12.2(50)SE](https://www.booches.nl/2010/03/funny-bug-in-cisco-cat-3750-12-250se/) - A colleague experienced a funny bug with a Cisco Catalyst 3750 running IOS 12.2(50)SE. The bug is know under Bug ID CScsy79004. Check the images below: He was doubting his alcohol level, because he thought he didn’t drink during the weekend….LOL - [Cisco ASA: DNS reply filtering](https://www.booches.nl/2009/08/cisco-asa-dns-request-filtering/) - Today I was asked to block access to multiple websites and the only device capable of doing this was the firewall. This customer is using a Cisco ASA firewall, which supports basic URL filtering. This customers wanted to block HTTP and HTTPS websites. HTTPS websites use a SSL tunnel from the end device to the - [Another blogging colleague](https://www.booches.nl/2010/03/another-blogging-colleague/) - There is a new blogger on the internet. The owner of the blog is working as Solution Consultant at 4IP and has a main focus on networking. His blog is called Frameburst and can be found via the URL http://www.frameburst.net. He is still developing this blog and working at the layout, but here are some - [eSafe Proxy with NTLM v2.0](https://www.booches.nl/2010/03/esafe-proxy-with-ntlm-v2-0/) - Today I am playing with eSafe 8 operating in eSafe Proxy with NTLM authentication mode. Configuring eSafe Proxy with NTLM authentication is very straightforward and not difficult. The authentication settings are configuring using the eSafe Appliance Manager web interface, like shown below. I did some testing with multiple browsers and single sign-on with NTLM authentication - [MAB and MDA in an IP Phone environment](https://www.booches.nl/2010/02/mab-and-mda-in-an-ip-phone-environment/) - I blogged before about the MAC Authentication Bypass (MAB) feature in network environments. MAC Authentication Bypass can be used to secure the wired network by verifying MAC addresses to a central database. By using a radius server, like Microsoft IAS or FreeRadius, you can also redirect verified MAC addresses to a specific VLAN. Lately I - [Playing with text files in Linux](https://www.booches.nl/2010/02/playing-with-text-files-in-linux/) - I had a big Microsoft Event Viewer log file and I wanted specific information from the log file. At first I was thinking about using Microsoft Excel to do some filtering, but that didn’t really help. At the end Linux did the trick. I used Cygwin under Windows to extract the specific information. The raw - [Cacti and HP Procurve](https://www.booches.nl/2010/02/cacti-and-hp-procurve/) - Finding a template for HP Procurve switches wasn’t that hard. I needed to find a template for HP Procurve 2510G switches. The place to look for templates is forums.cacti.net. I searched the forums on the key word “procurve”, which resulted in many hits. I used the template from the article HP procurve 2600 series. After - [Port-channel configuration for VMWare](https://www.booches.nl/2008/05/port-channel-configuration-for-vmware/) - I received some e-mails from people asking for configuration examples for Cisco switch in conjunction with VMWare servers. That is why I post the configuration (I normally use) beneath. This configuration enables a 802.1Q trunk connection between the switch and the VMWare server. This configuration requires the VMWare server to use VLAN tagging. The Port-channel - [Configure IOS SSL VPN on IOS router](https://www.booches.nl/2010/02/configure-ios-ssl-vpn-on-ios-router/) - Yesterday I blogged about configuring a VPN client on an IOS router and today I blogged about importing PKCS12 certificates for WebVPN purposes. This follow up blog is about configuring the WebVPN functionality together with the AnyConnect client and port forwarding on an IOS router. I use the same setup as with the VPN client - [Import PKCS12 certificate on IOS router](https://www.booches.nl/2010/02/import-pkcs12-certificate-on-ios-router/) - Nowadays IOS routers can be configured with WebVPN (Clientless SSL VPN) functionalities. WebVPN allows a user to securely access resources on the corporate LAN from anywhere with an SSL-enabled Web browser. To secure the connection you should use a SSL certificate to encrypt all transferred data. There are different ways of creating and importing SSL - [Configure VPN client on IOS router](https://www.booches.nl/2010/02/configure-vpn-client-on-ios-router/) - One way to remotely access a network is using the Cisco VPN client. Nowadays more and more implementations of SSL VPN are being done and Cisco stopped their development on their VPN client and pushes their Cisco AnyConnect client. Still the Cisco VPN client is often used to remotely gain access to a network. The - [Simply back to startup-config](https://www.booches.nl/2010/02/simply-back-to-startup-config/) - There are multiple ways to get back from the running-configuration to the startup-configuration on a Cisco router. One of the simplest ways is just rebooting the router, but this takes a couple of minutes. You can also issue a copy startup-config running-config, but that doesn’t actually replace the configuration, but merges both together. A very - [Layer 2 security](https://www.booches.nl/2008/07/layer-2-security/) - I attended the session layer 2 security, because I had some discussions about layer 2 security with one of my colleagues. We were discussing about using layer 2 security and especially implementing it in the environments from our customers. Looking at my/our customers, I don't see environments where layer 2 threats would be immediate. But - [MAC Authentication Bypass](https://www.booches.nl/2008/06/mac-authentication-bypass/) - MAC Authentication Bypass configuration and caveats - [MAC Authentication Bypass - Continued](https://www.booches.nl/2008/06/mac-authentication-bypass-continued/) - Test environment with MAC Authentication Bypass working for authenticating workstations - [Policy-Based Routing Catalyst 3560](https://www.booches.nl/2008/06/policy-based-routing-catalyst-3560/) - Today I visited a customer where the power a Cisco Catalyst 3548XL blew up. The switch had a manufacture date of December 2000. It is an old one, but still I haven't seen a power supply being blown up from a Cisco switch from that age. But oké, the switch needed to be replaced. The - [Cisco error message: %SYS-2-MALLOCFAIL](https://www.booches.nl/2010/02/cisco-error-message-sys-2-mallocfail/) - While looking through some logging on a switch (Cisco Catalyst 3550), I noticed the following messages popping up multiple times in the buffer logging. -Process= "Pool Manager", ipl= 0, pid= 5 -Traceback= 1A57D0 1A6DF4 161B3C 1B2BF0 1B2E38 1C6440 Jan 26 14:45:48.970 CET: %SYS-2-MALLOCFAIL: Memory allocation of 1680 bytes failed from 0x161B38, alignment 0 Pool: I/O - [NTP Configuration](https://www.booches.nl/2008/03/ntp-configuration/) - The right time synchronization is very important while troubleshooting different kind of problems. Most network components have the option to synchronize their time with a time server on the internal network or the internet. This post shows how to configure NTP with the right time zone on Cisco and HP ProCurve components. The example configurations - [Cisco router: determine amount of memory/flash](https://www.booches.nl/2010/01/cisco-router-determine-amount-of-memoryflash/) - Somebody asked me how he could determine the amount of DRAM and flash memory on a Cisco router. I always thought that everybody would know how to determine this information, but since this isn’t matter, I will tell you how you can determine the values. You use the show version command to retrieve the requested - [Cisco Aironet: multiple SSID’s](https://www.booches.nl/2009/11/cisco-aironet-multiple-ssids/) - I have been playing with some Cisco Aironet’s today. Configuration is quite simple and straightforward, but maybe not for everyone: Broadcast two SSID’s, unsecure and secure Authentication via WPA version 2 pre-shared key Management IP adres in management VLAN You are maybe thinking: “stand-alone access points, why no WLAN controller?” I agree, but be honest. - [Automated eSafe backup](https://www.booches.nl/2010/01/automated-esafe-backup/) - After configuring an eSafe appliance you have the option to export the configuration through the management interface, but you have to do this manually. eSafe has also a build in command line option to create a backup of the required files. The command line allows backing up and restoring files using standard backup/restore commands. The - [Cisco IOS 15 licensing](https://www.booches.nl/2010/01/cisco-ios-licensing/) - I just read an interesting article about the new licensing on Cisco hardware, especially after the End-of-Sale and End-of-Life Announcement for Cisco IOS Software Release 12.4. In short the article tells the following: IOS 12.4 is replaced by IOS 15. IOS 15 is a single software package for the hardware platform that your are using. - [Twitter Weekly Updates for 2010-01-10](https://www.booches.nl/2010/01/twitter-weekly-updates-for-2010-01-10/) - Sounds like fun ;-( # Today 30 degrees Celtius in Santiago de Chile, tomorrow -5 degrees Celtius in Atlanta and the day after even more cold in the Netherlands.. # Hope we can land at Amsterdam Schiphol with all that snow?!?!?! # survived flight number 8 this holiday......tomorrow flight number 9 and 10 # Survived - [Twitter Weekly Updates for 2010-01-03](https://www.booches.nl/2010/01/twitter-weekly-updates-for-2010-01-03/) - Celebrating new year and tomorrow morning a 4 day tour to Salar de Uyuni (salt desert). I cannot wait!!! # Happy new year to all of you!!! I still have to wait for 4 more hours ;-( # @markmeijerink you have to download the iTunes 12 days app from the AppStore, so you can get - [Twitter Weekly Updates for 2009-12-27](https://www.booches.nl/2009/12/twitter-weekly-updates-for-2009-12-27/) - @vterhaar & @markmeijerink : muchas gracias # Strange feeling, I'm celebrating christmas and my birthday in the most southern city on the planet # @nicoroosenboom Are you going to let them add some air into your head?? Could be interesting ;-) # @mramsmeets I don't know Bonzi Bunny? Did I miss something import in life?? - [Twitter Weekly Updates for 2009-12-20](https://www.booches.nl/2009/12/twitter-weekly-updates-for-2009-12-20/) - 10:30 pm and still rise and shine... will the sun ever go down here?!?!? # 9 :15 pm and it is still light and warm outside...strange compared to the winter in the Netherlands # I haven't used my iBook for a while. Need to look for a special character sheet cheat... I can't remember the - [Internet in Argentina](https://www.booches.nl/2009/12/internet-in-argentina/) - I don't know if people from Argentina read my blog, but if they do I would like to thank them for their wireless coverage throughout the country. I am traveling for some time through Argentina and I slept in multiple hotels and hostels. Every single hotel and hostel offers some kind of internet connection. Mostly - [Twitter Weekly Updates for 2009-12-13](https://www.booches.nl/2009/12/twitter-weekly-updates-for-2009-12-13-2/) - Geert de Wever is giving a demo about wireless networking from Aruba Networks at 4IP in Eindhoven # Only 8 more hours and then on holiday to Argentina and Chili # I have enough for today. My eyes are shaped squarely from looking at my laptop screen...... # Finished for today...driving home to write multiple - [Technology in the air](https://www.booches.nl/2009/12/technology-in-the-air/) - Technology and high-tech is evolving and keeps evolving. Everything you almost wish for is present in your phone. Take my Nokia E71 and my iPhone as an example. Together they almost represent a full work space for me. I have e-mail, agenda and contacts synchronized. There are multiple VPN capabilities to connect to the office - [Website Cisco](https://www.booches.nl/2009/12/website-cisco/) - What is happing with Cisco’s website? Lately I am having serious problems. At a glance: I just cannot register 4IP as Channel Partner. The Partner Registration Database isn’t responding. There is a TAC case for this issue, but still no luck even after hundreds of mails and phone calls; CCO login problems. I cannot login, - [Twitter Weekly Updates for 2009-12-06](https://www.booches.nl/2009/12/twitter-weekly-updates-for-2009-12-06/) - @mramsmeets Like I said, they are just lucky. We already did the Johnny Loftis 4 years ago. # RT @NetGeNoten: Nieuwe NGN-blog: Wireshark Tip: mark packets http://bit.ly/7Mr5EI # Watching K-1 fighting...are they lucky that I'm lying on the couch! ;-) # Powered by Twitter Tools - [GNS3 supports JunOS](https://www.booches.nl/2009/12/gns3-supports-junos/) - A lot of you will know GNS3. GNS3 is a graphical network simulator that allows simulation of complex networks. With GNS3 you can simulate multiple Cisco routers and the Cisco PIX firewall. GNS3 allows you to emulate real Cisco IOS images, design and experiment with complex networks, connect the virtual lab to the real world - [Google Public DNS](https://www.booches.nl/2009/12/google-public-dns/) - I just read an article about Google publishing a Public DNS service. Google Public DNS is a free, global DNS resolution service. Google recommends using their Public DNS server as an alternative to your current DNS servers. To try it out: Configure your network settings to use the IP addresses 8.8.8.8 and 8.8.4.4 as your - [Barracuda – Outbound SMTP Host/Smart Host in Build 3.5.12.012](https://www.booches.nl/2009/12/barracuda-outbound-smtp-hostsmart-host-in-build-3-5-12-012/) - When upgrading from a build older then 3.5.12.012 to a build 0.12 or above, you should pay attention to the Outbound SMTP host/Smart host configuration. This picture below shows the configuration option. The release notes tell the following: Fix: Now honors outbound BASIC > Administration > 'SMTP host/Smarthost' for mail delivery when relaying (recipient domain - [RSA Authentication Manager 7.1 on VMware](https://www.booches.nl/2008/08/rsa-authentication-manager-71-on-vmware/) - I had to install and configure RSA Authentication Manager 7.1. Looking at the Supported Platforms I couldn't find VMware ESX as supported platform. VMware ESX was supported for RSA AU6.1. So I thought by myself, let's give it a try. What I noticed first was the size of the installer. The installation file for RSA - [Step-by-step guide: SwitchMap under CactiEZ](https://www.booches.nl/2009/12/step-by-step-guide-cactiez-with-switchmap/) - Switchmap is a Perl program that creates HTML pages that show information about a set of Cisco Ethernet switches. It uses SNMP to gather data from the switches. Normally I install Switchmap in conjunction with CactiEZ and every time I am struggling to get Switchmap to work perfectly. During another installation I wrote this step-by-step - [New Theme](https://www.booches.nl/2009/11/new-theme/) - As I already announced on Twitter, I have updated my blog theme. I am very curious about your comments…… should this theme stay or should I revert back to the old one? What would you change at the current theme? Updated on December 1ste 2009 Yesterday I have been playing with my new theme and - [eSafe license expires](https://www.booches.nl/2009/11/esafe-license-expires/) - I just received the following interesting question: What happens if our eSafe license expires?