<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>vpn &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://en.wordpress.com/tag/vpn/</link>
	<description>Feed of posts on WordPress.com tagged "vpn"</description>
	<pubDate>Sun, 29 Nov 2009 04:33:00 +0000</pubDate>

	<generator>http://en.wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA[Coding in Java using Vim]]></title>
<link>http://clustercomputing.wordpress.com/2009/11/28/coding-in-java-using-vim/</link>
<pubDate>Sat, 28 Nov 2009 02:27:21 +0000</pubDate>
<dc:creator>Srikanth Venkateswaran</dc:creator>
<guid>http://clustercomputing.wordpress.com/2009/11/28/coding-in-java-using-vim/</guid>
<description><![CDATA[This is one topic born out of necessity. I had to do it and had a discussion on the vim-use group ab]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>This is one topic born out of necessity. I had to do it and had a discussion on the vim-use group about it. Since I am lazy, I just cut-paste the conversation instead of summarizing it.</p>
<div>Hi,</div>
<div id=":60">I code Java in Vim using Vjde(<a href="http://www.vim.org/scripts/script.php?script_id=1213" target="_blank">http://www.vim.org/scripts/script.php?script_id=1213</a>). But I am not able to use many of the features because the documentation is entirely in Chinese, with a brief tutorial in English.</div>
<div>1) While it recognizes standard packages ( java.* ) for code completion, it does not recognize my custom packages. I am following the ctags instructions specified in the script homepage exactly as far as I can understand them.<br />
2) The auto-import feature works for standard packages but not mine.Questions:<br />
1) Is there any other tool for coding Java in Vim other than Vjde?<br />
2) Why am I using vim to code Java instead of Eclipse? Well, I have to code java over a VPN halfway across the world and the bandwidth makes a full fledged Eclipse IDE very slow. My question is, if there was a full fledged java plugin for vim with as many features as Eclipse, wouldn&#8217;t it be even slower, since it would have to do the parsing and matching in a language-generic way?
<p>&#160;</p>
<p>Thanks,<br />
Srikanth</p>
<div>&#62; 1) Is there any other tool for coding Java in Vim other than Vjde?</div>
<p>You may want to give a try to eclim (<a href="http://eclim.org/" target="_blank">http://eclim.org/</a>) I&#8217;ve not used it by myself but some people have told me that it&#8217;s good enough.</p>
<p>It requires you to run an instance of eclipse in the background though. Not sure if this poses a problem for the OP.</p>
<div>
<h3>Marc Weber</h3>
</div>
<p>Yes, of course vim script is slower than Java. There is one plugin on<a href="http://vim.org/" target="_blank"> vim.org</a> which implements a Java parser. However it wasn&#8217;t updated within the last year. And I think there are many reasons for it. It is insane to duplicate the work which was done on Eclipse. Eclim probably won&#8217;t solve the speed issues for you.</p>
<p>Maybe you can look at your problem in a different way?<br />
Maybe you can implement kind of file caching so that accessing files is faster ?<br />
Maybe you can start using a version control system so that you can keep a local copy of the source code.</p>
<p>Why do you have to use files which are stored on a server having a slow connection to you?<br />
What is your real problem?</p>
<p>Be aware that Netbeans has very good vi keybindings. Eclipse also has a vi-plugin.</p>
<p>Maybe try only reading .java files from the remote location while linking Eclipse stuff to a local disk. Using ntfs you can create different kinds of links etc.</p>
<p>Also be aware that you can&#8217;t debug Java code as comfortable as in Eclipse or netbeans. I&#8221;d also join #eclipse and ask how others work with a setup like yours.</p>
<p>There are alternative solutions: Eg log into the server and work using a terminal. I don&#8217;t know which works best for you. You have to try.</p>
<p>Good luck.<br />
<span style="color:#888888;">Marc Weber<br />
</span></p>
<p>Hi,<br />
Thanks for all the replies. I didn&#8217;t expect so many and so quick.<br />
&#62;&#62; Eclim probably won&#8217;t solve the speed issues for you.<br />
Actually it partly did. The background eclipse runs on the server (half the world away) and doesn&#8217;t have to transport the entire GUI across the n/w since the frontend s only a terminal vi..</p>
<p>&#62;&#62; log into the server and work using  a terminal.<br />
Exactly what I do.</p>
<p>&#62;&#62;Maybe you can implement kind of file caching so that accessing files is<br />
faster ?<br />
&#62;&#62; Maybe you can start using a version control system so that you can keep<br />
a local copy of the source code.<br />
Uh Oh&#8230; This is company code so strictly no checkouts allowed locally (at home). Of course we check out a local copy in the office so there is no problem using Eclipse/Netbeans there. At home, even connecting to the local server is slow.</p>
<p>&#62;&#62;  What is your real problem?<br />
Can&#8217;t checkout code at home (officially atleast)<br />
Currently using Eclim at home is sufficient for me, so thanks for all the help. This thread can be closed.</p>
<p>Thanks,<br />
<span style="color:#888888;"> Srikanth</span></p>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Thierry Lhermitte derrière Hadopi ?]]></title>
<link>http://scteam.wordpress.com/2009/11/27/thierry-lhermitte-derriere-hadopi/</link>
<pubDate>Fri, 27 Nov 2009 18:59:07 +0000</pubDate>
<dc:creator>ju4n1t0</dc:creator>
<guid>http://scteam.wordpress.com/2009/11/27/thierry-lhermitte-derriere-hadopi/</guid>
<description><![CDATA[Trident Media Guard pourrait répondre favorablement à l&#8217;appel d&#8217;offre du ministère de la]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><img class="alignnone" src="http://www.dutoitfreeblog.com/.a/6a00d83451935369e201156f171a06970c-800wi" alt="" width="184" height="203" /></p>
<p><a href="http://www.tmg.eu" target="_blank">Trident Media Guard</a> pourrait répondre favorablement à l&#8217;appel d&#8217;offre du ministère de la culture en charge de faire fonctionner la machine Hadopi.</p>
<p>La société TMG a dans ses rangs Thierry Lhermite, administrateur, cette société vise à défendre les données copyrightées en injectant de faux contenus sur les réseaux.</p>
<p>Ce que l&#8217;on peut retenir, c&#8217;est que TMG va leurrer les téléchargeurs pour mieux les attraper avec de faux fichiers.</p>
<p>Bref, une machine à fric.</p>
<p>Effectivement, un véritable <a href="http://www.pcinpact.com/actu/news/54339-hadopi-thierry-lhermitte-trident-media.htm" target="_blank">business financier</a> est derrière tout cela puisque Thierry Lhermitte aurait injecté 50 000 euros en numéraire sur un compte de la société commerciale contre 5 000 actions.</p>
<p>Une autre société serait elle aussi favorable pour l&#8217;Hadopi du nom de <a href="http://www.advestigo.com" target="_blank">AdVestigo</a>.</p>
<p>Bref, nous serons bientôt qui sera l&#8217;heureux élu de l&#8217;&#8221;Hadopisation&#8221;, ou plutôt, à qui empochera le pognon.</p>
<p>Pendant ce temps, de nombreux internautes multiplient et emploient d&#8217;autres services comme le téléchargement directe, des services de serveurs Proxy, VPN et autres cryptages de données comme Perseus.</p>
<p>Le petite guéguerre que mène le ministère de la culture risque fort d&#8217;augmenter l&#8217;utilisation et les méthodes de contournement qu&#8217;utiliserons les internautes de tout poils, tout cela, au risque de ne plus rien contrôler.</p>
<p>Comme on dit chez nous, le mal engendre le mal, et cela ne fait que commencer.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco VPN Client on Ubuntu Karmic 9.10]]></title>
<link>http://leifmadsen.wordpress.com/2009/11/27/cisco-vpn-client-on-ubuntu-karmic-9-10/</link>
<pubDate>Fri, 27 Nov 2009 13:19:44 +0000</pubDate>
<dc:creator>Leif Madsen</dc:creator>
<guid>http://leifmadsen.wordpress.com/2009/11/27/cisco-vpn-client-on-ubuntu-karmic-9-10/</guid>
<description><![CDATA[I have a client who I need to connect to via a Cisco VPN, and since I use Ubuntu as my primary OS on]]></description>
<content:encoded><![CDATA[I have a client who I need to connect to via a Cisco VPN, and since I use Ubuntu as my primary OS on]]></content:encoded>
</item>
<item>
<title><![CDATA[Looking deeper into OSPF as a PE-CE protocol]]></title>
<link>http://doccieshavespecialpowers.wordpress.com/2009/11/22/looking-deeper-into-ospf-as-a-pe-ce-protocol/</link>
<pubDate>Sun, 22 Nov 2009 05:27:19 +0000</pubDate>
<dc:creator>doccieshavespecialpowers</dc:creator>
<guid>http://doccieshavespecialpowers.wordpress.com/2009/11/22/looking-deeper-into-ospf-as-a-pe-ce-protocol/</guid>
<description><![CDATA[Default behavior of redistribution on VRF aware OSPF will lead to the MPLS VPN cloud trying to emula]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Default behavior of redistribution on VRF aware OSPF will lead to the MPLS VPN cloud trying to emulate OSPF. This is done using a &#8220;Super Backbone&#8221; which is hierarchically above area zero. RFC4577 explains in great detail how this should ideally work.</p>
<p>The whole point of this behavior is to mask the VPNv4 BGP from the customer networks. Traditionally if you redistribute any protocol into OSPF it will be created as an LSA type 5 (external). In Cisco&#8217;s implementation all LSAs of type 1-3 will be advertised out the egress PE(s) as type 3.</p>
<p>Given the topology below assume that the link from CE1-CE2 is not active (for the moment). All Ethernet links have been set to a network type of point-to-point for simplification.</p>
<p style="text-align:center;"><img class="aligncenter" src="http://doccieshavespecialpowers.wordpress.com/files/2009/11/ospfpece.jpg" alt="" /></p>
<p>Looking at the link state database we can see the summary prefixes (type 3) all have the router ID of the nearby PE. This means that the &#8220;Super Backbone&#8221; is working, converting area zero LSA type 1 into type 3 at the egress PE. It is important to make sure that the process IDs match between PEs. The process ID configured on the PE is attached in the form of an extended community, under the ospf process you can manually set the value to be attached to the ext-community;</p>
<blockquote><p>OSPF DOMAIN ID:0&#215;0005:0&#215;0000007B0200</p>
<p>router ospf 123 vrf cust<br />
domain-id type 0005 value 000000000123</p>
<p>OSPF DOMAIN ID:0&#215;0005:0&#215;000000000123</p></blockquote>