……Because it expires this weekend!!!!!!!! Interesting question, because I never encountered such a situation. Normally the license is renewed in a timely fashion or a trial is stopped before the license expires. I searched the Knowledge Base from eSafe and found an - [Citrix Terminal Server License Server problem](https://www.booches.nl/2009/11/citrix-terminal-server-license-server-problem/) - One of our customers is using a Citrix NetScaler appliance for SSL VPN capabilities for remote users. I tried to start an application (RDP Client) through this SSL VPN solution, but I couldn't succeed. I was able to login and I would see all the published applications, but when executing one, I received the following - [ISA 2006 Link Translation](https://www.booches.nl/2009/11/isa-2006-link-translation/) - Web pages returned from a Web server published by a Microsoft® Internet Security and Acceleration (ISA) Server 2006 Web publishing rule may include links containing internal names of computers or Web sites and internal paths to Web content. Because external clients cannot resolve these internal names, these links will be broken unless the internal names - [Coolest Error Message so far](https://www.booches.nl/2009/11/coolest-error-message-so-far/) - I just saw the coolest error message I have every seen on the Cisco Blog. CHECK IT OUT NOW!!! - [RSA 7.1 with On-Demand](https://www.booches.nl/2009/11/rsa-7-1-with-on-demand/) - RSA token security provides a way to strengthen the security on public services. Token authentication is most often implemented with hardware tokens. RSA 7.1 has additional methods of token authentication besides the hardware tokens: Token delivery by SMS; Token delivery by e-mail; To enable the above features you have to install at least RSA 7.1 - [NetScaler CAG Customisation](https://www.booches.nl/2009/11/netscaler-cag-customisation/) - I wanted to change the login screen of a NetScaler CAG, but I didn’t know which files to change. Luckily my college from DigiPulse and member of the Dutch Citrix User Group (DUCUG) gave me the solution by pointing me to the following blog post. Hey mensen, Op verzoek van Edwin Houben hieronder een overzicht - [Blogging from my iPhone](https://www.booches.nl/2009/11/blogging-from-my-iphone/) - From now on I can blog from my iPhone. I found a nice little app in the App Store called WordPress 2.0. With this app you can create and edit your posts, comments and pages. I see it as little version of Windows Live Writer. Ofcourse it isn't the ideal way to write large and - [ISA 2006 Web Chaining](https://www.booches.nl/2009/11/isa-2006-web-chaining/) - ISA Web Chaining rules define how traffic will be handled by the proxy server. Web request to specific destination can be handled in different ways by ISA: Retrieve directly from the destination / internet; Forward to an upstream proxy server; Redirect the request to a specific server / web page; The most popular use for - [Redundant DMVPN network](https://www.booches.nl/2009/08/redundant-dmvmp-network/) - Today I looked at the configuration DMVPN (Dynamic Multipoint VPN). A Dynamic Multipoint Virtual Private Network is an enhancement of the virtual private network (VPN) configuration process of Cisco IOS-based routers. DMVPN prevents the need for pre-configured (static) IPsec peers in crypto-map configurations and ISAKMP peer statements. This feature of Cisco IOS allows greater scalability - [Reset Nokia E71](https://www.booches.nl/2009/11/reset-nokia-e71/) - Are you having weird problems with your Nokia E71 that you didn’t have when you first got it? Maybe it is time to reset your phone. There are two ways of resetting, a soft and a hard reset. You should always backup your phone, before resetting it. Soft reset A soft reset only reboots your - [Nokia E71, XS4ALL and SIP](https://www.booches.nl/2009/11/nokia-e71-xs4all-and-sip/) - My Internet provider, XS4ALL, offers me the possibility to use a free SIP account. This is especially useful when travelling abroad. I can call to the Netherlands with the SIP accounts. This saves me a lot of money compared to calling with my regular cell phone. I often hard reset my phone, so all settings - [Active Directory: one account, two passwords](https://www.booches.nl/2009/11/active-directory-one-account-two-password/) - Lately I noticed something strange. I configured an ISA server as reverse proxy for OWA. The customer demanded the ability for users to change their password through OWA. I configured the OWA listener with LDAPS authentication against the Active Directory and enabled the option to select “I want to change my password after logging on” - [IPplan – IP address management](https://www.booches.nl/2009/09/ipplan-ip-address-management/) - A lot of customers have different methods for their IP address management. Most of them use some kind of static documentation, like an Excel sheet. In the past I implemented IPplan multiple times. I like this tool, because it dynamically scans multiple IP subnets, using ICMP and/or Nmap. Another advantage of IPplan is its ability - [Barracuda – Mail Protocol Violation](https://www.booches.nl/2009/09/barracuda-mail-protocol-violation/) - A customer updated the firmware from a Barracuda SPAM &Virus 300 firewall. The firmware was upgraded from version 3.4 to version 3.5.12.024. After the upgrade no email was coming in or going out through the Barracuda firewall. All email was blocked and the following reason was visible in the message log: Mail Protocol Violation At - [eSafe Gateway 7.1 Forwarding Proxy with squid](https://www.booches.nl/2009/08/esafe-gateway-7-1-forwarding-proxy-with-squid/) - My colleague over at PBSPlaza wrote a nice article about enabling squid on eSafe Gateway 7.1 Forwarding Proxy. Today I had to configure an extra step to enable squid. I followed the instructions from my colleague, but when I tried to start squid I received the following error message. FATAL: Could not determine fully qualified - [Cisco banners with SSH](https://www.booches.nl/2009/07/cisco-banners-with-ssh/) - When configuring a Cisco device I always configure some kind of banner, which is displayed when logging in. This banner contains some information, like security warnings and general information. There are different kind of banners. exec: display a banner before displaying the enable prompt; login: display a banner before the password login prompt when accessing - [RSA 7.1 supported under ESX 3.5](https://www.booches.nl/2009/07/rsa-7-1-supported-under-esx-3-5/) - More and more people would like to implement OTP (One Time Password) solutions. RSA is one of multiple vendors for OTP solutions. I also notice the wish to implement and support OTP with on-demand tokens, like SMS and e-mail. RSA supports on-demand tokens, but the minimum RSA Authentication Manager version required is 7.1. Not only - [REAL fun with the Nintendo Wii](https://www.booches.nl/2009/06/real-fun-with-the-nintendo-wii/) - I really enjoy playing on the Nintendo Wii, but the games aren’t very cheap. To overcome this problem, I spent the whole weekend on hacking/soft modding my Wii and I succeeded. From now on I can start downloading my favorite games, instead of spending lots of money. I have the option to boot my games - [Microsoft CA certificate validity period](https://www.booches.nl/2009/06/microsoft-ca-certificate-validity-period/) - Using a Microsoft CA is very common in network to issue self-signed certificates. Last week I had to configure a Windows IIS server with client certificate authorization. Remote people (non Active Directory users) need a client certificate to browse to a specific website. The communication between the remote user and the website is secure by - [Juniper SA – Host Checker](https://www.booches.nl/2009/05/juniper-sa-host-checker/) - Security is getting more and more important for people. I notice that especially IT manager would like to implement some kind of security measurements to improve the safety of their network and data. Lately I have been busy with configuring a Juniper SA solution. The customer wants to publish different kind of services through the - [Juniper SA & Terminal Server with Novell Client SSO](https://www.booches.nl/2009/05/juniper-sa-terminal-server-with-novell-client-sso/) - Normally configuring SSO on a Terminal Server in conjunction with a Juniper SA isn’t that hard. On the Juniper you pass the user credentials to the Terminal Server. On a normal Terminal Server you have to check the following: Disable Always prompt for password under: Terminal Services Configuration –> Connections –> Properties of RDP-tcp –> - [Juniper SA & Terminal Service with JavaRDP](https://www.booches.nl/2009/05/juniper-sa-terminal-service-with-javardp/) - Today I tried to configure a JavaRDP as fallback Terminal Services method on the Juniper SA appliances. It took me some time and with help of my colleague, I finally got it working. Even with Single Sign On to the Terminal Server. First of all, you need to upload a new Java applet. The Java - [Secret Barracuda Spam firewall options](https://www.booches.nl/2009/05/secret-barracuda-spam-firewall-options/) - While troubleshooting a Barracuda Spam Firewall 300 I found a forum on internet, which shows you how to get an extra tab under the Advanced configuration of the Barracuda Spam Firewall. The “secret” configuration page is enabled with the following steps: Logon to the Barracude Spam Firewall 300; Click on the Advanced tab; Add &expert=1 - [ASDM Error: Unconnected socket not implemented](https://www.booches.nl/2008/12/asdm-error-unconnected-socket-not-implemented/) - When you receive the following error, while starting ASDM: ASDM Error: Unconnected socket not implemented You should look at your Java versions. When you are using Java 6 Update 10 or higher and ASDM 6.1.5 or lower, you will receive this error. There are two workarounds for this problem: Downgrade Java to Java 6 Update - [Secure LDAP between Softerra and Novell NDS](https://www.booches.nl/2009/04/secure-ldap-between-softerra-and-novell-nds/) - Softerra LDAP Browser is a powerful tool for browsing servers, which support LDAP. Using Softerra LDAP Browser against a Novell NDS with secure LDAP is a different story. A secure LDAP connection is a connection which uses SSL certificates to encrypt the data stream. I had to use my LDAP Browser to query a Novell - [802.1Q between Catalyst 3750 en PowerConnect 6226](https://www.booches.nl/2009/04/8021q-between-catalyst-3750-en-powerconnect-6226/) - Configuring a 802.1Q connection isn’t that difficult, but you need to know the command line interface and the appropriate commands. Today I configured a 802.1Q connection between a Cisco Catalyst 3750G and a Dell PowerConnect 6226, while configuring I played a little with the trunking options on the PowerConnect and I noticed the following: The - [Strange VPDN-GROUP behavior](https://www.booches.nl/2009/04/strange-vpdn-group-behavior/) - I noticed some strange behavior in a vpdn-group configuration on a Cisco 876 router. I have a router with the following vpdn-group configuration: vpdn-group pptp-group ! Default PPTP VPDN group description pptp vpn users accept-dialin protocol pptp virtual-template 10 The configuration is working perfectly and users can dialin using a PPTP connection. Backups of the - [XMODEM recovery speed](https://www.booches.nl/2009/03/xmodem-recovery-speed/) - Configuring switches and routers is regular work for me. But if I would like to configure a switch or a