<p>An issue which can occur when implementing OSPF as the PE-CE protocol, which I have seen first hand in a production network is that the &#8220;Super Backbone&#8221; cannot be treated as a transit network as it would in a layer two VPN. I can imagine that enterprises and even the people who design/architect for enterprises (not trying to have a dig a CCIE RS holders) do not take into consideration how OSPF MPLS VPNs actually work. You cannot just make the MPLS VPN cloud a single area, even if all the PE-CE links are in area zero all LSAs will be type three after they have crossed the cloud.</p>
<blockquote><p>CE1#show ip ospf 123 database router adv 172.0.0.2</p>
<p>OSPF Router with ID (172.0.0.1) (Process ID 123)<br />
Router Link States (Area 0)</p>
<p><strong>Adv Router is not-reachable</strong><br />
LS age: 481<br />
Options: (No TOS-capability, DC)<br />
LS Type: Router Links<br />
Link State ID: 172.0.0.2<br />
Advertising Router: 172.0.0.2<br />
LS Seq Number: 80000004<br />
Checksum: 0xD09A<br />
Length: 60<br />
Number of Links: 3</p></blockquote>
<p>The LSAs (from CE2) are inside the database (on CE1) but they will not ever be able to be used for forwarding because the topology has broken the &#8220;Area 0 must be contiguous&#8221; rule. CE2 is in fact sending LSA type 1 for both Area0 and Area1 but all LSAs from Area0 are marked &#8220;Adv Router is not reachable&#8221; above.</p>
<p style="text-align:center;"><img class="aligncenter" src="http://doccieshavespecialpowers.wordpress.com/files/2009/11/ospfpece2.jpg" alt="" width="394" height="217" /></p>
<p style="text-align:left;">Another thing worth noting is that in regular OSPF the &#8220;advertising router&#8221; for an LSA stays the same within an area and is changed at the border (by an ASBR/ABR). This is consistant with the &#8220;ever router must know every other router in the area&#8221; concept. This is also applied to the Superbackbone. The &#8220;advertising router&#8221; for an LSA will be changed as it is advertised out the egress PE. This combined with some of the above shows how the Superbackbone truely does act as an area hierachically above area zero.</p>
<p style="text-align:left;"><a href="http://doccieshavespecialpowers.wordpress.com/files/2009/11/ospf-pece.docx">GNS3 .net file</a> (rename to *.rar)</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ASA VPN Misconceptions]]></title>
<link>http://network-securityblog.globalknowledge.com/2009/11/20/asa-vpn-misconceptions/</link>
<pubDate>Fri, 20 Nov 2009 15:36:39 +0000</pubDate>
<dc:creator>gkmktgjll</dc:creator>
<guid>http://network-securityblog.globalknowledge.com/2009/11/20/asa-vpn-misconceptions/</guid>
<description><![CDATA[Numerous experiences with clients and students implementing Virtual Private Networks (VPNs) with IPS]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Numerous experiences with clients and students implementing Virtual Private Networks (VPNs) with IPSec have shown me that some common misconceptions exist as to their operation and troubleshooting.  We will examine three of these using the scenario below between an ASA running version 8.0 code and a Cisco Router running IOS version 12.2 or higher code.</p>
<p><a href="http://netsecblog.wordpress.com/files/2009/11/ex1.jpg"><img class="aligncenter size-full wp-image-371" title="ex1" src="http://netsecblog.wordpress.com/files/2009/11/ex1.jpg" alt="" width="500" height="178" /></a></p>
<p><strong>Misconception #1</strong>: A Site-to-Site VPN created with the ASDM Wizard is Bidirectional</p>
<p>The commands below are a portion of what would be displayed if the “Preview Commands&#8230;” option were selected in the ASDM preferences after finishing the Site-to-Site wizard.</p>
<p><strong>crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac<br />
crypto map outside_map 1 match address outside_1_cryptomap<br />
crypto map outside_map 1 set pfs group2<br />
crypto map outside_map 1 set peer 192.168.11.2<br />
crypto map outside_map 1 set transform-set ESP-3DES-SHA<br />
crypto map outside_map interface outside</strong></p>
<p>Note the <strong>set pfs group2</strong> statement above; this default deployment option with the wizard will result in the IKE Phase II proposal of Perfect Forward Secrecy using Diffie-Hellman Group #2.  While the IOS Router will support this and agree to it (even though it wasn’t explicitly configured), the tunnel CANNOT be successfully initiated by the site owning that router!  For this to happen, the router MUST be configured with the same statement for its Phase II policy in its crypto map.</p>
<p>&#160;</p>
<p><strong>Misconception #2</strong>: The IKE keepalive keeps the Site-to-Site tunnel up</p>
<p>Actually, the IKE keepalive merely insures that the remote peer is reachable. A little-known fact is that the Idle Timeout usually found in the <strong>Network (Client) Access</strong> for the IPSec client also impacts Site-to-Site tunnels being kept up.  A screenshot is provided below showing where this is configured for the default group policy, <strong>DfltGrpPolicy</strong>.</p>
<p>Studies have shown that if this time interval is increased to be greater than 80% of the Phase II IPSec Security Association lifetime, the tunnel will stay up.</p>
<p><a href="http://netsecblog.wordpress.com/files/2009/11/ex2.jpg"><img class="aligncenter size-full wp-image-372" title="ex2" src="http://netsecblog.wordpress.com/files/2009/11/ex2.jpg" alt="" width="427" height="434" /></a></p>
<p><strong>Misconception #3: </strong>Allowing IPSec ACL bypass is insecure – Default Wizard option</p>
<p>This appears as a checkbox in the wizard, or could be configured using the CLI command <strong>sysopt connection permit-vpn</strong>. Two very effective techniques can be used here, the mechanics of which will be discussed in future postings.  The first of these would be to configure a VPN Group Filter (done under the Group Policy settings), a feature which applies for both Site-to-Site or Remote Access VPNs. A second effective technique, applicable for both IPSec and SSL VPN Client access, would be to use downloadable access-control lists with RADIUS.</p>
<p><strong>Author: Doug McKillip</strong></p>
<p><strong>References</strong><br />
<a href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml">Most Common L2L and Remote Access IPSec VPN Troubleshooting Solutions</a> Document ID #81824</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ASA VPN Server config template]]></title>
<link>http://geniesis.wordpress.com/2009/11/20/asa-vpn-server-config-template/</link>
<pubDate>Fri, 20 Nov 2009 04:21:05 +0000</pubDate>
<dc:creator>geniesis</dc:creator>
<guid>http://geniesis.wordpress.com/2009/11/20/asa-vpn-server-config-template/</guid>
<description><![CDATA[I keep forgetting the config required for setting up an ASA VPN server, so here it is for reference:]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>I keep forgetting the config required for setting up an ASA VPN server, so here it is for reference:</p>
<p>This is an ASA config with Radius authentication.</p>
<blockquote><p>aaa-server RADIUS protocol radius<br />
aaa-server RADIUS (inside) host &#60;HOST&#62;<br />
key &#60;KEY&#62;</p>
<p>access-list VPN_splitTunnelAcl standard permit &#60;NETWORK&#62; &#60;SUBNET&#62;<br />
ip local pool VPN-IP-POOL &#60;FROM_IP&#62;-&#60;TO_IP&#62; mask 255.255.255.0</p>
<p>access-list nonat extended permit ip any &#60;NETWORK&#62; &#60;SUBNET&#62;<br />
nat (inside) 0 access-list nonat</p>
<p>group-policy &#60;GROUP&#62; internal<br />
group-policy &#60;GROUP&#62; attributes<br />
dns-server value &#60;DNS_IP&#62;<br />
vpn-tunnel-protocol IPSec webvpn<br />
ipsec-udp enable<br />
split-tunnel-policy tunnelspecified<br />
split-tunnel-network-list value VPN_splitTunnelAcl<br />
default-domain value &#60;DNS_SUFFIX&#62;<br />
webvpn<br />
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac<br />
crypto ipsec security-association lifetime seconds 28800<br />
crypto ipsec security-association lifetime kilobytes 4608000<br />
crypto dynamic-map outside_dyn_map 10 set transform-set ESP-3DES-SHA<br />
crypto dynamic-map outside_dyn_map 10 set security-association lifetime seconds 28800<br />
crypto dynamic-map outside_dyn_map 10 set security-association lifetime kilobytes 4608000<br />
crypto dynamic-map outside_dyn_map 10 set reverse-route<br />
crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map<br />
crypto map outside_map interface outside<br />
isakmp enable outside<br />
isakmp policy 10 authentication pre-share<br />
isakmp policy 10 encryption 3des<br />
isakmp policy 10 hash sha<br />
isakmp policy 10 group 2<br />
isakmp policy 10 lifetime 1000<br />
isakmp nat-traversal  20</p>
<p>tunnel-group &#60;TUNNEL&#62; type ipsec-ra<br />
tunnel-group &#60;TUNNEL&#62; ipsec-attributes<br />
pre-shared-key &#60;PRESHAREKEY&#62;<br />
isakmp keepalive threshold 10 retry 2<br />
tunnel-group &#60;TUNNEL&#62; general-attributes<br />
address-pool VPN-IP-POOL<br />
authentication-server-group RADIUS<br />
default-group-policy &#60;GROUP&#62;</p></blockquote>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[O que fazemos ??]]></title>
<link>http://overlan.wordpress.com/2009/11/19/o-que-fazemos/</link>
<pubDate>Thu, 19 Nov 2009 20:58:34 +0000</pubDate>
<dc:creator>overlan</dc:creator>
<guid>http://overlan.wordpress.com/2009/11/19/o-que-fazemos/</guid>
<description><![CDATA[1. Terceriração de TI – Outsourcing de TI com Segurança • Instalaçao de servidores de alta disponibi]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><div>
<p>1. Terceriração de TI – Outsourcing de TI com Segurança</p>
<p>• Instalaçao de servidores de alta disponibilidade windows e linux<br />
Servidores de internet<br />
Servidores de arquivos<br />
Servidores de Banco de Dados<br />
Servidores para controle de acesso de usuários</p>
<p>• Implementação e gerenciamento<br />
Segurança de rede (iptables)<br />
Controle de usuários (ad)<br />
Controle de acessos a internet (squid)<br />
Controle de Equipamentos  (ocs)<br />
Controle sobre softwares instalados (ocs)<br />
Politicas de Segurança (gpo)<br />
Backup de dados (ntbackup)<br />
Atualizações de softwares (wsus)</p>
<p>• Infraestrutura lógica de rede<br />
Configurações de switch e roteadores<br />
Conexao entre  matriz e filiais (vpn)<br />
Priorização de banda e fluxo de rede (proxy)<br />
Levantamento técnico da infraestrutura fisica</p>
<p>• Suporte e manutencao de estações<br />
Controle de virus<br />
Otimização de equipamento<br />
Suporte remoto<br />