router, I have to be able to boot the specific device…. Today I had to configure some new Cisco Catalyst 3650(E) en 3750 switches. In total I had 16 switches to configure, but three of - [Link State Tracking](https://www.booches.nl/2009/03/link-state-tracking/) - Last week a friend called me and told me he was having serious problems with his network. A complete blade environment wasn’t able to communicate with the rest of the network. I asked what changed in the network and he told me that he had added a VLAN to a trunk allowed lists. Because he - [RDP and Spooler system service](https://www.booches.nl/2008/08/rdp-and-spooler-system-service/) - My colleagues and I configure a Windows server from time-to-time. Mostly when we configure a server, it is a server which is placed in the DMZ zone, like an ISA Reverse Proxy or Citrix Secure Gateway. Recently I spoke with a colleague and we started discussing the running services under Windows. After installing a Windows - [Custom ringtones and SMS sounds on iPhone 3G](https://www.booches.nl/2009/02/custom-ringtones-on-iphone-3g/) - I received an iPhone 3G with a new cell phone contract. I started to play a little with it and noticed that there are only a few ringtones on the iPhone. Of course you can get more ringtones, but you have to get them through iTunes and pay for them, and that is not my - [Another NVRAM broken?](https://www.booches.nl/2009/01/another-nvram-broken/) - On Monday I visited another customer who had problems saving the running configuration of a Cisco devices. The devices involved were a Cisco 2620 and a Cisco 2610XM router. Both routers weren't able to save their running configuration. Both routers show the following error-message: startup-config file open failed (Bad file number) By both routers I - [NVRAM corrupt or broken?](https://www.booches.nl/2009/01/nvram-corrupt-or-broken/) - Today some of my colleagues and I "rebuild" an existing ESX with NetApp network. We change multiple VLAN's and did a lot of reconfiguring. Unfortunately some other people were working on the power, so sometimes all equipment had to power down. After we did our job, we started testing the environment. All DMZ VM's weren't - [Cisco ASA & ESX: strange ARP behavior](https://www.booches.nl/2009/01/cisco-asa-esx-strange-arp-behavior/) - Last week I had a very strange problem with a Cisco ASA firewall. The firewall is configured with multiple interfaces, including a DMZ interface. There are multiple servers in the DMZ. These servers are physical and virtual servers. The virtual servers are VMware servers in a blade environment. I configured the feature ip verify reverse-path - [VPN Filtering through Group Policy](https://www.booches.nl/2009/01/vpn-filtering-through-group-policy/) - When configuring a Remote Access VPN or a Site to Site VPN connection you have the ability to filter traffic entering and leaving the VPN connection. You have the ability to enable inbound IPsec sessions to bypass interface access lists. Group policy and per-user authorization access lists still apply to the traffic. The sysopt connection - [RSA LDAP query failed](https://www.booches.nl/2009/01/rsa-ldap-query-failed/) - While configuring a LDAP mapping for a RSA Authentication Manager 6.1 with an Active Directory Domain Controller, I received the following error while running the Synchronisation task c:\RSA\prog\sdldapsync.exe -j 102 "[LDAP search] Search failed (check Base DN)" At first I thought about a typo while configuring the Synchronisation task. To test the LDAP connection with - [Cisco 877W wireless authentication failed](https://www.booches.nl/2009/01/cisco-877w-wireless-authentication-failed/) - At home I have a Cisco 877W router. I use the wireless functionality to connect the different laptops to the networks. After upgrading the software from the router I have problems with the wireless authentication. The router is working perfectly, but after some time the laptops are able to connect to the wireless network. Vista - [Access rules DMZ components](https://www.booches.nl/2009/01/access-rules-dmz-components/) - Finally he first post in 2009, so before starting, HAPPY NEW YEAR!!!!! I know it's late, but who cares.... This post is about opening specific ports from the DMZ to the internal network. This specific topic often results in discussions about which ports to open. One of the biggest discussion points is the use of - [Netstat on IOS router](https://www.booches.nl/2008/12/netstat-on-ios-router/) - I often use the netstat command on a Windows machine to check on which IP and/or ports the servers or workstation is listening or established connection. By accident I found the same kind of command for a Cisco IOS router, while I was looking through the CLI. Check out the output below: Router#sh control-plane host - [GRE over IPsec with Cisco ASA](https://www.booches.nl/2008/12/gre-over-ipsec-with-cisco-asa/) - In different scenario's it is required to configure some kind of routing protocol between two offices, but the routers should be configured to look directly connected to each other. Normally I always configure an IPsec VPN between the two offices and configure an additional GRE tunnel over the IPsec VPN tunnel. In that way the - [Microsoft IAG](https://www.booches.nl/2008/11/microsoft-iag/) - It has been a while since my last post, but time is short these days. Today I had to troubleshoot a Microsoft IAG appliance. Microsoft IAG stands for Microsoft Intelligent Application Gateway. And indeed, intelligent it is. NOT. I have seen and configured multiple SSL VPN solutions like Juniper SA, Citrix Access Gateway, Citrix Secure - [Microsoft Outlook through Citrix Access Gateway SSL IP VPN](https://www.booches.nl/2008/10/microsoft-outlook-through-citrix-access-gateway-ssl-ip-vpn/) - One of our customers wants you use their locally installed Microsoft Outlook through a Citrix Access Gateway (CAG). Sales people from that customer travel through the country and use the Outlook offline to read or prepare e-mail to send later. These people use UMTS technology to connect their laptops to the Internet. The customers wants - [Where is the Internet Authentication Service?](https://www.booches.nl/2008/11/where-is-the-internet-authentication-service/) - Microsoft IAS server is often used as RADIUS server to authenticate VPN users or in conjunction with ISA reverse proxy to authenticate OWA users or PDA synchronization. Today I had to install an ISA reverse proxy server with ISA 2006 Standard and Exchange 2007. I wanted to install Microsoft IAS as RADIUS server to authenticate - [Cacti Plugin Management and RealTime Plugin](https://www.booches.nl/2008/10/cacti-plugin-management-and-realtime-plugin/) - I played a little with Cacti today and installed the Plugin Architecture 2.1. While reading some forums a lot of people are talking about the Plugin Management functionality. I looked and searched in my complete Cacti installation, checked all the configurations which can be made, but I couldn't find anything about Plugin Management. After some - [Upgrade Wordpress](https://www.booches.nl/2008/10/upgrade-wordpress/) - I just upgraded my Wordpress version from 2.6 to 2.6.3. So if you notice some strange behavior, feel free to inform me by mail or comment!! - [IEEE 802.3x FlowControl between Cat3750E and Cat2960](https://www.booches.nl/2008/10/ieee-8023x-flowcontrol-between-cat3750e-and-cat2960/) - I have a network with two Catalyst 3750E switch stacks, which are connected with a 2 x 10Gbps Etherchannel. Every stack facilitates a ring topology of approximately 10 to 15 Catalyst 2960 switches. Two of the 2960 are connected with 1Gbps links to a switch stack to create the ring topology. So lets say that - [Company transportation....](https://www.booches.nl/2008/10/company-transportation/) - Today I am working at a customer who has two locations in a very very small town. The "head quarters" is located in the center of town and the factory is located outside the town. On both locations I have to replace all network components, so there is some traveling between both locations. So one - [Telnet Time-Out is killing me....](https://www.booches.nl/2008/10/telnet-time-out-is-killing-me/) - Aaarrrgggghhh, I hate it when I would like to telnet into a device and enter the wrong IP address. This means, by default, waiting for 30 seconds before being able to correct the IP address and start a new telnet session, because there is no escape sequence. SW01#telnet 10.100.12.250 Trying 10.100.12.250 ... % Connection timed out; - [What is an UPLINK port?](https://www.booches.nl/2008/10/what-is-an-uplink-port/) - A colleague recently encountered some problems with keepalives on switch ports. He wrote a post about it. Keepalives are, quoted from his blog post: By default Cisco routers and switches periodically test their (Fast) Ethernet links by sending out Loopback frames (ethertype 0×9000) addressed to themselves. Call it a “L2 self-ping” if you will. In - [Alias IOS Command](https://www.booches.nl/2008/10/alias-ios-command/) - When configuring a router I often use different show commands to check or troubleshoot the configuration. I always hate to type in the whole show command, so I use aliases instead. Aliases are also used in the Open Source community, when working with a terminal. There are multiple options for the alias command, lets take - [DSL Terminology](https://www.booches.nl/2008/10/dsl-terminology/) - When configuring DSL or other analog connection, I sometimes have problems with the specific terminologies used in these technologies. I found a post explaining the terminology used for understanding Cisco DSL statistics. Reading this post helps me remember the terminology. Taken from the post: To troubleshoot Layer 1 problems, you can use the show dsl - [Fiber optics and UDLD](https://www.booches.nl/2008/10/fiber-optics-and-udld/) - UDLD (Unidirectional Link Detection) is a protocol to help prevent forwarding loops in switched networks. A fiber cable is build from two separate fibers (transmit and receive), where one of the two fiber could fail, which would result in a switch port not able to receive or send traffic. This scenario could result in some - [Failed to establish VPN through PIX](https://www.booches.nl/2008/10/failed-to-establish-vpn-through-pix/) - We migrated our Internet connection lately and reconfigured our PIX firewall. We added some memory to install the latest firmware version (8.0(4)). After putting the PIX firewall in production some of the employees were complaining they couldn't establish any PPTP VPN Tunnels anymore to customers. Every time when some one called me, I tried it - [Tools Page updated](https://www.booches.nl/2008/10/tools-page-updated/) - I added a new tool to the Tools page, called Interface Traffic Indicator. The tool can be compared to STG, but needs to be installed on a workstation. The tool can be used to measure the throughput of a specific interface. To use the tool, you need at least the IP address of the device - [HSRP and ACL's](https://www.booches.nl/2008/10/hsrp-and-acls/) - I added a Guest VLAN to a network environment with two multi layer switches running HSRP. To secure the internal network from the Guest VLAN, I added a ACL to the Guest VLAN SVI. The ACL is stated below: ip access-list extended GUEST-DENY-RFC1918 remark Allow DHCP permit udp any eq bootpc any remark Deny RFC - [Fully Automated Nagios](https://www.booches.nl/2008/09/fully-automated-nagios/) - A colleague noticed the new developments regarding Nagios. Nagios is an Open Source host, service and network monitoring program. I always had my doubts about Nagios, especially about the manageability of the application. The installation and configuration of Nagios can be very time consuming. And a lot of customers are "afraid" of using Nagios, because - [Cisco.com Searches and Tools](https://www.booches.nl/2008/09/ciscocom-searches-and-tools/) - Cisco published some tool and search plugins to your Internet Explorer 7 and Firefox 2/Firefox 3 browser. This makes it possible to quickly search the Cisco.com website for a particular question or item. Check the following website for more information: http://www.cisco.com/web/tsweb/searchplugins/plugin_homepage.html# - [Cisco IOS Flexible NetFlow](https://www.booches.nl/2008/09/cisco-ios-flexible-netflow/) - Browsing through the Cisco White Papers I stumbled on a new white paper about Flexible NetFlow. According to the white paper, Flexible NetFlow provides enhanced optimization of the network infrastructure, reduces costs, and improves capacity planning and security detection beyond other flow based technologies available today. Key Advantages to using Flexible NetFlow: Flexibility, scalability, aggregation - [Another Ictivity Connectivity blog](https://www.booches.nl/2008/09/another-ictivity-connectivity-blog/) - Another Ictivity Connectivity Consultant started a blog on the internet. Peter Bazelmans, a very experienced Connectivity Consultant started the blog PBSPlaza - Building things with IP... Check out some outtakes from this blog: The nice thing working with Cisco is that you always hear about features from which you never heard before. This is also - [Configuration Mode Locking](https://www.booches.nl/2008/09/configuration-locking/) - While browsing some networking related blogs, so stumbled on a nice new feature in Cisco IOS on 6200networks.com. The