Helpdesk<br />
2. Comercio de produtos de informática</p>
<p>Hardware</p>
<p>• Venda de computadores<br />
• Monitores<br />
• notebooks<br />
• Impressoras<br />
• Ativos de rede<br />
• No breaks<br />
• Perifericos<br />
• Acessorios<br />
Software<br />
• Anti-virus<br />
• Sistemas operacionais microsoft – Windows<br />
• Pacotes Office</p>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Come Guardare Film e Anime su Hulu.com in Italia]]></title>
<link>http://pcsoftwaredrivers.wordpress.com/2009/11/19/come-guardare-film-e-anime-su-hulu-com-in-italia/</link>
<pubDate>Thu, 19 Nov 2009 18:21:18 +0000</pubDate>
<dc:creator>sonotouri</dc:creator>
<guid>http://pcsoftwaredrivers.wordpress.com/2009/11/19/come-guardare-film-e-anime-su-hulu-com-in-italia/</guid>
<description><![CDATA[Caro internauta, per caso ti sei imbattuto nel sito hulu.com per guardare in streaming un film, un t]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Caro internauta, per caso ti sei imbattuto nel sito <a href="http://www.hulu.com" target="_blank"><strong>hulu.com</strong></a> per guardare in streaming un film, un telefilm o magari un anime e ti è uscito il fatidico messaggio <em>&#8220;The requested video cannot be displayed in your region&#8221; </em>ovvero <em>&#8220;Il video richiesto non può essere visionato nel tuo paese&#8221;</em> infatti Hulu a differenza degli altri siti in streaming, trasmette film, telefilm e anime regolarmente tramite accordi con le case produttrici però può essere guardato solo da chi è residente negli Stati Uniti.</p>
<p style="text-align:center;"><img class="aligncenter size-medium wp-image-14" title="Hulu sito streaming per guardare Film e Telefilm" src="http://pcsoftwaredrivers.wordpress.com/files/2009/11/hulu_streaming.jpg?w=300" alt="" width="300" height="168" /></p>
<p>Allora come possiamo aggirare questa restrizione di hulu? La prima idea è quella di usare un proxy americano, ma generalmente i proxy sono di una lentezza paradossale e inoltre di solito vengono riconosciuti immediatamente dai sistemi anti-proxy.</p>
<p>Esiste però un&#8217;altra soluzione, che fino ad ora ha sempre funzionato anche con Hulu; usare una connessione <strong>VPN</strong> (Virtual Private Network) con ip americano.</p>
<p>Direttamente da wikipedia:<em>&#8220;Una Virtual Private Network o VPN è una rete privata instaurata tra soggetti che utilizzano un sistema di trasmissione pubblico e condiviso come per esempio Internet. Lo scopo delle reti VPN è di dare alle aziende le stesse possibilità delle linee private in affitto ad un costo inferiore sfruttando le reti condivise pubbliche.&#8221;</em></p>
<p>In genere le connessioni VPN sono a pagamento, ma oggi esistono dei network gratuiti e uno di questi è <strong><a href="http://www.hotspotshield.com/" target="_blank">Hotspot shield</a></strong>, un programmino free che una volta installato e aperto ci installa una connessione VPN e ci genera un indirizzo ip statunitense. Una volta installato e connesso il programma, <strong>cancelliamo dal browser cronologia, cache e cookie</strong> (in particolare questi ultimi visto che hulu li installa e quindi se non li cancelli verrai riconosciuto dal sito che non sei residente degli Stati Uniti).</p>
<p>Puoi scaricare Hotspot <a href="http://www.hotspotshield.com/" target="_blank">cliccando qui</a> e poi clicca in alto a destra su &#8220;Download The Latest Version&#8221;.</p>
<p>Sei hai fatto tutto bene vai sul film che ti interessa e potrai guardarlo in santa pace! <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Ovviamente la connessione VPN non andrà veloce come la nostra ADSL, ma neanche tanto lento, anzi và anni luce meglio dei proxy, ti do però un consiglio, quando parte il video metti pausa per almeno 10-20 secondi in modo che il video non vada scattoso.</p>
<p>A volte può capitare che Hulu riconosca il VPN, in quel caso cancellate di nuovo tutti i cookie e chiudete e riaprite il programma di modo che vi generi un nuovo indirizzo ip.</p>
<p>Spero di esserti stato utile e ti saluto! Se lasci un commento mi farebbe piacere.</p>
<p>NB: questo articolo è solo a scopo informativo, non mi riterrò responsabile per l&#8217;uso che ne farai.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pandémies, les PMEs sont-elles prêtes ?]]></title>
<link>http://pmeblog.cisco-france.com/2009/11/19/pandemies-les-pmes-sont-elles-pretes/</link>
<pubDate>Thu, 19 Nov 2009 09:12:25 +0000</pubDate>
<dc:creator>jfoucaul</dc:creator>
<guid>http://pmeblog.cisco-france.com/2009/11/19/pandemies-les-pmes-sont-elles-pretes/</guid>
<description><![CDATA[Pas un jour sans parler du sujet dans les médias ! Des écoles qui ferment, des campagnes de vaccinat]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Pas un jour sans parler du sujet dans les médias ! Des écoles qui ferment, des campagnes de vaccinations qui se mettent en place et aussi des avis très partagés sur le bien fondé de la vaccination !&#8230;</p>
<p>Toujours est-il que le constat est là, les PME sont aujourd’hui très peu organisées pour affronter une pandémie :</p>
<p>Les entreprises ont déployées des solutions pour répondre à des coupures de courant, des pannes informatiques (perte d’un serveur, d’une application) mais rares sont celles qui savent répondre aux perturbations liées à l’absence des employés.</p>
<p>Risc Group vient de publier un étude :</p>
<p>La réalité du télétravail à l’épreuve de l’épidémie</p>
<p>Plus des deux tiers des responsables de PME (70%) estiment pouvoir développer le télétravail pour faire face aux risques épidémiques. Cependant, moins d’un sur trois (30%) est réellement en mesure de le faire pour la plupart (26%) ou pour tous leurs salariés (4%). 30% seraient totalement incapables de permettre le télétravail.</p>
<p>Les plus petites entreprises souffrent d’avantage de ce problème. Si 56% des patrons de PME de plus de 50 salariés prétendent pouvoir faire travailler à distance quelques uns de leurs collaborateurs, 41% des responsables de TPE (6 à 9 salariés) reconnaissent leur incapacité totale au télétravail.</p>
<p>Parmi les « champions » du télétravail potentiel, 94% des entreprises de services aux entreprises pensent pouvoir mettre en place le télétravail sécurisé. A l’inverse, seulement un tiers (36%) des</p>
<p>PME du secteur de la santé l’envisagent.</p>
<p>Solutions Cisco : Plusieurs type de solutions existe en fonction du besoin et du niveau de service : </p>
<p><strong>1<sup>er</sup> niveau : Webex</strong></p>
<p>Webex est une suite applicative complète qui permet de mettre en œuvre une conférence audio avec partage de document, support vidéo et chat.</p>
<p>Il suffit pour le salarié d’avoir un PC (personnel ou professionnel) connecté à internet. Webex est une application web qui peut se déployer très facilement et qui convient quelque soit le nombre d’utilisateurs …facturation par abonnement ou à l’utilisation.</p>
<p>A partir de 46 € par mois.</p>
<p>Plus d’info sur <a href="http://www.webex.fr/">www.webex.fr</a></p>
<p><strong>2eme niveau : Acces VPN</strong></p>
<p>Cette solution consiste à utiliser internet pour permettre à un utilisateur distant de se connecter sur le réseau de l’entreprise via un « tunnel » sécurisé. Il existe deux techniques :</p>
<p>-          VPN SSL : l’utilisateur peut se connecter à partir de n’importe quel PC (professionnel,personnel, ou même PC libre service). Il se connecte en utilisant un identifiant + mot de passe à un portail défini par l’entreprise qui lui donne accès aux applications prédéfinies.</p>
<p>-          VPN IPSEC : l’utilisateur doit posséder un portable professionnel car ce poste doit etre configurer avec un logiciel client qui permet de se connecter au réseau de l’entreprise comme si il était en local.</p>
<p>Mise en œuvre de ces accès : L’accès VPN implique la mise en place d’un équipement sur le réseau de l’entreprise et l’achat de licences SSL (pour le VPN SSL)</p>
<p>Les routeurs Cisco, les boitiers de sécurité Cisco ASA ou les nouveaux boitiers dédiés PME SA4500 permettent de mettre en place facilement ces liaisons VPN.</p>
<p><strong>3eme niveau : extension Wifi / IP phone</strong></p>
<p>Cette solution implique un réseau wifi Cisco déjà installé dans l’entrprise et le déploiement de bornes wifi dans les bureaux distants ou à la maison.</p>
<p>Permet d’avoir un accès wifi comme dans l’entreprise.</p>
<p><strong>4eme niveau : Cisco Virtual Office.</strong></p>
<p>Permet de fournir le meme niveau de service au domicile que celui de l’entreprise (accès téléphonique et informatique).</p>
<p>Implique le déploiement d’un routeur au domicile + téléphone IP.</p>
<p>Implique une solution de communication unifiée Cisco dans l’entreprise.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Using TeamViewer yesterday reminded me of the utility of the net.]]></title>
<link>http://scotstockton.wordpress.com/2009/11/18/using-teamviewer-yesterday-reminded-me-of-the-utility-of-the-net/</link>
<pubDate>Wed, 18 Nov 2009 17:53:04 +0000</pubDate>
<dc:creator>Scot Stockton</dc:creator>
<guid>http://scotstockton.wordpress.com/2009/11/18/using-teamviewer-yesterday-reminded-me-of-the-utility-of-the-net/</guid>
<description><![CDATA[I spent time yesterday on a friend&#8217;s computer in a different city.  I, of course, was home sit]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>I spent time yesterday on a friend&#8217;s computer in a different city.  I, of course, was home sitting in my favorite chair.  TeamViewer ( http://www.teamviewer.com/index.aspx ) is a package that allows me at home to see my friend&#8217;s &#8216;puter screen in a browser window and to move the mouse and type in commands.  Neat stuff.</p>
<p>This is an example of VPN ( Virtual Private Network ) software, that I have used before in unix environments.  I have a couple VPNs loaded up now on this Windows machine.  There was one that seemed to confuse, or cross-operate, a university and a city library.  That all seems sorted now.</p>
<p>I want to see how TeamViewer works as a remote desktop on a Mac as the other &#8216;puter.</p>
<p>All still neat stuff.</p>
<p>&#160;</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 7 VPN Setup]]></title>
<link>http://ttcshelbyville.wordpress.com/2009/11/18/windows-7-vpn-setup/</link>
<pubDate>Wed, 18 Nov 2009 06:46:44 +0000</pubDate>
<dc:creator>SMallard</dc:creator>
<guid>http://ttcshelbyville.wordpress.com/2009/11/18/windows-7-vpn-setup/</guid>
<description><![CDATA[A Virtual Private Network is used to encrypt data from one computer to another.  If you need to setu]]></description>
<content:encoded><![CDATA[A Virtual Private Network is used to encrypt data from one computer to another.  If you need to setu]]></content:encoded>
</item>
<item>
<title><![CDATA[No existen más que dos reglas para escribir: Tener algo que decir y decirlo]]></title>
<link>http://angelferras.wordpress.com/2009/11/17/no-existen-mas-que-dos-reglas-para-escribir-tener-algo-que-decir-y-decirlo/</link>
<pubDate>Tue, 17 Nov 2009 18:04:15 +0000</pubDate>
<dc:creator>angelferras</dc:creator>
<guid>http://angelferras.wordpress.com/2009/11/17/no-existen-mas-que-dos-reglas-para-escribir-tener-algo-que-decir-y-decirlo/</guid>
<description><![CDATA[Esta frase de Oscar Wilde da inicio al libro Redes Privadas Virtuales de mi buen amigo Javier Andrés]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Esta frase de Oscar Wilde da inicio al libro <a href="http://redes-privadas-virtuales.blogspot.com/2009/07/redes-privadas-virtuales-ya-la-venta.html" target="_blank">Redes Privadas Virtuales</a> de mi buen amigo <a href="http://redes-privadas-virtuales.blogspot.com" target="_blank">Javier Andrés Alonso</a> que hoy por fin recibí en casa vía editorial <a href="http://www.ra-ma.es/libros/REDES-PRIVADAS-VIRTUALES/2830/978-84-7897-929-5" target="_blank">Ra-Ma</a>. En el primer vistazo al libro lo que más me ha llamado la atención ha sido su finalidad  puramente práctica junto con el grosor, casi 900 páginas, &#8230; todo un tratado de seguridad, redes y encriptación única en su género y en castellano.</p>
<p><img class="aligncenter" title="Redes Privadas Virtuales" src="http://4.bp.blogspot.com/_EvoxXLEnC6E/St41NMHLKLI/AAAAAAAAANQ/hYn1338Tzu8/S270/Portada+Redes+Privadas+Virtuales.JPG" alt="" width="188" height="270" />Ha sido muy emotivo este primer encuentro con su libro y que me ha traido recuerdos del antiguo equipo de <strong>mucha calidad</strong> del GateDefender (<a href="http://redes-privadas-virtuales.blogspot.com" target="_blank">Javi</a>, <a href="http://daniel-montero.conquenses.com/" target="_blank">Dani</a>, Patri y yo),  compañeros del equipo de desarrollo y de managers. Son muchas horas codo con codo, analizando tráfico de red, buscando la forma de que &#8220;explotaran&#8221; las nuevas releases o buscando el entrecotte para la dieta multiproteica de <a href="http://aicastell.blogspot.com/" target="_blank">Iván</a> ,  aunque destacaría esas clases <strong>magistrales</strong> que tanto me ayudaron para hacerme con el producto y adentrarme en el mundo de la seguridad informática. Se hace irónico encontrar mi nombre en los agradecimientos del libro, &#8230; , aprendí mucho de su poesía en directo y sigo aprendiendo de su prosa escrita MAESTRO!!!</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[[How To] Play Call of Duty - World at War 5 Co-Op Online Using Hamachi (Tunngle Preferred)]]></title>
<link>http://versatile1.wordpress.com/2009/11/17/how-to-play-call-of-duty-world-at-war-5-online-using-hamachi-tunngle-preferred/</link>
<pubDate>Tue, 17 Nov 2009 06:15:21 +0000</pubDate>
<dc:creator>Chyea</dc:creator>
<guid>http://versatile1.wordpress.com/2009/11/17/how-to-play-call-of-duty-world-at-war-5-online-using-hamachi-tunngle-preferred/</guid>
<description><![CDATA[Foreword: I&#8217;ve decided to put this tutorial back up, which was originally created by author Ch]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><img class="aligncenter" src="http://i36.tinypic.com/v8igs1.jpg" alt="" width="282" height="400" /></p>
<blockquote><p>Foreword: I&#8217;ve decided to put this tutorial back up, which was originally created by author Chyea for Call of Duty World at War. Please note that the preferred method is Tunngle. You need to update your game to the latest version. Please see my exclusive Tunngle video below.</p>
<p>Of course, this article is no way in shape or form created to promote piracy. There are legitimate players with legitimate users who want to play this game via LAN with their friends.  This is an educational piece, and shall be treated as one.  ~ Versatile</p></blockquote>
<p>Revisions:<br />
11-17-09: Re-release of an old article per indiscreet demand. MW2 is a better game. Does anyone care about this one? <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<hr /><strong><span style="text-decoration:underline;">Tunngle Video </span></strong></p>
<p>&#160;</p>
<p><span style='text-align:center; display: block;'><object width='425' height='350'><param name='movie' value='http://www.youtube.com/v/7nnFPZS8tk8&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' /><param name='allowfullscreen' value='true' /><param name='wmode' value='transparent' /><embed src='http://www.youtube.com/v/7nnFPZS8tk8&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' type='application/x-shockwave-flash' allowfullscreen='true' width='425' height='350' wmode='transparent'></embed></object></span></p>
<p><!--more--></p>
<hr /><span style="text-decoration:underline;">Chyea&#8217;s old school tutorial starts below:</span></p>
<p>Note: It is highly recommended you go to www.filefront.com and download ALL the game patches to update yourself t the latest version. If you need new patch files, then go to www.gamecopyworld.com.<span style="text-decoration:underline;"> </span></p>
<p>All files have been scanned with NOD32 antivirus.</p>
<p><span style="color:#ff0000;"><strong>1. Download Hamachi 1.0.1.5: (</strong>the older versions are better, the newer one didn&#8217;t work for me<strong>)<br />
</strong></span></p>
<p><span style="color:#ff0000;"><strong><a href="http://www.filehippo.com/download_hamachi/">http://rapidshare.com/files/166420002/HamachiSetup-1.0.1.5-en.exe</a></strong></span></p>
<p><span style="color:#ff0000;"><strong>2. Run Hamachi and create a virtual LAN.</strong></span></p>
<p><span style="color:#ff0000;"><strong>3. Download this patch for the singleplayer version of the game:</strong></span></p>
<p><span style="color:#ff0000;"><strong>Call of Duty: World at War v1.0 PRIVATE SERVER PATCH #1<br />
<a href="//dl.gamecopyworld.com/?d=2008&#38;f=Call.of.Duty.5.LANFiX!7z">http://rapidshare.com/files/166420570/CoDWaW_LANFixed.exe</a></strong></span></p>
<p><span style="color:#ff0000;"><strong>This fixes the &#8220;CD key in use&#8221; issue.<br />
</strong></span></p>
<p><span style="color:#ff0000;"><strong>4. Paste the patch into your cod5 directory, don&#8217;t need to rename or anything.</strong></span></p>
<p><span style="color:#ff0000;"><strong>5. Both CLIENT and the HOST of the game server will use this patch to start up your game.</strong></span></p>
<p><span style="color:#ff0000;"><strong>6. If you encounter an error involving a conflict of CD keys, download this keygen by razor <a href="http://rapidshare.com/files/162328894/rzr-c5kg.exe">http://rapidshare.com/files/162328894/rzr-c5kg.exe</a></strong></span></p>
<p><span style="color:#ff0000;"><strong>and change your cd key.</strong></span></p>
<p>Edit: In the case that you have no friends, you can join a hamachi network with more activity. There are tons of them out there, if you know any, we&#8217;d appreciate it if you posted it in the comments.</p>
<p>Much thanks to RedDot, we acquired a lot more servers:</p>
<ul>
<li><span style="color:#008000;">Name: coop zombie -&#62; Password: 123</span></li>
<li><!--[if gte mso 9]&#62;  Normal 0     false false false  EN-US X-NONE X-NONE              MicrosoftInternetExplorer4              &#60;![endif]--><!--[if gte mso 9]&#62;                                                                                                                                            &#60;![endif]--><!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} a:link, span.MsoHyperlink 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:blue; 	mso-themecolor:hyperlink; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:purple; 	mso-themecolor:followedhyperlink; 	text-decoration:underline; 	text-underline:single;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --><!--[if gte mso 10]&#62; &#60;!   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} --> <!--[endif]-->
<p class="MsoNormal" style="margin-bottom:.0001pt;line-height:normal;"><span style="font-size:12pt;font-family:&#38;"> <a href="http://hamachi.cc/control/join.php?n=coop+zomie&#38;p=123"></a> </span></p>
<p class="MsoNormal" style="margin-bottom:.0001pt;line-height:normal;"><span style="color:#008000;">Name: coop zombie2 -&#62; Password: 123</span></p>
</li>
<li>
<p class="MsoNormal" style="margin-bottom:.0001pt;line-height:normal;"><span style="color:#008000;">Name: cod5waw.vcr.pl-&#62; Password: 123</span></p>
</li>
<li>
<p class="MsoNormal" style="margin-bottom:.0001pt;line-height:normal;"><span style="color:#008000;">Name: cod5waw.vcr.pl1-&#62; Password: 123</span></p>
</li>
<li><span style="color:#008000;">Name: cod5waw.vcr.pl2-&#62; Password: 123</span></li>
<li><span style="color:#008000;">Name: cod5waw.vcr.pl3-&#62; Password: 123</span></li>
<li><span style="color:#008000;">Name: cod5waw.vcr.pl4-&#62; Password: 123</span></li>
<li><span style="color:#008000;">Name: cod5waw.vcr.pl5-&#62; Password: 123</span></li>
<li><span style="color:#008000;">Name: cod5waw.vcr.pl6-&#62; Password: 123</span></li>
<li><span style="color:#008000;">Name: cod5waw.vcr.pl7-&#62; Password: 123</span></li>
<li><span style="color:#008000;">Name: cod5waw.vcr.pl8-&#62; Password: 123</span></li>
<li><span style="color:#008000;">Name: cod5waw.vcr.pl9-&#62; Password: 123</span></li>
<li><span style="color:#008000;">Name: cod5waw.vcr.pl10-&#62; Password: 123</span></li>
</ul>
<p>Warning: if you do join a big hamachi network, be sure to go to your control panel and make sure your hamachi network is set to &#8220;public&#8221;, so that other peeps won&#8217;t be able to see your personal folders.</p>
<p>Don&#8217;t go anywhere, we will write a tutorial on how to play multiplayer soon.</p>
<p>Here&#8217;s a screenshot of it on my computer:</p>
<p><a href="http://versatile1.wordpress.com/files/2008/11/test1.jpg"><img class="alignnone size-full wp-image-1390" title="test1" src="http://versatile1.wordpress.com/files/2008/11/test1.jpg" alt="test1" width="336" height="210" /></a></p>
<p>And here is a video of how I got mine to work, you can download it here and see it more clearly, or you can scroll down and look at the crappy youtube quality vid.</p>
<p><a href="http://rapidshare.com/files/168327132/cod5.wmv">http://rapidshare.com/files/168327132/cod5.wmv</a></p>