feature prevents multiple users from changing the configuration of a network component simultaneous. This feature, configuration mode locking, is available in two different modes: Automatic - the session is locked, when you log in to the - [Secure Copy Server Cisco ASA](https://www.booches.nl/2008/09/secure-copy-server-cisco-asa/) - Lately there are a lot of changes in the firmware and the ASDM for the Cisco ASA firewalls. This means a lot of copying from files to the flash memory of the specific appliances. Normally when upgrading the software from an appliance I use a computer on the customer network. This could be my own - [Change password through LDAPS on ISA server](https://www.booches.nl/2008/08/change-password-through-isa-server/) - Today I received the question about allowing users to changes his/her password through webmail, whereby webmail is published via an ISA server 2006 reverse proxy. This is possible, but it requires the configuration of LDAPS to authenticate users. I started by configuring a Certificate Authority (CA) on a member server in the domain. During the - [Cisco RPS 2300](https://www.booches.nl/2008/08/cisco-rps-2300/) - Lately I was looking at the Cisco Redundant Power System 2300, because this unit delivers power supply redundancy and resiliency for different power requirements. The RPS 2300 helps to seamlessly failover in the event of power failures. Depending on the number of internal power supplies, the RPS 2300 can provide redundant power of up to - [PDA Active Sync - Invalid Certificate](https://www.booches.nl/2008/06/pda-active-sync-invalid-certificate/) - The usage of Pocket PCs (PDAs) becomes more and more a default feature for business. The last months I have installed quit some Windows ISA 2006 servers for Reverse Proxy purposes. I have installed them normally for webmail only, but lately I have added the Microsoft Active Sync feature. The Pocket PCs connect to the - [Secure HSRP configuration](https://www.booches.nl/2008/07/secure-hsrp-configuration/) - A friend of mine works for a well known auditing and penetration testing company in the Netherlands. Recently we were talking about how he starts looking for flaws in network infrastructures. My friend told me that the first thing he does is simply starting WireShark and start looking at all the packets he receives. By - [eSafe Configuration Restore](https://www.booches.nl/2008/07/esafe-configuration-restore/) - Some of our customers use eSafe as forwarding proxy for SMTP and HTTP scanning. Today I had to restore an eSafe, which is configured in NitroInspection II Router mode. I had created a backup configuration file from the running eSafe server and installed a new eSafe server with the default settings. After the installation I - [Serious DNS Vulnerability](https://www.booches.nl/2008/07/serious-dns-vulnerability/) - I guess you already read about it, but if not here a short outcome. Despite Dan Kaminsky's efforts to keep a lid on the details of the critical DNS vulnerability he found, someone at the security firm Matasano leaked the information on its blog yesterday, then quickly pulled the post down. But not before others - [IBM Blade with Nortel and HP switches](https://www.booches.nl/2008/07/ibm-blade-with-nortel-and-hp-switches/) - Today I had to troubleshoot an IBM Blade system. The customer was complaining that all servers, except one, weren't able to communicate with the rest of the network. The blade system contains two Nortel switches. Each Nortel switch is connected with a 3 Gbps LACP channel to separate HP switches. The HP switches are the - [Auto Backup Configurations](https://www.booches.nl/2008/07/auto-backup-config/) - Till recently I didn't have a decent way to backup configurations from routers and switches without using some kind of management tool, like Cacti or Nagios. I wanted to automatically backup configurations by only using a TFTP or FTP server on a network. I started looking and found the solution by using the archive and - [Blog offline.. and online again](https://www.booches.nl/2008/07/website-offline/) - This blog was offline for a couple of days, because my ISP thought it would be cool to change the public IP address. I bought a house with my girl and we are still rebuilding the place. However the end is near. I already signed up with an ISP, which is XS4ALL. It is always - [Automatic Log In Reverse Proxy with FBA](https://www.booches.nl/2008/07/automatic-log-in-reverse-proxy-with-fba/) - Recently I configured another ISA 2006 server as reverse proxy to publish the Exchange 2007 OWA environment on a secure way to the internet. The customer where I configured the reverse proxy is migrating from Novell GroupWise to Microsoft Exchange. During the migration period, the customer has specific requirements when connecting to the webmail environment - [ISA 2006 Authentication over HTTP](https://www.booches.nl/2008/07/isa-2006-authentication-over-http/) - I implemented different ISA 2006 Reverse Proxy servers in conjunction with Microsoft Exchange 2003 or Windows Exchange 2007. Today I configured ISA 2006 with Exchange 2007. I configured the Reverse Proxy server as I did always. And the connection from outside the network works perfectly. On the internal Exchange server I configured Basic and Integrated - [PIX / ASA - Threat Detection](https://www.booches.nl/2008/06/pix-asa-thread-detection/) - From software release 8.0 and later the Cisco PIX and Cisco ASA firewalls support the feature called Threat Detection. In the default configuration Basic Threat Detection is enabled on the security appliance. Using Threat Detection the appliance monitors the rate of dropped packets and security events due to these reasons (Source): Denial by access lists; - [Great colleague leaves Ictivity](https://www.booches.nl/2008/06/great-colleague-leaves-ictivity/) - My, now official, former colleague Duncan Epping left Ictivity and is going to work for VMware as Senior PSO Consultant. Duncan is the owner of the Yellow-Bricks blog, which you need to check on interesting posts on VMware. Duncan, it was great working with you. I learned a lot about VMware from you. Good luck - [Campus QoS Design Add-On](https://www.booches.nl/2008/06/campus-qos-design-add-on/) - Yesterday I attended the QoS Design session and blogged on the subject. After posting the blog on the internet I received an e-mail about a statement in the blog. I placed the following statement on the blog: "Remember e-mail is NOT mission-critical." In the e-mail I received the following comment on this statement. "What he - [Customer Appreciation Event](https://www.booches.nl/2008/06/customer-appreciation-event/) - Last night Cisco organized the Cisco Customer Appreciation Event. The event took place at Universal Orlando. I thought that should be cool and it really was...... A big part of the park was closed and only accessible for Cisco Live attendees. All the different rides were open, like the Mummy Returns, Terminator 2-D, Twister and - [Campus QoS Design](https://www.booches.nl/2008/06/campus-qos-design/) - What can somebody tell me about QoS after I passed the Cisco QoS (642-642) exam just one hour ago ?!?!?! ;-). A lot as I noticed from the session. When designing QoS SLA's are very important. What are the required latency, jitter and data loss for the different applications, which traffic is really mission-critical and - [Passed Exam 642-642 Cisco QoS](https://www.booches.nl/2008/06/passed-exam-642-642-cisco-qos/) - During the Cisco Live conference you have to opportunity to take one exam certification for free. I am currently learning for my CCVP certification. I started with exam 642-642 which is all about Quality of Service. I thought to myself: "Lets give it a try!!". I was stunned by the passing score of 940 out - [Troubleshooting EIGRP](https://www.booches.nl/2008/06/troubleshooting-eigrp/) - This session during Cisco Live coverted the troubleshooting of the routing protocol EIGRP - [Cisco Firewall Design and Deployment](https://www.booches.nl/2008/06/firewall-design-and-deployment/) - The session about firewall design and deployment didn't reveal a lot of new things about the Cisco ASA appliance or FWSM module. The only new thing for me was the possibility to configure a redundant interface for a Cisco ASA appliance. The screen shot below shows the cabling scheme for an implementation with and without - [Cisco Live - A lot of rude people](https://www.booches.nl/2008/06/cisco-live-a-lot-of-rude-people/) - I haven't seen so much rude people in one place during the first day of Cisco Live 2008. I noticed during all the sessions and especially during the general keynote by Cisco's CEO John Chambers a lot of people left the room, when they noticed that the session was going to an end. I don't - [Wired 802.1X](https://www.booches.nl/2008/06/wired-8021x/) - The session about wired 802.1X deployment was really interesting. I was stunned about the information I already knew after my testing with MAC Authentication Bypass last week. Of course the speaker had more configuration options when configuring the switch ports. Important for me to hear where the ways for deploying 802.1X in environments. It isn't - [Cisco IOS Security](https://www.booches.nl/2008/06/cisco-ios-security/) - The first session I attended is about Deploying IOS Security. The session is about using the Cisco IOS as firewall to protect branch offices. We discussed normal classic firewalling and zone-based firewalling. I normally use classing firewalling, but I guess I have to try zone-based firewalling in the future. The advantage of zone-based firewalling is - [Cisco Live 2008](https://www.booches.nl/2008/06/cisco-live-2008/) - It took a while to finally register for Cisco Networkers / Live. First we wanted to attend last year, then we wanted to attend in Barcelona, Spain, but there were no more tickets. Now I am sitting in my hotel room in Orlando, Florida after a long trip getting here. My colleague and I left - [ID Control](https://www.booches.nl/2008/06/id-control/) - Discussing different authentication products from ID Control - [New look and feel!!](https://www.booches.nl/2008/06/new-look/) - I updated the theme I use for my blog and I noticed that the RSS feeds weren't working for me anymore. I had to subscribe again before the RSS entries were updated again. So for those of you who have subscribed to my RSS feed, maybe you have to unsubscribe and subscribe again to get - [Another colleague starts blogging again](https://www.booches.nl/2008/06/another-colleague-start-blogging-again/) - Yep, there is another one. His name is Ivo Beerens. Ivo is another VMWare consultant at Ictivity. His blog contains post many categories, but is mostly related to VMWare. His blog can be found at IvoBeerens.eu. A couple of outtakes from his blog: directly access a VDM Connection Server by using the hostname of the - [Juniper SA publish custom ICA](https://www.booches.nl/2008/06/juniper-sa-publish-custom-ica/) - I have deployed more Juniper SA 2000 appliance and in overall I am pleased with the working of the appliance. Sometimes we have minor problems when publishing ICA sessions through the appliance. My colleagues have customers with connection problems, where suddenly the ICA sessions get disconnected and we cannot find the cause of these disconnects. - [Change ESX host IP address](https://www.booches.nl/2008/06/change-esx-host-ip-address/) - Monday I had to migrate an existing network. I added more VLAN's to the network for segmentation and breaking the broadcast domain. I introduced a regular VLAN, a VoIP VLAN and a management VLAN. So far no problem. The customer is using Cisco Catalyst 3750G and Cisco Catalyst 3560 switches with PoE. I configured the - [WebMarshal performance problems](https://www.booches.nl/2008/05/webmarshal/) - One of our customers is using WebMarshal for HTTP/HTTPS URL filtering and content scanning. The WebMarshall software is installed on two Microsoft ISA 2003 servers. These ISA servers are behind a Cisco Content Switch for load-balancing and redundancy purposes. The problem with the WebMarshal is the PERFORMANCE. Internet browsing with the WebMarshal as proxy just - [Blogging colleagues](https://www.booches.nl/2008/05/blogging-colleagues/) - I am not the only one from Ictivity spamming the Internet with my blog. Their are more Consultants, from different disciplines, who share their knowledge with other people. Let's have a closer look at them. Yellow Bricks Recently my colleague Duncan Epping already introduced me on his personal blog. Duncan is Virtualization Consultant for Ictivity, - [Exchange 2007 with ISA 2006](https://www.booches.nl/2008/05/exchange-2007-with-isa-2006/) - Today I have be working on publishing Microsoft Exchange Outlook WebAccess and Active Sync to the Internet. We had some discussions with some Microsoft Consultants about a secure way to publish Outlook Web Access to the Internet, especially the authentication part of such a solution. Some people are talking about publishing OWA directly to the - [HP Blade Switch Development](https://www.booches.nl/2008/05/hp-blade-switches/) - HP Blade Switch Development with Cisco Catalyst Blade Switch 3120 Series - [Network simulator](https://www.booches.nl/2008/04/network-simulator/) - More often I have to change critical configuration options in live environments, but sometimes I don't no the effect of these changes on the network. So I would like to build a test network where I can check the impact of the configuration changes. A good network simulator would definitely help in this situation. Cisco - [Cisco Networkers 2008](https://www.booches.nl/2008/03/cisco-networkers/) - Cisco Live (aka Cisco Networkers) 2008 has opened the registration for Orlando, Florida. Cisco Live is Cisco's annual IT and communications conference. The conference features Networkers, the premier education and training program, and other special programs designed to meet the diverse needs of today's IT and communications professional from increasing technical proficiency to understanding the - [HP ProCurve licenses](https://www.booches.nl/2008/03/hp-procurve-licenses/) - During an check-up on a network, I looked at the configuration of two HP ProCurve 5400zl switches. One of these switches functions as the core switch and default gateway for the various VLANs. To improve the availability and redundancy of the default gateway, I mentioned the configuration of VRRP (Virtual Router Redundancy Protocol). On of - [ProCurve excessive STP topology changes](https://www.booches.nl/2008/03/procurve-excessive-stp-topology-changes/) - Recently a colleque of mine noticed something strange in the STP configuration from a couple of HP ProCurve switches. He had a network, which was configured by another party, with switches running MST en RSTP mode spanning-tree. He noticed a lot of topology changes in the configuration, but couldn't find out where they were coming - [relays.ordb.org](https://www.booches.nl/2008/03/relaysordborg/) - Since the day before yesterday, some of our customers complained having problems with receiving e-mail. The senders from the e-mail noticed that their mail had been blocked by relays.ordb.org. This RBL is offline, according to this article, at least everybody thought. Seems to me, the RBL came online yesterday and blocked everything. I have heard - [Barracuda User Creation](https://www.booches.nl/2008/03/barracuda-user-creation/) - I have a customer running a Barracuda SPAM firewall 300. The customer has the specific request that only the administrator can look at Quarantine messages and users shouldn't get their own Quarantine inbox. To accomplish this I have configured the Quarantine Type: Global. I see that all Quarantine messages are delivered in the globally configured - [Cacti, easy going](https://www.booches.nl/2008/04/cacti-easy-going/) - A decent management server is very important in a network, at least that is my opinion. The most important aspect of a management server is its user friendliness. Our customers are most of the time busy with their own problems and the problems of end users, which include all kind of (silly) problems. So the ## Pages - [About](https://www.booches.nl/about/) - Welcome to Booches.nl, a personal blog dedicated to the world of Connectivity. For me, Connectivity encompasses everything related to IT network infrastructures and the ever-evolving software and hardware that power them. You'll find insights and experiences on various components, with a focus on industry-leading vendors like HPE Aruba, Fortinet, and more. I also share practical ## Categories - [Other stuff...](https://www.booches.nl/category/other-stuff/) - [Management](https://www.booches.nl/category/management/) - [Switching](https://www.booches.nl/category/switching/) - [Routing](https://www.booches.nl/category/routing/) - [Firewalling](https://www.booches.nl/category/firewalling/) - [Mail relaying](https://www.booches.nl/category/mail-relaying/) - [Anti-virus / Anti-SPAM](https://www.booches.nl/category/anti-virus-anti-spam/) - [IP Telephony](https://www.booches.nl/category/ip-telephony/) - [Configuration Example](https://www.booches.nl/category/configuration-example/) - [Proxy](https://www.booches.nl/category/proxy/) - [IPSec / SSL VPN](https://www.booches.nl/category/ipsec-ssl-vpn/) - [Security](https://www.booches.nl/category/security/) - [Quality of Service](https://www.booches.nl/category/quality-of-service/) - [IDS / IPS](https://www.booches.nl/category/ids-ips/) - [Wireless](https://www.booches.nl/category/wireless-3/) - [Fortinet](https://www.booches.nl/category/fortinet/) - [Aruba Networks](https://www.booches.nl/category/aruba-networks/) - [Cisco](https://www.booches.nl/category/cisco/) - [ClearPass](https://www.booches.nl/category/clearpass/) - [Come-in-Handy](https://www.booches.nl/category/come-in-handy/) - [Python](https://www.booches.nl/category/python/) - [HPE Aruba](https://www.booches.nl/category/hpe-aruba/) ## Tags - [Cisco](https://www.booches.nl/tag/cisco/) - [Cisco networkers](https://www.booches.nl/tag/cisco-networkers/) - [Cisco live](https://www.booches.nl/tag/cisco-live/) - [Orlando](https://www.booches.nl/tag/orlando/) - [Florida](https://www.booches.nl/tag/florida/) - [HP](https://www.booches.nl/tag/hp/) - [ProCurve](https://www.booches.nl/tag/procurve/) - [Premium](https://www.booches.nl/tag/premium/) - [Base](https://www.booches.nl/tag/base/) - [license](https://www.booches.nl/tag/license/) - [NTP](https://www.booches.nl/tag/ntp/) - [MST](https://www.booches.nl/tag/mst/) - [RSTP](https://www.booches.nl/tag/rstp/) - [topology](https://www.booches.nl/tag/topology/) - [changes](https://www.booches.nl/tag/changes/) - [5412](https://www.booches.nl/tag/5412/) - [5412zl](https://www.booches.nl/tag/5412zl/) - [3500](https://www.booches.nl/tag/3500/) - [3500yl](https://www.booches.nl/tag/3500yl/) - [relays.ordb.org](https://www.booches.nl/tag/relaysordborg/) - [ordb](https://www.booches.nl/tag/ordb/) - [mail](https://www.booches.nl/tag/mail/) - [problems](https://www.booches.nl/tag/problems/) - [Barracuda](https://www.booches.nl/tag/barracuda/) - [SPAM](https://www.booches.nl/tag/spam/) - [firewall](https://www.booches.nl/tag/firewall/) - [user](https://www.booches.nl/tag/user/) - [creation](https://www.booches.nl/tag/creation/) - [account](https://www.booches.nl/tag/account/) - [LACP](https://www.booches.nl/tag/lacp/) - [port-channel](https://www.booches.nl/tag/port-channel/) - [ESX](https://www.booches.nl/tag/esx/) - [etherchannel](https://www.booches.nl/tag/etherchannel/) - [esxtop](https://www.booches.nl/tag/esxtop/) - [src-map](https://www.booches.nl/tag/src-map/) - [src-dst-ip](https://www.booches.nl/tag/src-dst-ip/) - [src](https://www.booches.nl/tag/src/) - [dst](https://www.booches.nl/tag/dst/) - [mac](https://www.booches.nl/tag/mac/) - [ip](https://www.booches.nl/tag/ip/) - [load](https://www.booches.nl/tag/load/) - [balancing](https://www.booches.nl/tag/balancing/) - [load-balancing](https://www.booches.nl/tag/load-balancing/) - [cacti](https://www.booches.nl/tag/cacti/) - [cactiez](https://www.booches.nl/tag/cactiez/) - [cisco works](https://www.booches.nl/tag/cisco-works/) - [hp openview](https://www.booches.nl/tag/hp-openview/) - [nagios](https://www.booches.nl/tag/nagios/) - [rrdtool](https://www.booches.nl/tag/rrdtool/) - [switchmap](https://www.booches.nl/tag/switchmap/) - [voip](https://www.booches.nl/tag/voip/) - [rtp](https://www.booches.nl/tag/rtp/) - [rtcp](https://www.booches.nl/tag/rtcp/) - [h.323](https://www.booches.nl/tag/h323/) - [h.245](https://www.booches.nl/tag/h245/) - [h.225](https://www.booches.nl/tag/h225/) - [MGCP](https://www.booches.nl/tag/mgcp/) - [SCCP](https://www.booches.nl/tag/sccp/) - [SGCP](https://www.booches.nl/tag/sgcp/) - [payload](https://www.booches.nl/tag/payload/) - [signaling](https://www.booches.nl/tag/signaling/) - [1720](https://www.booches.nl/tag/1720/) - [2427](https://www.booches.nl/tag/2427/) - [2428](https://www.booches.nl/tag/2428/) - [UDP](https://www.booches.nl/tag/udp/) - [TCP](https://www.booches.nl/tag/tcp/) - [eSafe](https://www.booches.nl/tag/esafe/) - [gateway](https://www.booches.nl/tag/gateway/) - [ldap](https://www.booches.nl/tag/ldap/) - [maxpagesize](https://www.booches.nl/tag/maxpagesize/) - [active](https://www.booches.nl/tag/active/) - [directory](https://www.booches.nl/tag/directory/) - [publicfolders](https://www.booches.nl/tag/publicfolders/) - [NDR](https://www.booches.nl/tag/ndr/) - [non-delivery](https://www.booches.nl/tag/non-delivery/) - [report](https://www.booches.nl/tag/report/) - [objectclass](https://www.booches.nl/tag/objectclass/) - [remote](https://www.booches.nl/tag/remote/) - [change](https://www.booches.nl/tag/change/) - [network](https://www.booches.nl/tag/network/) - [simulator](https://www.booches.nl/tag/simulator/) - [dynamips](https://www.booches.nl/tag/dynamips/) - [dynagen](https://www.booches.nl/tag/dynagen/) - [gns3](https://www.booches.nl/tag/gns3/) - [ias](https://www.booches.nl/tag/ias/) - [radius](https://www.booches.nl/tag/radius/) - [privilege](https://www.booches.nl/tag/privilege/) - [level](https://www.booches.nl/tag/level/) - [shell:priv-lvl=15](https://www.booches.nl/tag/shellpriv-lvl15/) - [authenticate](https://www.booches.nl/tag/authentication/) - [authorization](https://www.booches.nl/tag/authorization/) - [bgp](https://www.booches.nl/tag/bgp/) - [multihoming](https://www.booches.nl/tag/multihoming/) - [ISP](https://www.booches.nl/tag/isp/) - [local](https://www.booches.nl/tag/local/) - [AS](https://www.booches.nl/tag/as/) - [blade](https://www.booches.nl/tag/blade/) - [3120G](https://www.booches.nl/tag/3120g/) - [3120X](https://www.booches.nl/tag/3120x/) - [stack](https://www.booches.nl/tag/stack/) - [isa](https://www.booches.nl/tag/isa/) - [2006](https://www.booches.nl/tag/2006/) - [exchange](https://www.booches.nl/tag/exchange/) - [2007](https://www.booches.nl/tag/2007/) - [owa](https://www.booches.nl/tag/owa/) - [outlook](https://www.booches.nl/tag/outlook/) - [web](https://www.booches.nl/tag/web/) - [access](https://www.booches.nl/tag/access/) - [sync](https://www.booches.nl/tag/sync/) - [microsoft](https://www.booches.nl/tag/microsoft/) - [server](https://www.booches.nl/tag/server/) - [publish](https://www.booches.nl/tag/publish/) - [ldaps](https://www.booches.nl/tag/ldaps/) - [isaserver.org](https://www.booches.nl/tag/isaserverorg/) - [vmware](https://www.booches.nl/tag/vmware/) - [port](https://www.booches.nl/tag/port/) - [channel](https://www.booches.nl/tag/channel/) - [configuration](https://www.booches.nl/tag/configuration/) - [switchport](https://www.booches.nl/tag/switchport/) - [channel-group](https://www.booches.nl/tag/channel-group/) - [Synology](https://www.booches.nl/tag/synology/) - [DS](https://www.booches.nl/tag/ds/) - [107+](https://www.booches.nl/tag/107/) - [virtual](https://www.booches.nl/tag/virtual/) - [hosts](https://www.booches.nl/tag/hosts/) - [host](https://www.booches.nl/tag/host/) - [httpd.conf-user](https://www.booches.nl/tag/httpdconf-user/) - [httpd-vhosts.conf](https://www.booches.nl/tag/httpd-vhostsconf/) - [webmarshal](https://www.booches.nl/tag/webmarshal/) - [performance](https://www.booches.nl/tag/performance/) - [bad](https://www.booches.nl/tag/bad/) - [static](https://www.booches.nl/tag/static/) - [ARP](https://www.booches.nl/tag/arp/) - [Content](https://www.booches.nl/tag/content/) - [switch](https://www.booches.nl/tag/switch/) - [ha](https://www.booches.nl/tag/ha/) - [failure](https://www.booches.nl/tag/failure/) - [vlan](https://www.booches.nl/tag/vlan/) - [segmentation](https://www.booches.nl/tag/segmentation/) - [IOS](https://www.booches.nl/tag/ios/) - [juniper](https://www.booches.nl/tag/juniper/) - [sa](https://www.booches.nl/tag/sa/) - [2000](https://www.booches.nl/tag/2000/) - [windows](https://www.booches.nl/tag/windows/) - [2003](https://www.booches.nl/tag/2003/) - [custom](https://www.booches.nl/tag/custom/) - [ica](https://www.booches.nl/tag/ica/) - [I/O](https://www.booches.nl/tag/io/) - [pocket](https://www.booches.nl/tag/pocket/) - [pc](https://www.booches.nl/tag/pc/) - [invalid](https://www.booches.nl/tag/invalid/) - [certificate](https://www.booches.nl/tag/certificate/) - [pda](https://www.booches.nl/tag/pda/) - [reverse](https://www.booches.nl/tag/reverse/) - [ssl](https://www.booches.nl/tag/ssl/) - [disable](https://www.booches.nl/tag/disable/) - [on](https://www.booches.nl/tag/on/) - [the](https://www.booches.nl/tag/the/) - [is](https://www.booches.nl/tag/is/) - [bypass](https://www.booches.nl/tag/bypass/) - [802.1x](https://www.booches.nl/tag/8021x/) - [NAC](https://www.booches.nl/tag/nac/) - [NAP](https://www.booches.nl/tag/nap/) - [Guest-VLAN](https://www.booches.nl/tag/guest-vlan/) - [caveats](https://www.booches.nl/tag/caveats/) - [pix](https://www.booches.nl/tag/pix/) - [failover](https://www.booches.nl/tag/failover/) - [normal](https://www.booches.nl/tag/normal/) - [waiting](https://www.booches.nl/tag/waiting/) - [not](https://www.booches.nl/tag/not/) - [working](https://www.booches.nl/tag/working/) - [error](https://www.booches.nl/tag/error/) - [asa](https://www.booches.nl/tag/asa/) - [basic](https://www.booches.nl/tag/basic/) - [threat](https://www.booches.nl/tag/threat/) - [detection](https://www.booches.nl/tag/detection/) - [8.0](https://www.booches.nl/tag/80/) - [what you have](https://www.booches.nl/tag/what-you-have/) - [what you are](https://www.booches.nl/tag/what-you-are/) - [what you know](https://www.booches.nl/tag/what-you-know/) - [ID Control](https://www.booches.nl/tag/id-control/) - [HandyID](https://www.booches.nl/tag/handyid/) - [KeystrokeID](https://www.booches.nl/tag/keystrokeid/) - [USB Token](https://www.booches.nl/tag/usb-token/) - [strong