<p><span style='text-align:center; display: block;'><object width='425' height='350'><param name='movie' value='http://www.youtube.com/v/TOvMKV4P2dM&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' /><param name='allowfullscreen' value='true' /><param name='wmode' value='transparent' /><embed src='http://www.youtube.com/v/TOvMKV4P2dM&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' type='application/x-shockwave-flash' allowfullscreen='true' width='425' height='350' wmode='transparent'></embed></object></span></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[vpnc with ssl on ubuntu]]></title>
<link>http://flukebox.wordpress.com/2009/11/16/vpnc-with-ssl-on-ubuntu/</link>
<pubDate>Mon, 16 Nov 2009 16:52:53 +0000</pubDate>
<dc:creator>flukebox</dc:creator>
<guid>http://flukebox.wordpress.com/2009/11/16/vpnc-with-ssl-on-ubuntu/</guid>
<description><![CDATA[Previously I used Cisco VPN client for connecting to my company VPN. But since, I moved to kernel 2.]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><span style="font-family:lucida grande;">Previously I used Cisco VPN client for connecting to my company VPN. But since, I moved to kernel 2.6.30+ things are broken. Cisco VPN client does not work anymore. Whenever I tried to connect to VPN whole system freeze and I had to do a hard power off. So, I switched to </span><a style="font-weight:bold;font-family:lucida grande;" href="http://www.unix-ag.uni-kl.de/%7Emassar/vpnc/">VPNC</a><span style="font-family:lucida grande;">, which worked quite but after lot of tweaks. Moreover, you have to extract the configuration for VPNC from Cisco VPN profile files (*.pcf) . You can use </span><a style="font-weight:bold;font-family:lucida grande;" href="http://svn.unix-ag.uni-kl.de/vpnc/trunk/pcf2vpnc">pcf2vpnc</a><span style="font-family:lucida grande;"> to extract configuration for you from *.pcf profile files.</span></p>
<p><span style="font-family:lucida grande;">Extracted configuration file would look like as below.</span><br />
<span style="font-weight:bold;font-family:lucida grande;">## generated by pcf2vpnc</span><br />
<span style="font-family:lucida grande;">IPSec ID </span><span style="font-weight:bold;font-family:lucida grande;">your-group-id</span><br />
<span style="font-family:lucida grande;">IPSec secret </span><span style="font-weight:bold;font-family:lucida grande;">your-group-secret</span><br />
<span style="font-family:lucida grande;">IPSec gateway </span><span style="font-weight:bold;font-family:lucida grande;">your-vpn-gateway</span><br />
<span style="font-family:lucida grande;">Xauth username </span><span style="font-weight:bold;font-family:lucida grande;">flukebox</span><br />
<span style="font-family:lucida grande;">Enable </span><span style="font-weight:bold;font-family:lucida grande;">Single DES</span><br />
<span style="font-family:lucida grande;">IKE </span><span style="font-weight:bold;font-family:lucida grande;">Authmode</span><span style="font-family:lucida grande;"> </span><span style="font-weight:bold;font-family:lucida grande;">hybrid</span><br />
<span style="font-family:lucida grande;">CA-File </span><span style="font-weight:bold;font-family:lucida grande;">path-to-certificate file</span><br />
<span style="font-family:lucida grande;">Application version</span><span style="font-weight:bold;font-family:lucida grande;"> &#8220;Cisco Systems VPN Client 4.8.01 (0640):Linux&#8221;</span><br />
<span style="font-family:lucida grande;">Script </span><span style="font-weight:bold;font-family:lucida grande;">/etc/vpnc/vpnc-script</span></p>
<p><span style="font-family:lucida grande;">You can connect to your vpn server </span><span style="font-weight:bold;font-family:lucida grande;">vpnc-connect</span><span style="font-family:lucida grande;"> in </span><span style="font-weight:bold;font-family:lucida grande;">root</span><span style="font-family:lucida grande;"> or </span><span style="font-weight:bold;font-family:lucida grande;">sudo</span><span style="font-family:lucida grande;"> mode.</span></p>
<p><span style="font-family:lucida grande;">There could be few glitches when using </span><span style="font-weight:bold;font-family:lucida grande;">vpnc</span><span style="font-family:lucida grande;"> on Ubuntu. Due some licensing issues, vpnc</span><span style="font-family:lucida grande;"> is not built with </span><span style="font-weight:bold;font-family:lucida grande;">ssl</span><span style="font-family:lucida grande;"> </span><span style="font-weight:bold;font-family:lucida grande;">support</span><span style="font-family:lucida grande;"> on </span><span style="font-weight:bold;font-family:lucida grande;">Ubuntu</span><span style="font-family:lucida grande;"> and you may see error like this.</span></p>
<p><span style="font-weight:bold;font-family:lucida grande;">vpnc was built without openssl: Can&#8217;t do hybrid or cert mode.</span><br />
<span style="font-family:lucida grande;">To avoid that you have to built the vpnc from source manually which is quite easy though.</span></p>
<p><span style="font-family:lucida grande;">Get necessary package to built vpnc with ssl support.</span><br />
<span style="font-weight:bold;font-family:lucida grande;">$apt-get install libgcrypt11-dev openssl libssl-dev</span></p>
<p><span style="font-family:lucida grande;">Create a temp vpnc directory to hold the source.</span><br />
<span style="font-weight:bold;font-family:lucida grande;">$mkdir /tmp/vpnc</span><br />
<span style="font-weight:bold;font-family:lucida grande;">$cd /tmp/vpnc</span></p>
<p><span style="font-family:lucida grande;">Get the source of vpnc and cd to source directory</span><br />
<span style="font-weight:bold;font-family:lucida grande;">$apt-get source vpnc</span><br />
<span style="font-weight:bold;font-family:lucida grande;">$cd vpnc-version</span></p>
<p><span style="font-family:lucida grande;">Now, modify Makefile to enable SSL support. Basically search for OPENSSL in Makefile</span><span style="font-family:lucida grande;"> and uncomment OPENSSL options, than save the file.</span></p>
<p><span style="font-weight:bold;font-family:lucida grande;">48 # Comment this in to obtain a binary with certificate support which is</span><br />
<span style="font-weight:bold;font-family:lucida grande;">49 # GPL incompliant though.</span><br />
<span style="font-weight:bold;font-family:lucida grande;">50 #OPENSSL_GPL_VIOLATION = -DOPENSSL_GPL_VIOLATION </span><br />
<span style="font-weight:bold;font-family:lucida grande;">51 #OPENSSLLIBS = -lcrypto</span></p>
<p><span style="font-weight:bold;font-family:lucida grande;">$vi Makefile</span></p>
<p><span style="font-weight:bold;font-family:lucida grande;">48 # Comment this in to obtain a binary with certificate support which is</span><br />
<span style="font-weight:bold;font-family:lucida grande;">49 # GPL incompliant though.</span><br />
<span style="font-weight:bold;font-family:lucida grande;">50 OPENSSL_GPL_VIOLATION = -DOPENSSL_GPL_VIOLATION</span><br />
<span style="font-weight:bold;font-family:lucida grande;">51 OPENSSLLIBS = -lcrypto</span></p>
<p><span style="font-family:lucida grande;">Now, build the package by running the following command in vpnc source directory.</span><br />
<span style="font-weight:bold;font-family:lucida grande;">$dpkg-buildpackage</span></p>
<p><span style="font-family:lucida grande;">If everything goes fine, you will see  a vpnc_version_i386.deb package in /tmp/vpnc</span><span style="font-family:lucida grande;"> made by dpkg. Which you can install with dpkg -i.</span><br />
<span style="font-weight:bold;font-family:lucida grande;">$dpkg -i vpnc_version_i386.deb</span></p>
<p><span style="font-family:lucida grande;">Now, enjoy connecting with vpn network and happy coding </span><span style="font-weight:bold;font-family:lucida grande;"> <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </span></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[VPN's, censorship, and the good fight]]></title>
<link>http://thepeoplearetryingtosleep.wordpress.com/2009/11/16/vpns-censorship-and-the-good-fight/</link>
<pubDate>Mon, 16 Nov 2009 11:47:09 +0000</pubDate>
<dc:creator>thepeoplearetryingtosleep</dc:creator>
<guid>http://thepeoplearetryingtosleep.wordpress.com/2009/11/16/vpns-censorship-and-the-good-fight/</guid>
<description><![CDATA[A few thoughts on VPN&#8217;s: VPN (virtual private network) One can buy VPN service subscriptions f]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>A few thoughts on VPN&#8217;s:</p>
<p>VPN (virtual private network)<br />
<img src="http://lookpic.com/i/250/dNC2OzaU.png" alt="VPN image in Ubuntu" /><br />
One can buy VPN service subscriptions for as little as 6 euro/month.  That&#8217;s cheap for &#8220;perfect&#8221; (or whatever) anonymity, whether you want to fileshare (and your ISP forbids legal file sharing), whether you live in <a href="http://www.greatfirewallofchina.org/">China</a>, <a href="http://en.wikipedia.org/wiki/Internet_censorship_in_Australia">Australia</a>, <a href="http://opennet.net/blog/2008/10/burma-steps-up-internet-restrictions">Burma</a>, or <a href="http://en.wikipedia.org/wiki/Censorship_in_Iran#Internet_Censorship_in_Iran">Iran</a> (and the web is censored or much of it blocked) or if you want to use streaming video sites that are prohibited in your region.  Or if you just don&#8217;t want your ISP to know every site that you visit: because now they have to <a href="http://cyberlaw.org.uk/2009/05/28/sweden-challenges-eu-data-retention-directive/">retain</a> that sort of information.  It&#8217;s better than a proxy in some respects because you can run any protocol, from mail to skype to utorrent through it.  It&#8217;s terrible to have to pay for anonymity, and maybe this sends the wrong message (i.e. we should be battling for <a href="http://www.eff.org/">our rights online</a>, not subverting their authority with cool technologies) &#8212; but really we need to open the world up, not censor and close it up.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SSL and TLS Protocols Renegotiation Vulnerability]]></title>
<link>http://sdaguiar.wordpress.com/2009/11/15/ssl-and-tls-protocols-renegotiation-vulnerability/</link>
<pubDate>Sun, 15 Nov 2009 06:13:27 +0000</pubDate>
<dc:creator>Scott D. Aguiar</dc:creator>
<guid>http://sdaguiar.wordpress.com/2009/11/15/ssl-and-tls-protocols-renegotiation-vulnerability/</guid>