authentication](https://www.booches.nl/tag/strong-authentication/) - [secure](https://www.booches.nl/tag/secure/) - [password](https://www.booches.nl/tag/password/) - [manager](https://www.booches.nl/tag/manager/) - [RSA](https://www.booches.nl/tag/rsa/) - [SecurID](https://www.booches.nl/tag/securid/) - [PKI](https://www.booches.nl/tag/pki/) - [VPN](https://www.booches.nl/tag/vpn/) - [Wake](https://www.booches.nl/tag/wake/) - [LAN](https://www.booches.nl/tag/lan/) - [WOL](https://www.booches.nl/tag/wol/) - [zone-based](https://www.booches.nl/tag/zone-based/) - [classic](https://www.booches.nl/tag/classic/) - [wired](https://www.booches.nl/tag/wired/) - [Inaccessible](https://www.booches.nl/tag/inaccessible/) - [IAB](https://www.booches.nl/tag/iab/) - [FWSM](https://www.booches.nl/tag/fwsm/) - [redundant](https://www.booches.nl/tag/redundant/) - [redundancy](https://www.booches.nl/tag/redundancy/) - [mode](https://www.booches.nl/tag/mode/) - [routed](https://www.booches.nl/tag/routed/) - [transparant](https://www.booches.nl/tag/transparant/) - [multi-context](https://www.booches.nl/tag/multi-context/) - [multiple](https://www.booches.nl/tag/multiple/) - [context](https://www.booches.nl/tag/context/) - [mixed](https://www.booches.nl/tag/mixed/) - [standby](https://www.booches.nl/tag/standby/) - [virtualization](https://www.booches.nl/tag/virtualization/) - [dynamic](https://www.booches.nl/tag/dynamic/) - [protocol](https://www.booches.nl/tag/protocol/) - [site-to-site](https://www.booches.nl/tag/site-to-site/) - [multicast](https://www.booches.nl/tag/multicast/) - [bridging](https://www.booches.nl/tag/bridging/) - [troubleshooting](https://www.booches.nl/tag/troubleshooting/) - [EIGRP](https://www.booches.nl/tag/eigrp/) - [Stuck](https://www.booches.nl/tag/stuck/) - [in](https://www.booches.nl/tag/in/) - [hold](https://www.booches.nl/tag/hold/) - [time](https://www.booches.nl/tag/time/) - [black](https://www.booches.nl/tag/black/) - [hole](https://www.booches.nl/tag/hole/) - [summary](https://www.booches.nl/tag/summary/) - [default-metric](https://www.booches.nl/tag/default-metric/) - [metric](https://www.booches.nl/tag/metric/) - [redistribute](https://www.booches.nl/tag/redistribute/) - [neighbors](https://www.booches.nl/tag/neighbors/) - [table](https://www.booches.nl/tag/table/) - [RTO](https://www.booches.nl/tag/rto/) - [retransmit](https://www.booches.nl/tag/retransmit/) - [out](https://www.booches.nl/tag/out/) - [policing](https://www.booches.nl/tag/policing/) - [shaping](https://www.booches.nl/tag/shaping/) - [trust](https://www.booches.nl/tag/trust/) - [boundary](https://www.booches.nl/tag/boundary/) - [Cos](https://www.booches.nl/tag/cos/) - [DSCP](https://www.booches.nl/tag/dscp/) - [queuing](https://www.booches.nl/tag/queuing/) - [serialization](https://www.booches.nl/tag/serialization/) - [propagation](https://www.booches.nl/tag/propagation/) - [policy](https://www.booches.nl/tag/policy/) - [based](https://www.booches.nl/tag/based/) - [PBR](https://www.booches.nl/tag/pbr/) - [3560](https://www.booches.nl/tag/3560/) - [route-map](https://www.booches.nl/tag/route-map/) - [scanning](https://www.booches.nl/tag/scanning/) - [intrusion](https://www.booches.nl/tag/intrusion/) - [prevention](https://www.booches.nl/tag/prevention/) - [layer](https://www.booches.nl/tag/layer/) - [two](https://www.booches.nl/tag/two/) - [attacks](https://www.booches.nl/tag/attacks/) - [hopping](https://www.booches.nl/tag/hopping/) - [address](https://www.booches.nl/tag/address/) - [DHCP](https://www.booches.nl/tag/dhcp/) - [spoofing](https://www.booches.nl/tag/spoofing/) - [BPDUGuard](https://www.booches.nl/tag/bpduguard/) - [RootGuard](https://www.booches.nl/tag/rootguard/) - [Inspection](https://www.booches.nl/tag/inspection/) - [Source](https://www.booches.nl/tag/source/) - [over](https://www.booches.nl/tag/over/) - [http](https://www.booches.nl/tag/http/) - [forwarding](https://www.booches.nl/tag/forwarding/) - [code](https://www.booches.nl/tag/code/) - [403](https://www.booches.nl/tag/403/) - [12250](https://www.booches.nl/tag/12250/) - [block](https://www.booches.nl/tag/block/) - [requests](https://www.booches.nl/tag/requests/) - [require](https://www.booches.nl/tag/require/) - [automatic](https://www.booches.nl/tag/automatic/) - [log](https://www.booches.nl/tag/log/) - [FBA](https://www.booches.nl/tag/fba/) - [form](https://www.booches.nl/tag/form/) - [POST](https://www.booches.nl/tag/post/) - [statement](https://www.booches.nl/tag/statement/) - [auto](https://www.booches.nl/tag/auto/) - [backup](https://www.booches.nl/tag/backup/) - [configurations](https://www.booches.nl/tag/configurations/) - [archive](https://www.booches.nl/tag/archive/) - [cron](https://www.booches.nl/tag/cron/) - [occurrence](https://www.booches.nl/tag/occurrence/) - [DNS](https://www.booches.nl/tag/dns/) - [vulnerability](https://www.booches.nl/tag/vulnerability/) - [Dan](https://www.booches.nl/tag/dan/) - [Kaminsky](https://www.booches.nl/tag/kaminsky/) - [IBM](https://www.booches.nl/tag/ibm/) - [Nortel](https://www.booches.nl/tag/nortel/) - [Switches](https://www.booches.nl/tag/switches/) - [VRRP](https://www.booches.nl/tag/vrrp/) - [restore](https://www.booches.nl/tag/restore/) - [NitroInspection](https://www.booches.nl/tag/nitroinspection/) - [router](https://www.booches.nl/tag/router/) - [II](https://www.booches.nl/tag/ii/) - [37233](https://www.booches.nl/tag/37233/) - [ifcfg-eth0](https://www.booches.nl/tag/ifcfg-eth0/) - [ifcfg-eth1](https://www.booches.nl/tag/ifcfg-eth1/) - [esafecfg.ini](https://www.booches.nl/tag/esafecfgini/) - [HSRP](https://www.booches.nl/tag/hsrp/) - [DTP](https://www.booches.nl/tag/dtp/) - [CDP](https://www.booches.nl/tag/cdp/) - [MD5](https://www.booches.nl/tag/md5/) - [clear](https://www.booches.nl/tag/clear/) - [text](https://www.booches.nl/tag/text/) - [key-string](https://www.booches.nl/tag/key-string/) - [Yersinia](https://www.booches.nl/tag/yersinia/) - [WireShark](https://www.booches.nl/tag/wireshark/) - [timeout](https://www.booches.nl/tag/timeout/) - [preempt](https://www.booches.nl/tag/preempt/) - [priority](https://www.booches.nl/tag/priority/) - [rps](https://www.booches.nl/tag/rps/) - [2300](https://www.booches.nl/tag/2300/) - [power](https://www.booches.nl/tag/power/) - [system](https://www.booches.nl/tag/system/) - [pwr-rps2300](https://www.booches.nl/tag/pwr-rps2300/) - [C3K-PWR-1150WAC](https://www.booches.nl/tag/c3k-pwr-1150wac/) - [C3K-PWR-750WAC](https://www.booches.nl/tag/c3k-pwr-750wac/) - [CAB-RPS2300-E=](https://www.booches.nl/tag/cab-rps2300-e/) - [CAB-RPS2300](https://www.booches.nl/tag/cab-rps2300/) - [CA](https://www.booches.nl/tag/ca/) - [set](https://www.booches.nl/tag/set/) - [authority](https://www.booches.nl/tag/authority/) - [private](https://www.booches.nl/tag/private/) - [key](https://www.booches.nl/tag/key/) - [FQDN](https://www.booches.nl/tag/fqdn/) - [Spooler](https://www.booches.nl/tag/spooler/) - [print](https://www.booches.nl/tag/print/) - [eventid](https://www.booches.nl/tag/eventid/) - [1114](https://www.booches.nl/tag/1114/) - [lmhost](https://www.booches.nl/tag/lmhost/) - [lookup](https://www.booches.nl/tag/lookup/) - [netbios](https://www.booches.nl/tag/netbios/) - [TermServDevices](https://www.booches.nl/tag/termservdevices/) - [communicating](https://www.booches.nl/tag/communicating/) - [registry](https://www.booches.nl/tag/registry/) - [fEnablePrintRDR](https://www.booches.nl/tag/fenableprintrdr/) - [REG_DWORD](https://www.booches.nl/tag/reg_dword/) - [RDP](https://www.booches.nl/tag/rdp/) - [7.1](https://www.booches.nl/tag/71/) - [6.1](https://www.booches.nl/tag/61/) - [slow](https://www.booches.nl/tag/slow/) - [ssh](https://www.booches.nl/tag/ssh/) - [copy](https://www.booches.nl/tag/copy/) - [asdm](https://www.booches.nl/tag/asdm/) - [scopy](https://www.booches.nl/tag/scopy/) - [puttyscp](https://www.booches.nl/tag/puttyscp/) - [scp](https://www.booches.nl/tag/scp/) - [Cygwin](https://www.booches.nl/tag/cygwin/) - [signing](https://www.booches.nl/tag/signing/) - [request](https://www.booches.nl/tag/request/) - [CSR](https://www.booches.nl/tag/csr/) - [OpenSSL](https://www.booches.nl/tag/openssl/) - [Verisign](https://www.booches.nl/tag/verisign/) - [GeoTrust](https://www.booches.nl/tag/geotrust/) - [generate](https://www.booches.nl/tag/generate/) - [locking](https://www.booches.nl/tag/locking/) - [manual](https://www.booches.nl/tag/manual/) - [Flexible](https://www.booches.nl/tag/flexible/) - [NetFlow](https://www.booches.nl/tag/netflow/) - [white](https://www.booches.nl/tag/white/) - [paper](https://www.booches.nl/tag/paper/) - [Cisco.com](https://www.booches.nl/tag/ciscocom/) - [search](https://www.booches.nl/tag/search/) - [tools](https://www.booches.nl/tag/tools/) - [internet](https://www.booches.nl/tag/internet/) - [explorer](https://www.booches.nl/tag/explorer/) - [7](https://www.booches.nl/tag/7/) - [firefox](https://www.booches.nl/tag/firefox/) - [2](https://www.booches.nl/tag/2/) - [3](https://www.booches.nl/tag/3/) - [fully](https://www.booches.nl/tag/fully/) - [automated](https://www.booches.nl/tag/automated/) - [FAN](https://www.booches.nl/tag/fan/) - [1985](https://www.booches.nl/tag/1985/) - [access-list](https://www.booches.nl/tag/access-list/) - [acl](https://www.booches.nl/tag/acl/) - [list](https://www.booches.nl/tag/list/) - [Hot](https://www.booches.nl/tag/hot/) - [interface](https://www.booches.nl/tag/interface/) - [traffic](https://www.booches.nl/tag/traffic/) - [indicator](https://www.booches.nl/tag/indicator/) - [snmp](https://www.booches.nl/tag/snmp/) - [real-time](https://www.booches.nl/tag/real-time/) - [real](https://www.booches.nl/tag/real/) - [regular](https://www.booches.nl/tag/regular/) - [translation](https://www.booches.nl/tag/translation/) - [failed](https://www.booches.nl/tag/failed/) - [for](https://www.booches.nl/tag/for/) - [47](https://www.booches.nl/tag/47/) - [pptp](https://www.booches.nl/tag/pptp/) - [1723](https://www.booches.nl/tag/1723/) - [GRE](https://www.booches.nl/tag/gre/) - [stateful](https://www.booches.nl/tag/stateful/) - [305006](https://www.booches.nl/tag/305006/) - [UDLD](https://www.booches.nl/tag/udld/) - [unidirectional](https://www.booches.nl/tag/unidirectional/) - [Link](https://www.booches.nl/tag/link/) - [STP](https://www.booches.nl/tag/stp/) - [listening](https://www.booches.nl/tag/listening/) - [learning](https://www.booches.nl/tag/learning/) - [BPDU](https://www.booches.nl/tag/bpdu/) - [aggressive](https://www.booches.nl/tag/aggressive/) - [fiber](https://www.booches.nl/tag/fiber/) - [optics](https://www.booches.nl/tag/optics/) - [DSL](https://www.booches.nl/tag/dsl/) - [show](https://www.booches.nl/tag/show/) - [atm](https://www.booches.nl/tag/atm/) - [noise](https://www.booches.nl/tag/noise/) - [margin](https://www.booches.nl/tag/margin/) - [signal-to-noise](https://www.booches.nl/tag/signal-to-noise/) - [SNR](https://www.booches.nl/tag/snr/) - [ratio](https://www.booches.nl/tag/ratio/) - [downstream](https://www.booches.nl/tag/downstream/) - [upstream](https://www.booches.nl/tag/upstream/) - [attenuation](https://www.booches.nl/tag/attenuation/) - [alias](https://www.booches.nl/tag/alias/) - [exec](https://www.booches.nl/tag/exec/) - [configure](https://www.booches.nl/tag/configure/) - [uplink](https://www.booches.nl/tag/uplink/) - [trunk](https://www.booches.nl/tag/trunk/) - [keepalives](https://www.booches.nl/tag/keepalives/) - [0x9000](https://www.booches.nl/tag/0x9000/) - [synwait](https://www.booches.nl/tag/synwait/) - [synwait-time](https://www.booches.nl/tag/synwait-time/) - [telnet](https://www.booches.nl/tag/telnet/) - [connection](https://www.booches.nl/tag/connection/) - [timed](https://www.booches.nl/tag/timed/) - [flow](https://www.booches.nl/tag/flow/) - [control](https://www.booches.nl/tag/control/) - [flowcontrol](https://www.booches.nl/tag/flowcontrol/) - [802.3x](https://www.booches.nl/tag/8023x/) - [Catalyst](https://www.booches.nl/tag/catalyst/) - [3750](https://www.booches.nl/tag/3750/) - [3750E](https://www.booches.nl/tag/3750e/) - [2960](https://www.booches.nl/tag/2960/) - [congested](https://www.booches.nl/tag/congested/) - [Plugin](https://www.booches.nl/tag/plugin/) - [Architecture](https://www.booches.nl/tag/architecture/) - [enable](https://www.booches.nl/tag/enable/) - [2.1](https://www.booches.nl/tag/21/) - [pa.sql](https://www.booches.nl/tag/pasql/) - [citrix](https://www.booches.nl/tag/citrix/) - [cag](https://www.booches.nl/tag/cag/) - [epmap](https://www.booches.nl/tag/epmap/) - [administrator](https://www.booches.nl/tag/administrator/) - [135](https://www.booches.nl/tag/135/) - [1536](https://www.booches.nl/tag/1536/) - [ampr](https://www.booches.nl/tag/ampr/) - [inter](https://www.booches.nl/tag/inter/) - [ampr-inter](https://www.booches.nl/tag/ampr-inter/) - [synchronization](https://www.booches.nl/tag/synchronization/) - [authenticate](https://www.booches.nl/tag/authenticate/) - [Services](https://www.booches.nl/tag/services/) - [2008](https://www.booches.nl/tag/2008/) - [Network Policy Server](https://www.booches.nl/tag/network-policy-server/) - [Network Policy and Access Service](https://www.booches.nl/tag/network-policy-and-access-service/) - [Network Access