<description><![CDATA[On 11/05/09 the notice of Renegotiation vulnerabilities within SSL/TLS protocols became public.  The]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>On 11/05/09 the notice of Renegotiation vulnerabilities within SSL/TLS protocols became public.  The vulnerability allows for injection of arbitrary plain-text allowing for HTTP requests, or impersonate the victim, as well as other consequences.</p>
<p>~Opinion~</p>
<p>While the known possible outcomes of this vulnerability seem similar to many of the run-of-the-mill exploits we&#8217;ve seen, the ramifications behind this vulnerability are monumental.</p>
<p>Just the number of vendors, and their products effected by this alone show that there will soon be a revolution.  The affect on everyday lives of so many will undoubtedly negative.</p>
<p>Either a major overhaul of the protocols is necessary, or we are in for a new breed of security focus.  An overhaul is most likely to occur; however, if it doesn&#8217;t we will have to be prepared to move into a security stance which covers security in both a pre- and post- environment.</p>
<p>Our previously hardened infrastructure would have to be analyzed, and protected during use.  Protecting our protection if you will.</p>
<p>While all this seems goofy, given the fact that we will most likely just patch and move on, it seems to beckon the time for more intuitive security measures is nearing, or hear.  Security measures that&#8230; think.</p>
<p>Packets with guns.  Headers with secret handshakes. Connections that conspire against their own existence.</p>
<p>~/Opinion~</p>
<p>&#160;</p>
<p>As usual, if you want to hear more information, visit the link below&#8230; And I am very interested in hearing comments on this one&#8230; Maybe I am just blowing it out of proportion, but it seems big.</p>
<p><a class="aligncenter" title="SSL/TLS Renegotiation Vulnerability" href="http://www.kb.cert.org/vuls/id/120541" target="_blank">Vulnerability Note VU#120541 (New Window)</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Using Public Wi-Fi? Hop Into a Free VPN Tunnel First]]></title>
<link>http://gigaom.com/2009/11/13/using-public-wi-fi-hop-into-a-free-vpn-tunnel-first/</link>
<pubDate>Fri, 13 Nov 2009 19:05:34 +0000</pubDate>
<dc:creator>Sebastian Rupley</dc:creator>
<guid>http://gigaom.com/2009/11/13/using-public-wi-fi-hop-into-a-free-vpn-tunnel-first/</guid>
<description><![CDATA[I spent several hours during yesterday&#8217;s NewTeeVee Live conference at San Francisco&#8217;s Mi]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><img class="alignnone" src="http://farm3.static.flickr.com/2072/2490605502_0c34e6f7d9_o.jpg" alt="" width="178" height="106" />I spent several hours during yesterday&#8217;s <a href="http://newteevee.com/2009/11/12/tv-everywhere-live-stream-of-newteevee-live/">NewTeeVee Live</a> conference at San Francisco&#8217;s Mission Bay Conference Center sitting at the press table with tech writers from various publications who were connecting to the open Wi-Fi network. Before I connected to the center&#8217;s hotspot, I loaded a VPN (virtual private network) application, which provides a secure, encrypted tunnel within which I use public Wi-Fi. The one I use happens to be custom and proprietary, and takes about 15 seconds to establish a connection that will keep me completely secure on an open network.</p>
<p>I noticed, though, that while some of the writers at the conference were probably using firewalls, hardly any of them used VPNs to keep their Wi-Fi sessions completely secure. And these were tech writers. That&#8217;s a shame, because there are <a href="http://webworkerdaily.com/2007/08/17/free-vpn-solutions-for-securing-your-public-wi-fi-sessions/">a lot of good, completely free VPN applications</a> available.<!--more--></p>
<p>One of the <a href="http://webworkerdaily.com/2008/04/09/4-ways-to-keep-your-public-wi-fi-sessions-secure/">best choices </a>out there is <a href="http://openvpn.net/">OpenVPN</a>, an open-source, cross-platform VPN solution. The freeware world, too, includes many VPN applications that users swear by, such as <a href="http://www.iopus.com/iPig/">iPig</a> from iOpus and the free version of <a href="https://secure.logmein.com/products/hamachi2/">LogMeIn&#8217;s Hamachi</a>. <a href="http://compnetworking.about.com/od/vpn/p/ciscovpnclient.htm">Cisco&#8217;s (S csco) cross-platform VPN client</a> is also widely used, although note that it&#8217;s incompatible with some firewalls. <a href="http://www.hotspotshield.com/">Hotspot Shield</a> is also well-liked by many Windows and Mac users.</p>
<p>Windows 7 (S msft) actually comes with a built-in Agile VPN client, but it&#8217;s not said to be as easy as many of the free, time-tested clients. Snow Leopard (S aapl) Server also offers VPN functionality, and previous versions of the Mac OS have included it. For many users, though, especially ones who don&#8217;t have access to help from an IT department, simple, free downloadable VPN solutions&#8211;which usually have intuitive interfaces&#8211;are great choices.</p>
<p>VPN applications couldn&#8217;t be easier to use. Once installed, you simply sign in to them, and your online communications are routed through encrypted tunnels. Problems with particular VPN clients are typically the result of firewall-related conflicts, but you can easily find an app that works for you.</p>
<p>As is always true with security software solutions, user apathy is the biggest problem of all. So the next time you use public Wi-Fi, make sure you hop into a secure VPN tunnel first.</p>
<p><em>Do you use a VPN application that you like?</em></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Real Security for a Virtual Network]]></title>
<link>http://3comsblog.wordpress.com/2009/11/13/real-security-for-a-virtual-network/</link>
<pubDate>Fri, 13 Nov 2009 16:10:05 +0000</pubDate>
<dc:creator>3Com Corporation</dc:creator>
<guid>http://3comsblog.wordpress.com/2009/11/13/real-security-for-a-virtual-network/</guid>
<description><![CDATA[By Gary Kinghorn Virtualization has certainly become a driving factor in networking, application dep]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>By <a href="mailto:gary_kinghorn@3com.com">Gary Kinghorn</a></p>
<p><a title="wiki link" href="http://en.wikipedia.org/wiki/Network_virtualization" target="_blank">Virtualization</a> has certainly become a driving factor in networking, application deployment and data center design over the last few years. One of our marketing folks recently ran across an interesting deployment scenario where as part of a large network virtualization project, they were also making use of virtual firewalls to virtualize the security layer of their network, further reducing costs. While the first step of virtualization usually happens in the application server, customers should also be thinking about ways to reduce hardware costs and management complexity by taking advantage of the same concepts inherent in all of our <a title="Security link" href="http://h3cnetworks.com/en_US/category.page?pathtype=Purchase&#38;category=CAT_SECURITY&#38;name=Security" target="_blank">H3C security appliances and blades</a>.</p>
<p>The typical deployment scenario goes something like this: A large distributed enterprise has multiple campuses, or a large distributed campus, with divisions or groups spread throughout. You can think of these as potentially subsidiaries of a conglomerate, departments in a university, or logically separated clean-room projects. The problem is that the physical location of the groups is not aligned with the physical layout of the campuses or buildings. This is a challenge for network designs that frequently are aligned with campus layouts and not the virtual organizations. Virtual Local Area Networks (VLANs) work well locally, when closely mirroring the network topology, but don’t work well across the enterprise WAN, since Layer 2 network virtualization doesn’t scale when extended through the Layer 3 routers.</p>
<p>Providing the functionality of a VLAN for a widely separated logical group (over a Layer 3 WAN or router core) requires a technology called <a title="VRF wiki" href="http://en.wikipedia.org/wiki/VRF" target="_blank">Virtual Routing and Forwarding (VRF)</a>. This provides what could be thought of as a virtual VLAN (but that sounds both redundant and confusing). These new private WANs are more accurately called VRFs, or what can logically be viewed as a wide area broadcast domain.</p>
<p>VRFs effectively provide the appropriate policy enforcement and network capacity appropriate for each division or group, no matter what their size, while sharing the same Layer 2 and 3 network infrastructure with many other VRFs. This can help optimize network resources and provide better service to individual users. These VRFs are reasonably straightforward to set up and manage since the H3C <a title="Routers link" href="http://h3cnetworks.com/en_US/category.page?pathtype=Purchase&#38;category=CAT_ROUTERS&#38;name=Routers" target="_blank">networking infrastructure</a> and <a title="IMC link" href="http://h3cnetworks.com/en_US/category.page?pathtype=Purchase&#38;category=CAT_NTWK_MNMGT&#38;name=Network-Management" target="_blank">management platform</a> supports this capability for highly scalable deployments.</p>
<p>But things get even better when enterprises take advantage of virtual firewalls. Whereas logically distinct organizations sharing a network would need their own firewall to protect their LAN segment and to define their unique security policies, firewalls no longer need a one-to-one correspondence with the LAN segment they are protecting any more than an enterprise application still needs its own server to provide adequate service. In essence, a single physical firewall can be divided into hundreds of virtual firewalls, each with its own distinct set of rules, aligned with a particular LAN segment, VLAN, or VRF and can be individually managed by a local group administrator (as needed).</p>
<p>The enterprise class <a title="security link" href="http://h3cnetworks.com/en_US/product.page?pathtype=Purchase&#38;category=CAT_SECURITY&#38;class=CLS_SEC_APPLIANCES&#38;family=FAM_SP_FRWL&#38;product=0150A0AG&#38;name=H3C-SecPath-F5000-A5-Advanced-VPN-Firewall" target="_blank">SecPath F5000-A5</a> and the <a title="secblade link" href="http://h3cnetworks.com/en_US/family.page?pathtype=Purchase&#38;category=CAT_SECURITY&#38;class=CLS_INTEGR_SEC&#38;family=FAM_SB_FRWL&#38;name=H3C-SecBlade-Advanced-VPN-Firewall-Modules" target="_blank">SecBlade VPN Firewall</a> module, for example, both support up to 256 virtual firewalls. The SecBlade module could be deployed right into one of the core router chassis, and all the traffic that flows through the firewall can be partitioned to the right VLAN, applying the relevant policies. A widely distributed VLAN doesn’t need a firewall at each physical site. A few physical firewalls can support hundreds of distributed VLANs in a highly scalable fashion, no matter how widely distributed, as part of a larger virtual network. This can greatly reduce the proliferation of security devices by consolidating and centralizing deployments, while greatly reducing ongoing management costs and overhead. Networks will be able to grow more efficiently and cost-effectively, and maximize use of shared resources.</p>