Protection](https://www.booches.nl/tag/network-access-protection/) - [NPS](https://www.booches.nl/tag/nps/) - [TechNet](https://www.booches.nl/tag/technet/) - [IAG](https://www.booches.nl/tag/iag/) - [intelligent](https://www.booches.nl/tag/intelligent/) - [application](https://www.booches.nl/tag/application/) - [appliance](https://www.booches.nl/tag/appliance/) - [CSG](https://www.booches.nl/tag/csg/) - [WebVPN](https://www.booches.nl/tag/webvpn/) - [IPsec](https://www.booches.nl/tag/ipsec/) - [local-host](https://www.booches.nl/tag/local-host/) - [sysopt](https://www.booches.nl/tag/sysopt/) - [reclassify-vpn](https://www.booches.nl/tag/reclassify-vpn/) - [CSCse36327](https://www.booches.nl/tag/cscse36327/) - [netstat](https://www.booches.nl/tag/netstat/) - [plane](https://www.booches.nl/tag/plane/) - [control-plane](https://www.booches.nl/tag/control-plane/) - [open-ports](https://www.booches.nl/tag/open-ports/) - [unconnected](https://www.booches.nl/tag/unconnected/) - [socket](https://www.booches.nl/tag/socket/) - [implemented](https://www.booches.nl/tag/implemented/) - [java](https://www.booches.nl/tag/java/) - [update](https://www.booches.nl/tag/update/) - [10](https://www.booches.nl/tag/10/) - [11](https://www.booches.nl/tag/11/) - [6.1.5.51](https://www.booches.nl/tag/61551/) - [%DOT11-7-CCKM_AUTH_FAILED](https://www.booches.nl/tag/dot11-7-cckm_auth_failed/) - [CCKM](https://www.booches.nl/tag/cckm/) - [broadcast-key](https://www.booches.nl/tag/broadcast-key/) - [interval](https://www.booches.nl/tag/interval/) - [AES](https://www.booches.nl/tag/aes/) - ["[LDAP search] Search failed (check Base DN)"](https://www.booches.nl/tag/ldap-search-search-failed-check-base-dn/) - [Softerra](https://www.booches.nl/tag/softerra/) - [browser](https://www.booches.nl/tag/browser/) - [BaseDN](https://www.booches.nl/tag/basedn/) - [sdaceldap](https://www.booches.nl/tag/sdaceldap/) - [adfind](https://www.booches.nl/tag/adfind/) - [ldap_search_s Sizelimit exceeded](https://www.booches.nl/tag/ldap_search_s-sizelimit-exceeded/) - [query](https://www.booches.nl/tag/query/) - [filter](https://www.booches.nl/tag/filter/) - [sdldapsync](https://www.booches.nl/tag/sdldapsync/) - [tunnel](https://www.booches.nl/tag/tunnel/) - [group](https://www.booches.nl/tag/group/) - [lists](https://www.booches.nl/tag/lists/) - [filtering](https://www.booches.nl/tag/filtering/) - [vpn-filtering](https://www.booches.nl/tag/vpn-filtering/) - [permit-vpn](https://www.booches.nl/tag/permit-vpn/) - [permit-ipsec](https://www.booches.nl/tag/permit-ipsec/) - [verify](https://www.booches.nl/tag/verify/) - [path](https://www.booches.nl/tag/path/) - [reverse-path](https://www.booches.nl/tag/reverse-path/) - [behavior](https://www.booches.nl/tag/behavior/) - [strange](https://www.booches.nl/tag/strange/) - [ICMP](https://www.booches.nl/tag/icmp/) - [NAT](https://www.booches.nl/tag/nat/) - [noproxyarp](https://www.booches.nl/tag/noproxyarp/) - [policy-based](https://www.booches.nl/tag/policy-based/) - [nvram](https://www.booches.nl/tag/nvram/) - [broken](https://www.booches.nl/tag/broken/) - [corrupt](https://www.booches.nl/tag/corrupt/) - [verification](https://www.booches.nl/tag/verification/) - [%SYS-7-NV_BLOCK_INIT](https://www.booches.nl/tag/sys-7-nv_block_init/) - [Initialized](https://www.booches.nl/tag/initialized/) - [geometry](https://www.booches.nl/tag/geometry/) - [nv_done](https://www.booches.nl/tag/nv_done/) - [unable](https://www.booches.nl/tag/unable/) - [open](https://www.booches.nl/tag/open/) - [%SYS-4-NV_BLOCK_INITFAIL](https://www.booches.nl/tag/sys-4-nv_block_initfail/) - [no](https://www.booches.nl/tag/no/) - [space](https://www.booches.nl/tag/space/) - [information](https://www.booches.nl/tag/information/) - [available](https://www.booches.nl/tag/available/) - [startup-config](https://www.booches.nl/tag/startup-config/) - [file](https://www.booches.nl/tag/file/) - [number](https://www.booches.nl/tag/number/) - [compress-config](https://www.booches.nl/tag/compress-config/) - [iPhone](https://www.booches.nl/tag/iphone/) - [iTunes](https://www.booches.nl/tag/itunes/) - [ringtone](https://www.booches.nl/tag/ringtone/) - [/Library/Ringtones](https://www.booches.nl/tag/libraryringtones/) - [m4r](https://www.booches.nl/tag/m4r/) - [OpenSSH](https://www.booches.nl/tag/openssh/) - [jailbreak](https://www.booches.nl/tag/jailbreak/) - [3G](https://www.booches.nl/tag/3g/) - [SMS](https://www.booches.nl/tag/sms/) - [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Ter](https://www.booches.nl/tag/hkey_local_machinesystemcurrentcontrolsetcontrolter/) - [state](https://www.booches.nl/tag/state/) - [tracking](https://www.booches.nl/tag/tracking/) - [err-disabled](https://www.booches.nl/tag/err-disabled/) - [route](https://www.booches.nl/tag/route/) - [portid](https://www.booches.nl/tag/portid/) - [xmodem](https://www.booches.nl/tag/xmodem/) - [recovery](https://www.booches.nl/tag/recovery/) - [speed](https://www.booches.nl/tag/speed/) - [flash](https://www.booches.nl/tag/flash/) - [9600](https://www.booches.nl/tag/9600/) - [115200](https://www.booches.nl/tag/115200/) - [baud](https://www.booches.nl/tag/baud/) - [rate](https://www.booches.nl/tag/rate/) - [tftp](https://www.booches.nl/tag/tftp/) - [vpdn](https://www.booches.nl/tag/vpdn/) - [vpdn-group](https://www.booches.nl/tag/vpdn-group/) - [l2tp](https://www.booches.nl/tag/l2tp/) - [receive](https://www.booches.nl/tag/receive/) - [receive-window](https://www.booches.nl/tag/receive-window/) - [802.1Q](https://www.booches.nl/tag/8021q/) - [native](https://www.booches.nl/tag/native/) - [pvid](https://www.booches.nl/tag/pvid/) - [general](https://www.booches.nl/tag/general/) - [acceptable-frame-type](https://www.booches.nl/tag/acceptable-frame-type/) - [tagged-only](https://www.booches.nl/tag/tagged-only/) - [dell](https://www.booches.nl/tag/dell/) - [powerconnect](https://www.booches.nl/tag/powerconnect/) - [6226](https://www.booches.nl/tag/6226/) - [novell](https://www.booches.nl/tag/novell/) - [nds](https://www.booches.nl/tag/nds/) - [cert7.db](https://www.booches.nl/tag/cert7db/) - [key3.db](https://www.booches.nl/tag/key3db/) - [netscape](https://www.booches.nl/tag/netscape/) - [communicator](https://www.booches.nl/tag/communicator/) - [4.8](https://www.booches.nl/tag/48/) - [secret](https://www.booches.nl/tag/secret/) - [extra](https://www.booches.nl/tag/extra/) - [option](https://www.booches.nl/tag/option/) - [advanced](https://www.booches.nl/tag/advanced/) - [&expert](https://www.booches.nl/tag/expert/) - [1](https://www.booches.nl/tag/1/) - [&expert=1](https://www.booches.nl/tag/expert1/) - [2500](https://www.booches.nl/tag/2500/) - [groupwise](https://www.booches.nl/tag/groupwise/) - [webacc](https://www.booches.nl/tag/webacc/) - [webaccess](https://www.booches.nl/tag/webaccess/) - [single](https://www.booches.nl/tag/single/) - [sign](https://www.booches.nl/tag/sign/) - [forms](https://www.booches.nl/tag/forms/) - [sso](https://www.booches.nl/tag/sso/) - [terminal](https://www.booches.nl/tag/terminal/) - [client](https://www.booches.nl/tag/client/) - [javardp](https://www.booches.nl/tag/javardp/) - [service](https://www.booches.nl/tag/service/) - [checker](https://www.booches.nl/tag/checker/) - [virus](https://www.booches.nl/tag/virus/) - [scanner](https://www.booches.nl/tag/scanner/) - [os](https://www.booches.nl/tag/os/) - [x](https://www.booches.nl/tag/x/) - [linux](https://www.booches.nl/tag/linux/) - [check](https://www.booches.nl/tag/check/) - [predefined](https://www.booches.nl/tag/predefined/) - [validity](https://www.booches.nl/tag/validity/) - [period](https://www.booches.nl/tag/period/) - [support](https://www.booches.nl/tag/support/) - [3.5](https://www.booches.nl/tag/3-5/) - [banner](https://www.booches.nl/tag/banner/) - [motd](https://www.booches.nl/tag/motd/) - [login](https://www.booches.nl/tag/login/) - [variable](https://www.booches.nl/tag/variable/) - [showing](https://www.booches.nl/tag/showing/) - [displaying](https://www.booches.nl/tag/displaying/) - [correctly](https://www.booches.nl/tag/correctly/) - [squid](https://www.booches.nl/tag/squid/) - [squid.conf](https://www.booches.nl/tag/squid-conf/) - [dmvpn](https://www.booches.nl/tag/dmvpn/) - [multipoint](https://www.booches.nl/tag/multipoint/) - [resilient](https://www.booches.nl/tag/resilient/) - [ISAKMP](https://www.booches.nl/tag/isakmp/) - [dual](https://www.booches.nl/tag/dual/) - [hub](https://www.booches.nl/tag/hub/) - [spoke](https://www.booches.nl/tag/spoke/) - [cloud](https://www.booches.nl/tag/cloud/) - [nhrp](https://www.booches.nl/tag/nhrp/) - [network-id](https://www.booches.nl/tag/network-id/) - [URL](https://www.booches.nl/tag/url/) - [expression](https://www.booches.nl/tag/expression/) - [regex](https://www.booches.nl/tag/regex/) - [inspect](https://www.booches.nl/tag/inspect/) - [policy-map](https://www.booches.nl/tag/policy-map/) - [class](https://www.booches.nl/tag/class/) - [map](https://www.booches.nl/tag/map/) - [drop](https://www.booches.nl/tag/drop/) - [cache](https://www.booches.nl/tag/cache/) - [violation](https://www.booches.nl/tag/violation/) - [howto](https://www.booches.nl/tag/howto/) - [ipplan](https://www.booches.nl/tag/ipplan/) - [ipam](https://www.booches.nl/tag/ipam/) - [nmap](https://www.booches.nl/tag/nmap/) - [cs mars](https://www.booches.nl/tag/cs-mars/) - [monitoring](https://www.booches.nl/tag/monitoring/) - [analysis](https://www.booches.nl/tag/analysis/) - [response](https://www.booches.nl/tag/response/) - [pnadmin](https://www.booches.nl/tag/pnadmin/) - [upgrade](https://www.booches.nl/tag/upgrade/) - [4.3.6](https://www.booches.nl/tag/4-3-6/) - [6.0.1](https://www.booches.nl/tag/6-0-1/) - [6.0.5](https://www.booches.nl/tag/6-0-5/) - [IPS](https://www.booches.nl/tag/ips/) - [pnexp](https://www.booches.nl/tag/pnexp/) - [pnimp](https://www.booches.nl/tag/pnimp/) - [NFS](https://www.booches.nl/tag/nfs/) - [one](https://www.booches.nl/tag/one/) - [passwords](https://www.booches.nl/tag/passwords/) - [sip](https://www.booches.nl/tag/sip/) - [xs4all](https://www.booches.nl/tag/xs4all/) - [nokia](https://www.booches.nl/tag/nokia/) - [e71](https://www.booches.nl/tag/e71/) - [registrar](https://www.booches.nl/tag/registrar/) - [reset](https://www.booches.nl/tag/reset/) - [hard](https://www.booches.nl/tag/hard/) - [soft](https://www.booches.nl/tag/soft/) - [chaining](https://www.booches.nl/tag/chaining/) - [rule](https://www.booches.nl/tag/rule/) - [wizard](https://www.booches.nl/tag/wizard/) - [directly](https://www.booches.nl/tag/directly/) - [demand](https://www.booches.nl/tag/demand/) - [otp](https://www.booches.nl/tag/otp/) - [email](https://www.booches.nl/tag/email/) - [token](https://www.booches.nl/tag/token/) - [selfservice](https://www.booches.nl/tag/selfservice/) - [clickatell](https://www.booches.nl/tag/clickatell/) - [netscaler](https://www.booches.nl/tag/netscaler/) - [customisation](https://www.booches.nl/tag/customisation/) - [mapping](https://www.booches.nl/tag/mapping/) - [aironet](https://www.booches.nl/tag/aironet/) - [ssid](https://www.booches.nl/tag/ssid/) - [wpa](https://www.booches.nl/tag/wpa/) - [guest](https://www.booches.nl/tag/guest/) - [guest-mode](https://www.booches.nl/tag/guest-mode/) - [mbssid](https://www.booches.nl/tag/mbssid/) - [dot11](https://www.booches.nl/tag/dot11/) - [bridge](https://www.booches.nl/tag/bridge/) - [irb](https://www.booches.nl/tag/irb/) - [Dot11Radio](https://www.booches.nl/tag/dot11radio/) - [problem](https://www.booches.nl/tag/problem/) - [session](https://www.booches.nl/tag/session/) - [disconnected](https://www.booches.nl/tag/disconnected/) - [provide](https://www.booches.nl/tag/provide/) - [MSLicensing](https://www.booches.nl/tag/mslicensing/) - [expires](https://www.booches.nl/tag/expires/) - [registered](https://www.booches.nl/tag/registered/) - [evaluation](https://www.booches.nl/tag/evaluation/) - [knowledge](https://www.booches.nl/tag/knowledge/) - [wp_footer](https://www.booches.nl/tag/wp_footer/) - [blog](https://www.booches.nl/tag/blog/) - [stats](https://www.booches.nl/tag/stats/) - [findoffice.pl](https://www.booches.nl/tag/findoffice-pl/) - [thissite.pm](https://www.booches.nl/tag/thissite-pm/) - [searchportlists.html](https://www.booches.nl/tag/searchportlists-html/) - [step](https://www.booches.nl/tag/step/) - [step-by-step](https://www.booches.nl/tag/step-by-step/) - [guide](https://www.booches.nl/tag/guide/) - [outbound](https://www.booches.nl/tag/outbound/) - [smtp](https://www.booches.nl/tag/smtp/) - [smart](https://www.booches.nl/tag/smart/) - [relaying](https://www.booches.nl/tag/relaying/) - [build 