<p>Interested in hearing more? Give us a call and we’ll show you how.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Que utilidad darle a nuestros viejos equipos inform&aacute;ticos en una organizaci&oacute;n? PARTE II]]></title>
<link>http://gerardopauza.wordpress.com/2009/11/13/que-utilidad-darle-a-nuestros-viejos-equipos-informticos-en-una-organizacin-parte-ii/</link>
<pubDate>Fri, 13 Nov 2009 15:22:00 +0000</pubDate>
<dc:creator>gerardopauza</dc:creator>
<guid>http://gerardopauza.wordpress.com/2009/11/13/que-utilidad-darle-a-nuestros-viejos-equipos-informticos-en-una-organizacin-parte-ii/</guid>
<description><![CDATA[Seguridad de la información, acceso remoto a la red organizacional y filtrado de correos spam son ne]]></description>
<content:encoded><![CDATA[Seguridad de la información, acceso remoto a la red organizacional y filtrado de correos spam son ne]]></content:encoded>
</item>
<item>
<title><![CDATA[ KU VPN ใน Ubuntu 9.10]]></title>
<link>http://darker08.wordpress.com/2009/11/13/ku-vpn-ubuntu-9-10/</link>
<pubDate>Fri, 13 Nov 2009 14:37:38 +0000</pubDate>
<dc:creator>darker08</dc:creator>
<guid>http://darker08.wordpress.com/2009/11/13/ku-vpn-ubuntu-9-10/</guid>
<description><![CDATA[เนื่องด้วยเจ้าโคอาล่ามีกรรม(Karmic Koala) นั้นเพิ่งจะคลอดออกมา (ไม่ได้เป็นญาติกับหลินฮุ่ยหรือลิ้นห้อ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><div>
<p>เนื่องด้วยเจ้าโคอาล่ามีกรรม(Karmic Koala) นั้นเพิ่งจะคลอดออกมา (ไม่ได้เป็นญาติกับหลินฮุ่ยหรือลิ้นห้อยแต่ประการใด&#8230;) แล้ว GUI ใหม่ของ VPN มันก็เลยเปลี่ยนไปนิดหน่อย บางคนอาจจะไม่คุ้นกัน (ที่จริงมันแปลเป็นภาษาคนมากขึ้น ฮ่าๆ)</p>
<p style="padding-left:30px;"><strong>ขั้นตอนการติดตั้ง</strong><br />
1.ก่อนอื่นเลยก็เข้าไปโหลดไฟล์ Cer จาก <a title="https://vpn.ku.ac.th" href="https://vpn.ku.ac.th/">https://vpn.ku.ac.th</a> โหลดมาแล้วก็แตกไฟล์ออกมาซะ ข้างในจะมีไฟล์ bxxxxx@yyy.crt,bxxxxx@yyy.key,bxxxxx@yyy.ovpn และ ca.crt เอาไปไว้ซักที่<br />
2.แล้วก็ต้องติดตั้งโปรแกรม 2 ตัวครับ openvpn,network-manager-openvpn จะลงด้วยวิธีใดก็สุดแล้วแต่ความถนัดเลยนะครับ ส่วนผมก็<br />
<em>sudo apt-get install openvpn network-manager-openvpn</em><br />
ใครไม่ถนัดก็<em> System -&#62; Administration -&#62; Synaptic Package Manager</em></p>
<p style="padding-left:30px;">3.หลังจากนั้นก็เข้ามาตั้งค่า vpn ที่ network applet ที่มุมบนขวาเลยครับ  <a href="http://darker08.wordpress.com/files/2009/11/1.png"><img class="aligncenter size-full wp-image-139" title="Network Applet" src="http://darker08.wordpress.com/files/2009/11/1.png" alt="Network Applet" width="24" height="24" /></a></p>
<p style="padding-left:30px;text-align:left;">4.คลิกเข้าไปที่<em> VPN Connection-&#62;Configure VPN</em></p>
<p style="padding-left:30px;text-align:left;"><em> </em> <a href="http://darker08.wordpress.com/files/2009/11/2.png"><img class="aligncenter size-full wp-image-140" title="Configure VPN" src="http://darker08.wordpress.com/files/2009/11/2.png" alt="Configure VPN" width="354" height="212" /></a>5.จะได้หน้าต่างใหม่ขึ้นมา ที่แท็บ VPN กด Add แล้วจะมีหน้าต่างเล็กเด้งมาอีกกด Create</p>
<p style="padding-left:30px;text-align:left;"><a href="http://darker08.wordpress.com/files/2009/11/4.png"><img class="aligncenter size-medium wp-image-141" title="Add New VPN" src="http://darker08.wordpress.com/files/2009/11/4.png?w=300" alt="Add New VPN" width="300" height="247" /></a>6.หน้าต่างใหม่จะขึ้นมาก็ใส่ข้อมูลดังนี้</p>
<p style="padding-left:30px;text-align:left;"><a href="http://darker08.wordpress.com/files/2009/11/5.png"><img class="aligncenter size-medium wp-image-142" title="Configure Connection" src="http://darker08.wordpress.com/files/2009/11/5.png?w=300" alt="Configure Connection" width="300" height="205" /></a></p>
<blockquote>
<blockquote>
<ul>
<li>Connection name ก็ตั้งชื่อ Connection เช่น KU VPN</li>
<li>Gateway ใส่ nisit.vpn.ku.ac.th</li>
<li>Security Type เป็น Password with Certificates</li>
<li>Username ก็ใส่ Nontri Account ลงไป</li>
<li>Password ก็ใส่รหัสนนทรี</li>
<li>User Certificate ก็กดเลือกไฟล์ bxxxx@bkn.crt</li>
<li>CA Certificate ก็กดเลือกไฟล์ ca.crt</li>
<li>Private Key ก็กดเลือกไฟล์ bxxxx@bkn.key</li>
<li>Private Key Password ปล่อยว่าง</li>
<li>สุดท้ายก็กดปุ่ม Advanced แล้วติ๊กเลือก use LZO Data Compression กับ use a TAP device</li>
</ul>
</blockquote>
</blockquote>
<div><strong>ขั้นตอนการใช้งาน</strong></div>
<div style="padding-left:30px;">1.กดที่ Network Applet ที่เดิม  <em>VPN Connection-&#62; ชื่อ Connection ที่ตั้งไว้เมื่อกี้</em></div>
<div style="padding-left:30px;"><a href="http://darker08.wordpress.com/files/2009/11/6.png"><img class="aligncenter size-medium wp-image-143" title="connect" src="http://darker08.wordpress.com/files/2009/11/6.png?w=300" alt="connect" width="300" height="183" /></a>2.ระหว่างนี้ก็รอตอนมันกำลังต่อ</div>
<div style="padding-left:30px;"><a href="http://darker08.wordpress.com/files/2009/11/7.png"><img class="aligncenter size-full wp-image-144" title="Connecting" src="http://darker08.wordpress.com/files/2009/11/7.png" alt="Connecting" width="24" height="24" /></a>3. กดอนุญาตให้เก็บใน keyring</div>
<div style="padding-left:30px;"><a href="http://darker08.wordpress.com/files/2009/11/8.png"><img class="aligncenter size-medium wp-image-145" title="8" src="http://darker08.wordpress.com/files/2009/11/8.png?w=300" alt="8" width="300" height="144" /></a></div>
<div style="padding-left:30px;">4. ต่อติดแล้ว</div>
<p style="text-align:left;padding-left:60px;">
<p style="text-align:left;padding-left:60px;"><a href="http://darker08.wordpress.com/files/2009/11/9.png"><img class="aligncenter size-full wp-image-146" title="Connected" src="http://darker08.wordpress.com/files/2009/11/9.png" alt="Connected" width="24" height="24" /></a></p>
<p style="text-align:left;">credit : <a href="http://www.ploysics.com/openvpn-on-ubuntu/">ploysics</a></p>
<p style="text-align:left;padding-left:60px;">
<p style="padding-left:30px;text-align:left;">
<p style="padding-left:30px;">
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Les équipements de Sécurité “Tout-en-Un” sont-ils toujours adaptés à la PME ? ]]></title>
<link>http://pmeblog.cisco-france.com/2009/11/12/les-equipements-de-securite-%e2%80%9ctout-en-un%e2%80%9d-sont-ils-toujours-adaptes-a-la-pme/</link>
<pubDate>Thu, 12 Nov 2009 15:02:40 +0000</pubDate>
<dc:creator>rfattori@cisco.com</dc:creator>
<guid>http://pmeblog.cisco-france.com/2009/11/12/les-equipements-de-securite-%e2%80%9ctout-en-un%e2%80%9d-sont-ils-toujours-adaptes-a-la-pme/</guid>
<description><![CDATA[La sécurité « tout-en-un » pour les PME a connu dans les années 2000 un essor fulgurant lié à plusie]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>La sécurité « tout-en-un » pour les PME a connu dans les années 2000 un essor fulgurant lié à plusieurs  facteurs : un raccordement massif des PME à Internet, l’explosion des menaces (virus, spyware, spam, phishing), et l’attrait financier que représente pour les pirates ces dizaines de milliers de PME  si faciles à spammer, infiltrer, rançonner, siphonner… Les PME ont plébiscité ces boitiers « tout-en-un » à base de logiciel open-source et de hardware générique. En effet, <strong>regrouper Pare-feu, Antivirus, VPN et même AntiSpam et filtrage d’URL dans une seule boite : c’est moins cher à l’achat, et c’est plus facile à gérer</strong>.</p>
<p>Cisco, construisant des réseaux destinés à accueillir la voix sur IP et la vidéo, n’était pas prêt à transiger sur la performance du firewall. Le célèbre Cisco PIX n’a jamais fait d’antivirus, tandis que les  « tout-en-un » en faisaient leur fonds de commerce. <strong>Fallait-il céder aux sirènes et se résoudre à fournir un firewall qui ne capture qu’un virus sur deux au prix d’un fonctionnement aléatoire ?</strong></p>
<p>Le remplacement du PIX par l’ASA a permis l’intégration du filtrage de contenu dans le firewall, mais sans fournir de vrai « tout-en-un » pour les plus petites PME… La carte d’extension Trend Micro sur l’ASA est <strong>une solution d’Entreprise</strong> <strong>: il faut accepter de payer la qualité d’une solution logicielle reconnue embarquée sur un hardware dédié qui ne pénalise pas les performances du firewall</strong>. Caramba, encore raté…</p>
<p><strong>La solution est venue du filtrage en mode hébergé « dans le nuage »</strong>, qu’on peut aussi qualifier de SAAS (software as a service). On connaissait les offres des opérateurs (l’option Antispam de votre FAI personnel…) : pas franchement impressionnant d’efficacité et de souplesse de réglage. Ou encore les offres de messagerie d’entreprise du type Messagelabs : trop haut-de-gamme. Mais cette fois ça y est, les investissements sont faits, les datacenters sont opérationnels.</p>
<p><strong>Les PME ont dorénavant leur solution « Tout-en-Un » Cisco : le Cisco SA500</strong> <strong>propose un service de filtrage de contenu entièrement « dans le nuage » pour les entreprises de moins de 100 utilisateurs.</strong> Le SA500 offre firewall et VPN à très hautes performances avec une administration graphique simplissime en trois clics. L’AntiSpam, l’Antivirus et le filtrage d’URL se font grâce aux Datacenters de Trend Micro. Le client conserve la possibilité de configurer sa propre politique de filtrage, et dispose de rapports d’activité détaillés. Les avantages sans les inconvénients : pas d’impact sur les performances du boîtier, pas de travail de déploiement ou de mise-à-jour, et une protection qui reste efficace en toutes circonstances grâce à une connaissance mutualisée des menaces en temps réel. Non seulement <strong>c’est plus simple et moins couteux en efforts et en matériel, mais c’est également plus efficace face aux nouvelles menaces comme les Botnets que les antivirus embarqués sont incapables d’identifier</strong>.  Les boitiers « tout-en-un » qui embarquent l’ « antivirus de papa » viennent de prendre un coup de vieux.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Comodo EasyVPN Creates a Virtual Private Network in a Few Clicks]]></title>
<link>http://atomfire.com/2009/11/11/comodo-easyvpn-creates-a-virtual-private-network-in-a-few-clicks/</link>
<pubDate>Wed, 11 Nov 2009 16:47:50 +0000</pubDate>
<dc:creator>Atomfire Tech News</dc:creator>
<guid>http://atomfire.com/2009/11/11/comodo-easyvpn-creates-a-virtual-private-network-in-a-few-clicks/</guid>
<description><![CDATA[Windows only: Free application Comodo EasyVPN creates a virtual private network between your compute]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><img src="http://cache.gawker.com/assets/images/17/2009/11/500x_comodo-easyvpn.jpg" width="500" alt="500x_comodo-easyvpn.jpg" /></p>
<p>Windows only: Free application Comodo EasyVPN creates a virtual private network between your computers for a hassle-free, secure private network. That means you can access, for example, anything on your home computer from work as though you&#8217;re on the same local network.<!--more--></p>
<p>Comodo EasyVPN, like <a href="http://lifehacker.com/201786/geek-to-live--create-your-own-virtual-private-network-with-hamachi">previously mentioned VPN app Hamachi</a>, is simple to set up. Just install the application, register for an account, and then log in. Once you&#8217;ve got the app running on a couple of computers, you can easily (and securely) access one computer from the other as though you&#8217;re on the same local network.</p>
<p>As we mentioned in our <a href="http://lifehacker.com/201786/geek-to-live--create-your-own-virtual-private-network-with-hamachi">guide to Hamachi</a>, a VPN comes in handy when:</p>
<blockquote>
<ul>
<li>You&#8217;re on the road with your laptop and want secure access to your PC&#8217;s files.</li>
<li>Your office or dorm room computer is behind a restrictive firewall that doesn&#8217;t let you reach it from the internet.</li>
<li>You want to add encryption to insecure network protocols like VNC.</li>
<li>You want to set up a shared folder of files for friends and family to access.</li>
</ul>
</blockquote>
<p>We showed you how to set up <a href="http://lifehacker.com/228862/geek-to-live--secure-vnc-with-hamachi">secure VNC with Hamachi</a>, and the same basic steps would apply with Comodo EasyVPN. So is EasyVPN better than Hamachi? Not necessarily, but since LogMeIn bought <a href="https://secure.logmein.com/products/hamachi2/">Hamachi</a>, it&#8217;s only free for non-commercial use. If you want or need to use a VPN for work purposes and don&#8217;t have the extra budget, Comodo EasyVPN will do the job nicely. <em>Update: Apparently EasyVPN is also only available for non-commercial use. This information was not on the main page, but I missed it on their download page. Apologies for the confusion.</em> Apart from the basics, EasyVPN also comes with a built-in, secure chat tool.</p>
<p>Comodo EasyVPN is a free download, works with Windows XP and above with support for 32- and 64-bit systems.</p>
<p><a href="http://easy-vpn.comodo.com/">Comodo EasyVPN</a> [Comodo via <a href="http://www.downloadsquad.com/2009/11/09/comodo-easy-vpn-is-a-fast-free-hamachi-alternative-for-windows/">Download Squad</a>]</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[IPsec]]></title>
<link>http://yanuangga.wordpress.com/2009/11/10/ipsec/</link>
<pubDate>Tue, 10 Nov 2009 16:50:28 +0000</pubDate>
<dc:creator>yanuangga</dc:creator>
<guid>http://yanuangga.wordpress.com/2009/11/10/ipsec/</guid>
<description><![CDATA[IP Security, atau IP Sec untuk jangka pendek, adalah kerangka kerja standar yang memberikan kunci be]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>IP Security, atau IP Sec untuk jangka pendek, adalah kerangka kerja standar yang memberikan kunci berikut fitur keamanan pada jaringan peer lapisan antara dua perangkat:</p>
<p>- Kerahasiaan data</p>
<p>- Integritas data</p>
<p>- Data otentikasi</p>
<p>- Deteksi anti-replay</p>
<p>- Peer otentikasi</p>
<p>Internet Engineering Task Force (IETF) mendefinisikan standar untuk IP Security di berbagai RFC. Karena memberikan perlindungan lapisan jaringan antar perangkat atau jaringan, dan karena itu adalah standar terbuka, itu biasa digunakan dalam jaringan saat ini yang menggunakan IPv4 dan IPv6.</p>
<p>vendor (seperti Cisco), memiliki kecenderungan untuk meningkatkan standar untuk mengatasi masalah yang dapat IP Security pengalaman di jaringan data. Cisco, misalnya, telah menambahkan banyak fitur untuk meningkatkan baik LAN ke LAN (L2L) dan sesi akses remote.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[KEAMANAN JARINGAN VPN]]></title>
<link>http://yanuangga.wordpress.com/2009/11/10/keamanan-jaringan-vpn/</link>
<pubDate>Tue, 10 Nov 2009 16:41:07 +0000</pubDate>
<dc:creator>yanuangga</dc:creator>
<guid>http://yanuangga.wordpress.com/2009/11/10/keamanan-jaringan-vpn/</guid>
<description><![CDATA[Virtual private network (VPN) berkembang pada saat perusahaan besar memperluas jaringan bisnisnya, n]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Virtual private network (VPN) berkembang pada saat perusahaan besar memperluas jaringan bisnisnya, namun mereka tetap dapat menghubungkan jaringan lokal (private) antar kantor cabang dengan perusahaan mitra kerjanya yang berada di tempat yang jauh. Perusahaan juga ingin memberikan fasilitas kepada pegawainya (yang memiliki hak akses) yang ingin terhubung ke jaringan lokal milik perusahaan di manapun mereka berada. Perusahaan tersebut perlu suatu jaringan lokal yang jangkauannya luas, tidak bisa diakses oleh sembarang orang, tetapi hanya orang yang memiliki hak akses saja yang dapat terhubung ke jaringan lokal tersebut.</p>
<p>Implementasi jaringan tersebut dapat dilakukan dengan menggunakan leased line. Namun biaya yang dibutuhkan untuk membangun infrastuktur jaringan yang luas menggunakan leased line sangat besar. Di sisi lain perusahaan ingin mengoptimalkan biaya untuk membangun jaringan mereka yang luas. Oleh karena itu VPN dapat digunakan sebagai teknologi alternatif untuk menghubungkan jaringan lokal yang luas dengan biaya yang relatif kecil, karena transmisi data teknologi VPN menggunakan media jaringan publik yang sudah ada (mis. internet).</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenVPN connected but No Surf in Ubuntu]]></title>
<link>http://jaidane.wordpress.com/2009/11/10/openvpn-connected-but-no-surf-in-ubuntu/</link>
<pubDate>Tue, 10 Nov 2009 00:26:47 +0000</pubDate>
<dc:creator>Maher</dc:creator>
<guid>http://jaidane.wordpress.com/2009/11/10/openvpn-connected-but-no-surf-in-ubuntu/</guid>
<description><![CDATA[If you&#8217;re using an OpenVPN Server to surf in Ubuntu, maybe you experienced this strange proble]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p style="text-align:left;">If you&#8217;re using an OpenVPN Server to surf in Ubuntu, maybe you experienced this strange problem : <span style="color:#ff9900;">you can connect but you cannot surf</span> <img class="alignnone size-full wp-image-161" title="icon_questiongif" src="http://jaidane.wordpress.com/files/2009/04/icon_questiongif.png" alt="icon_questiongif" width="18" height="18" /> !    <a href="http://jaidane.wordpress.com/2009/11/10/openvpn-connected-but-no-surf-in-ubuntu/#more-573"><span style="color:#ffff00;"><strong><span style="color:#fbea74;">This how to fix it..</span>.</strong></span></a></p>
<p><strong><br />
</strong></p>
<p><img class="aligncenter size-full wp-image-599" title="vpn" src="http://jaidane.wordpress.com/files/2009/11/vpn.png" alt="vpn" width="321" height="161" /></p>
<p><!--more--></p>
<p>Before we start check your current <a href="http://www.ip-adress.com/" target="_blank">IP online </a> and save it.</p>
<p>The first thing you have to know is that you shouldn&#8217;t use NetworkManager Applet to configure your OpenVPN Connexion, it seems that there&#8217;s a problem with vpn connections when using this applet (atleast with Intrepid), you can connect but traffic isn&#8217;t redirected correctly, so <span style="color:#b9f905;">let&#8217;s first make sure you&#8217;re correctly  connected</span><span style="color:#b9f905;"> !</span> The best thing to do is to download the configuration files from the OpenVPN Server&#8217;s website (just look in the forum if you don&#8217;t find it, it&#8217;s generally an archive file with a *.conf file and a *.crt file, this last one is the certificate) and use&#8217;em directly in a shell console.</p>
<p>Copy the archive content files to</p>
<p><span style="color:#f7e807;">/etc/openvpn/</span></p>
<p>Type :</p>
<p><span style="color:#f7e807;">cd /etc/openvpn &#38;&#38; sudo openvpn yourserver.conf</span></p>
<p>Enter your login and password and wait till you see :</p>
<p><span style="color:#f7e807;">Initialization Sequence Completed</span></p>
<p>It means that you&#8217;re in.</p>
<p>Now to <span style="color:#b9f905;">make sure that you&#8217;re not facing a routing problem</span>, just type :</p>
<p><span style="color:#f7e807;">route -n</span></p>
<p>If you see tunX connections with new IPs, it&#8217;s OK you&#8217;re connected, if one of your web connected peripheral connections (ethX, athX&#8230;) is showing the IP of your OpenVPN Server as a destination you&#8217;re correctly routed.</p>
<p>Now <span style="color:#b9f905;">try to ping the tunX IP with a gateway</span>, if you&#8217;ve got this message :</p>
<p><span style="color:#f7e807;">ping: sendmsg: Operation not permitted </span></p>
<p><span style="color:#ffcc00;">You got the fix ! It&#8217;s a SIMPLE FIREWALL PROBLEM</span> <img class="alignnone size-full wp-image-153" title="icon_biggringif" src="http://jaidane.wordpress.com/files/2009/04/icon_biggringif.png" alt="icon_biggringif" width="18" height="18" /><span style="color:#ffcc00;"> !</span></p>
<p>To solve it, you have to edit :</p>
<p><span style="color:#f7e807;">/etc/firestarter/user-pre</span></p>
<p>First thing to do is to make it writable (it&#8217;s a read-only file) then paste these lines and save the file :</p>
<p><span style="color:#f7e807;"># Allow OpenVPN traffic<br />
$IPT -A INPUT -i tun+ -j ACCEPT<br />
$IPT -A OUTPUT -o tun+ -j ACCEPT</span></p>
<p>Restart Firestarter :</p>
<p><span style="color:#f7e807;">sudo /etc/init.d/firestarter restart</span></p>
<p>It should work now <img class="alignnone size-full wp-image-80" title="icon_smilegif" src="http://jaidane.wordpress.com/files/2009/04/icon_smilegif.png" alt="icon_smilegif" width="18" height="18" /> ! Just re-check your <a href="http://www.ip-adress.com/" target="_blank">Online IP</a> to see if it changed !</p>
</div>]]></content:encoded>
</item>

</channel>
</rss>