012](https://www.booches.nl/tag/build-012/) - [google](https://www.booches.nl/tag/google/) - [public](https://www.booches.nl/tag/public/) - [JunOS](https://www.booches.nl/tag/junos/) - [emulate](https://www.booches.nl/tag/emulate/) - [argentina](https://www.booches.nl/tag/argentina/) - [wireless](https://www.booches.nl/tag/wireless/) - [default](https://www.booches.nl/tag/default/) - [class-based](https://www.booches.nl/tag/class-based/) - [cbwfq](https://www.booches.nl/tag/cbwfq/) - [queueing](https://www.booches.nl/tag/queueing/) - [max-reserved](https://www.booches.nl/tag/max-reserved/) - [bandwidth](https://www.booches.nl/tag/bandwidth/) - [weighted](https://www.booches.nl/tag/weighted/) - [fair](https://www.booches.nl/tag/fair/) - [15](https://www.booches.nl/tag/15/) - [licensing](https://www.booches.nl/tag/licensing/) - [esgapi](https://www.booches.nl/tag/esgapi/) - [createbackup](https://www.booches.nl/tag/createbackup/) - [dram](https://www.booches.nl/tag/dram/) - [memory](https://www.booches.nl/tag/memory/) - [determine](https://www.booches.nl/tag/determine/) - [retrieve](https://www.booches.nl/tag/retrieve/) - [ive](https://www.booches.nl/tag/ive/) - [cluster](https://www.booches.nl/tag/cluster/) - [active/passive](https://www.booches.nl/tag/activepassive/) - [active/standby](https://www.booches.nl/tag/activestandby/) - [passive](https://www.booches.nl/tag/passive/) - [%SYS-2-MALLOCFAIL](https://www.booches.nl/tag/sys-2-mallocfail/) - [allocation](https://www.booches.nl/tag/allocation/) - [leak](https://www.booches.nl/tag/leak/) - [leakage](https://www.booches.nl/tag/leakage/) - [mab](https://www.booches.nl/tag/mab/) - [domain](https://www.booches.nl/tag/domain/) - [mda](https://www.booches.nl/tag/mda/) - [cisco-av-pair](https://www.booches.nl/tag/cisco-av-pair/) - [mitel](https://www.booches.nl/tag/mitel/) - [lldp](https://www.booches.nl/tag/lldp/) - [phone](https://www.booches.nl/tag/phone/) - [multi-domain](https://www.booches.nl/tag/multi-domain/) - [host-mode](https://www.booches.nl/tag/host-mode/) - [vsa](https://www.booches.nl/tag/vsa/) - [device-traffic-class=voice](https://www.booches.nl/tag/device-traffic-classvoice/) - [5330](https://www.booches.nl/tag/5330/) - [replace](https://www.booches.nl/tag/replace/) - [nvram:startup-config](https://www.booches.nl/tag/nvramstartup-config/) - [split](https://www.booches.nl/tag/split/) - [tunneling](https://www.booches.nl/tag/tunneling/) - [split-tunneling](https://www.booches.nl/tag/split-tunneling/) - [pkcs12](https://www.booches.nl/tag/pkcs12/) - [import](https://www.booches.nl/tag/import/) - [trustpoint](https://www.booches.nl/tag/trustpoint/) - [crypto](https://www.booches.nl/tag/crypto/) - [passphrase](https://www.booches.nl/tag/passphrase/) - [anyconnect](https://www.booches.nl/tag/anyconnect/) - [thin](https://www.booches.nl/tag/thin/) - [cpu](https://www.booches.nl/tag/cpu/) - [count](https://www.booches.nl/tag/count/) - [template](https://www.booches.nl/tag/template/) - [graph](https://www.booches.nl/tag/graph/) - [cut](https://www.booches.nl/tag/cut/) - [uniq](https://www.booches.nl/tag/uniq/) - [sort](https://www.booches.nl/tag/sort/) - [sslvpn](https://www.booches.nl/tag/sslvpn/) - [vif](https://www.booches.nl/tag/vif/) - [sslvpn-vif](https://www.booches.nl/tag/sslvpn-vif/) - [ntlm](https://www.booches.nl/tag/ntlm/) - [ntlmv2](https://www.booches.nl/tag/ntlmv2/) - [r2](https://www.booches.nl/tag/r2/) - [root](https://www.booches.nl/tag/root/) - [2048](https://www.booches.nl/tag/2048/) - [bit](https://www.booches.nl/tag/bit/) - [migration](https://www.booches.nl/tag/migration/) - [same](https://www.booches.nl/tag/same/) - [ISA Server Default Policy](https://www.booches.nl/tag/isa-server-default-policy/) - [duplicate](https://www.booches.nl/tag/duplicate/) - [sta](https://www.booches.nl/tag/sta/) - [ticket](https://www.booches.nl/tag/ticket/) - [5.3](https://www.booches.nl/tag/5-3/) - [An error occurred while making the requested connection](https://www.booches.nl/tag/an-error-occurred-while-making-the-requested-connection/) - [RequireLaunchReference](https://www.booches.nl/tag/requirelaunchreference/) - [xenapp](https://www.booches.nl/tag/xenapp/) - [expired](https://www.booches.nl/tag/expired/) - [packetshaper](https://www.booches.nl/tag/packetshaper/) - [reliability](https://www.booches.nl/tag/reliability/) - [discovery](https://www.booches.nl/tag/discovery/) - [encryption](https://www.booches.nl/tag/encryption/) - [data](https://www.booches.nl/tag/data/) - [stream](https://www.booches.nl/tag/stream/) - [maxAAAUsers](https://www.booches.nl/tag/maxaaausers/) - [aaa](https://www.booches.nl/tag/aaa/) - [parameter](https://www.booches.nl/tag/parameter/) - [driver](https://www.booches.nl/tag/driver/) - [on-demand](https://www.booches.nl/tag/on-demand/) - [agent](https://www.booches.nl/tag/agent/) - [deliver](https://www.booches.nl/tag/deliver/) - [delivery](https://www.booches.nl/tag/delivery/) - [automatically](https://www.booches.nl/tag/automatically/) - [isdn](https://www.booches.nl/tag/isdn/) - [ospf](https://www.booches.nl/tag/ospf/) - [floating](https://www.booches.nl/tag/floating/) - [redirect](https://www.booches.nl/tag/redirect/) - [anywhere](https://www.booches.nl/tag/anywhere/) - [activesync](https://www.booches.nl/tag/activesync/) - [rpc over https](https://www.booches.nl/tag/rpc-over-https/) - [rpc](https://www.booches.nl/tag/rpc/) - [hardware](https://www.booches.nl/tag/hardware/) - [array](https://www.booches.nl/tag/array/) - [nlb](https://www.booches.nl/tag/nlb/) - [igmp](https://www.booches.nl/tag/igmp/) - [certsrv](https://www.booches.nl/tag/certsrv/) - [database](https://www.booches.nl/tag/database/) - [primary](https://www.booches.nl/tag/primary/) - [replica](https://www.booches.nl/tag/replica/) - [instance](https://www.booches.nl/tag/instance/) - [rsautil](https://www.booches.nl/tag/rsautil/) - [configUtil](https://www.booches.nl/tag/configutil/) - [calendar](https://www.booches.nl/tag/calendar/) - [2010](https://www.booches.nl/tag/2010/) - [3750X](https://www.booches.nl/tag/3750x/) - [com](https://www.booches.nl/tag/com/) - [console](https://www.booches.nl/tag/console/) - [usb](https://www.booches.nl/tag/usb/) - [superlinks](https://www.booches.nl/tag/superlinks/) - [plink](https://www.booches.nl/tag/plink/) - [9.2](https://www.booches.nl/tag/9-2/) - [webinterface](https://www.booches.nl/tag/webinterface/) - [wi](https://www.booches.nl/tag/wi/) - [iis7](https://www.booches.nl/tag/iis7/) - [iis](https://www.booches.nl/tag/iis/) - [.net](https://www.booches.nl/tag/net/) - [An error occurred while trying to access the requested resource](https://www.booches.nl/tag/an-error-occurred-while-trying-to-access-the-requested-resource/) - [C](https://www.booches.nl/tag/c/) - [trendmicro](https://www.booches.nl/tag/trendmicro/) - [imsva](https://www.booches.nl/tag/imsva/) - [trend](https://www.booches.nl/tag/trend/) - [micro](https://www.booches.nl/tag/micro/) - [recipients](https://www.booches.nl/tag/recipients/) - [reject](https://www.booches.nl/tag/reject/) - [secondary](https://www.booches.nl/tag/secondary/) - [ssm](https://www.booches.nl/tag/ssm/) - [module](https://www.booches.nl/tag/module/) - [iwsva](https://www.booches.nl/tag/iwsva/) - [built-in](https://www.booches.nl/tag/built-in/) - [openvpn](https://www.booches.nl/tag/openvpn/) - [als](https://www.booches.nl/tag/als/) - [adito](https://www.booches.nl/tag/adito/) - [ubuntu](https://www.booches.nl/tag/ubuntu/) - [install](https://www.booches.nl/tag/install/) - [AutoQos](https://www.booches.nl/tag/autoqos/) - [while](https://www.booches.nl/tag/while/) - [generating](https://www.booches.nl/tag/generating/) - [commands](https://www.booches.nl/tag/commands/) - [exclusive](https://www.booches.nl/tag/exclusive/) - [cco](https://www.booches.nl/tag/cco/) - [software](https://www.booches.nl/tag/software/) - [download](https://www.booches.nl/tag/download/) - [connect](https://www.booches.nl/tag/connect/) - [common](https://www.booches.nl/tag/common/) - [algorithms](https://www.booches.nl/tag/algorithms/) - [113](https://www.booches.nl/tag/113/) - [net::ERR_SSL_VERSION_OR_CIPHER_MISMATCH](https://www.booches.nl/tag/neterr_ssl_version_or_cipher_mismatch/) - [version](https://www.booches.nl/tag/version/) - [mismatch](https://www.booches.nl/tag/mismatch/) - [copy-sw](https://www.booches.nl/tag/copy-sw/) - [download-sw](https://www.booches.nl/tag/download-sw/) - [imageonly](https://www.booches.nl/tag/imageonly/) - [overwrite](https://www.booches.nl/tag/overwrite/) - [allow-feature-upgrade](https://www.booches.nl/tag/allow-feature-upgrade/) - [ftp](https://www.booches.nl/tag/ftp/) - [XenServer](https://www.booches.nl/tag/xenserver/) - [npe](https://www.booches.nl/tag/npe/) - [ipv6](https://www.booches.nl/tag/ipv6/) - [prefix](https://www.booches.nl/tag/prefix/) - [delegation](https://www.booches.nl/tag/delegation/) - [advertisements](https://www.booches.nl/tag/advertisements/) - [general-prefix](https://www.booches.nl/tag/general-prefix/) - [bvi](https://www.booches.nl/tag/bvi/) - [autoconfiguration](https://www.booches.nl/tag/autoconfiguration/) - [other-config-flag](https://www.booches.nl/tag/other-config-flag/) - [dhcpv6](https://www.booches.nl/tag/dhcpv6/) - [CSCej5092](https://www.booches.nl/tag/cscej5092/) - [management-access](https://www.booches.nl/tag/management-access/) - [nbar](https://www.booches.nl/tag/nbar/) - [recognition](https://www.booches.nl/tag/recognition/) - [match](https://www.booches.nl/tag/match/) - [mime](https://www.booches.nl/tag/mime/) - [test](https://www.booches.nl/tag/test/) - [tls](https://www.booches.nl/tag/tls/) - [starttls](https://www.booches.nl/tag/starttls/) - [s_client](https://www.booches.nl/tag/s_client/) - [s_server](https://www.booches.nl/tag/s_server/) - [crlf](https://www.booches.nl/tag/crlf/) - [ssg](https://www.booches.nl/tag/ssg/) - [overlapping](https://www.booches.nl/tag/overlapping/) - [subnet](https://www.booches.nl/tag/subnet/) - [screenos](https://www.booches.nl/tag/screenos/) - [export](https://www.booches.nl/tag/export/) - [grayed](https://www.booches.nl/tag/grayed/) - [renew](https://www.booches.nl/tag/renew/) - [storage](https://www.booches.nl/tag/storage/) - [encrypted](https://www.booches.nl/tag/encrypted/) - [full](https://www.booches.nl/tag/full/) - [sql](https://www.booches.nl/tag/sql/) - [poller_output](https://www.booches.nl/tag/poller_output/) - [marked](https://www.booches.nl/tag/marked/) - [crashed](https://www.booches.nl/tag/crashed/) - [should](https://www.booches.nl/tag/should/) - [be](https://www.booches.nl/tag/be/) - [repaired](https://www.booches.nl/tag/repaired/) - [fragment](https://www.booches.nl/tag/fragment/) - [mysqlcheck](https://www.booches.nl/tag/mysqlcheck/) - [auto-repair](https://www.booches.nl/tag/auto-repair/) - [888G](https://www.booches.nl/tag/888g/) - [kpn](https://www.booches.nl/tag/kpn/) - [cellular](https://www.booches.nl/tag/cellular/) - [pcex-3g-hspa-g](https://www.booches.nl/tag/pcex-3g-hspa-g/) - [apn](https://www.booches.nl/tag/apn/) - [ddr](https://www.booches.nl/tag/ddr/) - [chat-script](https://www.booches.nl/tag/chat-script/) - [gsm](https://www.booches.nl/tag/gsm/) - [atdt](https://www.booches.nl/tag/atdt/) - [profile](https://www.booches.nl/tag/profile/) - [line 3](https://www.booches.nl/tag/line-3/) - [rset](https://www.booches.nl/tag/rset/) - [idle](https://www.booches.nl/tag/idle/) - [psh](https://www.booches.nl/tag/psh/) - [packet](https://www.booches.nl/tag/packet/) - [legacy](https://www.booches.nl/tag/legacy/) - [aruba](https://www.booches.nl/tag/aruba/) - [networks](https://www.booches.nl/tag/networks/) - [rap5](https://www.booches.nl/tag/rap5/) - [rap5wn](https://www.booches.nl/tag/rap5wn/) - [user-role](https://www.booches.nl/tag/user-role/) - [wired-ap-port](https://www.booches.nl/tag/wired-ap-port/) - [wired-ap-profile](https://www.booches.nl/tag/wired-ap-profile/) - [ap-group](https://www.booches.nl/tag/ap-group/) - [cannot](https://www.booches.nl/tag/cannot/) - [activated](https://www.booches.nl/tag/activated/) - [due](https://www.booches.nl/tag/due/) - [to](https://www.booches.nl/tag/to/) - [following](https://www.booches.nl/tag/following/) - [External](https://www.booches.nl/tag/external/) - [choose](https://www.booches.nl/tag/choose/) - [a](https://www.booches.nl/tag/a/) - [different](https://www.booches.nl/tag/different/) - [forefront](https://www.booches.nl/tag/forefront/) - [unified](https://www.booches.nl/tag/unified/) - [uag](https://www.booches.nl/tag/uag/) - [sp1](https://www.booches.nl/tag/sp1/) - [aerohive](https://www.booches.nl/tag/aerohive/) - [spectrum](https://www.booches.nl/tag/spectrum/) - [hivemanager](https://www.booches.nl/tag/hivemanager/) - [hiveap](https://www.booches.nl/tag/hiveap/) - [networking](https://www.booches.nl/tag/networking/) - [netconfig](https://www.booches.nl/tag/netconfig/) - [mcafee](https://www.booches.nl/tag/mcafee/) - [enterprise](https://www.booches.nl/tag/enterprise/) - [spanning](https://www.booches.nl/tag/spanning/) - [tree](https://www.booches.nl/tag/tree/) - [scalability](https://www.booches.nl/tag/scalability/) - [spanning-tree](https://www.booches.nl/tag/spanning-tree/) - [flex-10](https://www.booches.nl/tag/flex-10/) - [sus](https://www.booches.nl/tag/sus/) - [shared](https://www.booches.nl/tag/shared/) - [cookbook](https://www.booches.nl/tag/cookbook/) - [wlc](https://www.booches.nl/tag/wlc/) - [controller](https://www.booches.nl/tag/controller/) - [fus](https://www.booches.nl/tag/fus/) - [field](https://www.booches.nl/tag/field/) - [myhive](https://www.booches.nl/tag/myhive/) - [landing](https://www.booches.nl/tag/landing/) - [page](https://www.booches.nl/tag/page/) - [redirector](https://www.booches.nl/tag/redirector/) - [hmol](https://www.booches.nl/tag/hmol/) - [serial](https://www.booches.nl/tag/serial/) - [issue](https://www.booches.nl/tag/issue/) - [relay](https://www.booches.nl/tag/relay/) - [server-group](https://www.booches.nl/tag/server-group/) - [a4800g](https://www.booches.nl/tag/a4800g/) - [4800g](https://www.booches.nl/tag/4800g/) - [mag](https://www.booches.nl/tag/mag/) - [pa](https://www.booches.nl/tag/pa/) - [3.0](https://www.booches.nl/tag/3-0/) - [wrong](https://www.booches.nl/tag/wrong/) - [images](https://www.booches.nl/tag/images/) - [plugins](https://www.booches.nl/tag/plugins/) - [securenvoy](https://www.booches.nl/tag/securenvoy/) - [securaccess](https://www.booches.nl/tag/securaccess/) - [debug](https://www.booches.nl/tag/debug/)