<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss'><id>tag:blogger.com,1999:blog-3026473213875412241</id><updated>2009-10-16T15:21:31.646-07:00</updated><title type='text'>Securitah!</title><subtitle type='html'>Respect it.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://respectmysecuritah.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3026473213875412241/posts/default'/><link rel='alternate' type='text/html' href='http://respectmysecuritah.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>astroman</name><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>6</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3026473213875412241.post-8505908535575075944</id><published>2008-05-20T15:42:00.000-07:00</published><updated>2008-08-05T18:36:49.238-07:00</updated><title type='text'>Goals, goals, goals...</title><content type='html'>&lt;span style="color: rgb(51, 204, 0);font-size:100%;" &gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;More often than not, we consider a new security control, whether it be a firewall upgrade, host intrusion software deployment, or Identity Management solution and fail to ask ourselves:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;Why are we doing this?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;What's the goal of putting this security control in place?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;Are there any risks associated?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;What is the expected outcome?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;Is the way we're deploying this technology, the "best" that we can do? (Without impacting business efficiency of course.)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;I know it's simple in nature, but seriously, asking those questions is where the real securitah lies.&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3026473213875412241-8505908535575075944?l=respectmysecuritah.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://respectmysecuritah.blogspot.com/feeds/8505908535575075944/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=3026473213875412241&amp;postID=8505908535575075944' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3026473213875412241/posts/default/8505908535575075944'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3026473213875412241/posts/default/8505908535575075944'/><link rel='alternate' type='text/html' href='http://respectmysecuritah.blogspot.com/2008/05/goals-goals-goals.html' title='Goals, goals, goals...'/><author><name>astroman</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16460411560237356039'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3026473213875412241.post-5374265616653775533</id><published>2008-02-27T07:29:00.001-08:00</published><updated>2008-02-27T07:29:18.804-08:00</updated><title type='text'>Know your fundamentals. Period.</title><content type='html'>&lt;span xmlns=''&gt;&lt;p&gt;&lt;span style='font-size:10pt'&gt;"I want to get into a security role within IT."&lt;br/&gt;&lt;br/&gt;My advice? Know your fundamentals. Know the core of what makes the world go round in systems, software, or networking technology.&lt;br/&gt;&lt;br/&gt;Now please, don't start with the "C'mon dude, are you serious?" after reading this list. Let me esplain. No, there is too much, lemme sum up. &lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;span style='font-size:10pt'&gt;Understand DNS, in and out. It's been around since the beginning of time.&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style='font-size:10pt'&gt;Understand TCP/IP, TCP flags &amp;amp; communication, and packets (at least at a level that you can use Wireshark or tcpdump.) I'm not talking about decoding packets in hex and chewing gum at the same time.&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style='font-size:10pt'&gt;Learn how to administer and troubleshoot issues with Windows Server, and pick-your-flavor of UNIX/Linux. Start small. Think performance monitoring, network monitoring, and service monitoring tools for each platform.&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style='font-size:10pt'&gt;Understand dynamic routing and networking topology protocols. Spanning-tree and BGP can get very deep – at least know how they function, and primary causes for them to not function properly.&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style='font-size:10pt'&gt;Learn what viruses, Trojans, and rootkits are, at a high level. Know how some of the primary penetration and propagation techniques occur.&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;span style='font-size:10pt'&gt;There are a lot more. I know. But I'm more and more surprised by how many technology professionals do not understand core fundamentals like DNS. Or how to break down a TCP traffic flow between two hosts.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style='font-size:10pt'&gt;Let's not forget this fact: you'll become a stronger security professional by being a great systems/software/networking professional first.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style='font-size:10pt'&gt;Respect the securitah by knowing and applying your base skills.&lt;span style='font-family:Verdana'&gt;&lt;br /&gt;					&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3026473213875412241-5374265616653775533?l=respectmysecuritah.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://respectmysecuritah.blogspot.com/feeds/5374265616653775533/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=3026473213875412241&amp;postID=5374265616653775533' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3026473213875412241/posts/default/5374265616653775533'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3026473213875412241/posts/default/5374265616653775533'/><link rel='alternate' type='text/html' href='http://respectmysecuritah.blogspot.com/2008/02/know-your-fundamentals-period.html' title='Know your fundamentals. Period.'/><author><name>astroman</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16460411560237356039'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3026473213875412241.post-2146870674736398523</id><published>2008-02-07T05:23:00.000-08:00</published><updated>2008-12-12T00:54:19.810-08:00</updated><title type='text'>WSUS, 2/12, IE7 for all! Joy and merriment!</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_lXN1kcRPYsU/R6sK4zUNnWI/AAAAAAAAABs/k5jqZDQoyW4/s1600-h/astromangroupshot.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_lXN1kcRPYsU/R6sK4zUNnWI/AAAAAAAAABs/k5jqZDQoyW4/s320/astromangroupshot.jpg" alt="" id="BLOGGER_PHOTO_ID_5164233368674344290" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;For those that didn't see the diary posting at the &lt;a href="http://isc.sans.org/"&gt;Internet Storm Center&lt;/a&gt; yesterday/today:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=";font-family:&amp;quot;;font-size:8;"  &gt;"On February 12, 2008 Microsoft will release the Windows Internet Explorer 7 Installation and Availability update to Windows Server Update Services (WSUS). Windows Internet Explorer 7 Installation and Availability Update is a complete installation package that &lt;strong&gt;will upgrade&lt;/strong&gt; machines running Internet &lt;strong&gt;Explorer 6 to Windows Internet Explorer 7&lt;/strong&gt;. Customers who have configured WSUS to &lt;strong&gt;"auto-approve" Update Rollup&lt;/strong&gt; packages will automatically upgrade machines running Internet Explorer 6 to Windows Internet Explorer 7 after February 12, 2008 and consequently, may want to read &lt;a href="http://go.microsoft.com/?linkid=8250930"&gt;Knowledge Base article 946202&lt;/a&gt; to manage how and when this update is installed. For more on the Windows Internet Explorer 7 Installation and Availability Update, read &lt;a href="http://go.microsoft.com/?linkid=8250931"&gt;Knowledge Base article 940767&lt;/a&gt;."&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;Moral of the story:&lt;br /&gt;&lt;br /&gt;As much as Microsoft wants to extend their QA department into your corporation, don't let them. I'm not a fan of any "auto-updating" service. True, most of the time, everything will work out just peachy, you'll be patched/updated/band-aided/snug-as-a-remedied-software-bug-in-a-rug....BUT....there's always the chance that the new shiny update will PUNCH YOU IN THE FACE.&lt;br /&gt;&lt;br /&gt;So, test, test, test.&lt;br /&gt;&lt;br /&gt;And if you're screaming at me - "We don't have the money for a test environment!" - there are virtual PC/server options. And they're free. And they work.&lt;br /&gt;&lt;br /&gt;I'm pretty sure Matt Neely over at &lt;a href="http://matthewneely.blogspot.com/"&gt;Security Second Thoughts&lt;/a&gt; knows a thing or two about virtualization. And believe me, he definitely knows three or four things about mobile commerce...&lt;br /&gt;&lt;br /&gt;On another note...I'll be adding a section that shows the security blogs I like reading. I'll keep it limited to 10 - a lot of them tend to repeat what others are saying.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3026473213875412241-2146870674736398523?l=respectmysecuritah.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://respectmysecuritah.blogspot.com/feeds/2146870674736398523/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=3026473213875412241&amp;postID=2146870674736398523' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3026473213875412241/posts/default/2146870674736398523'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3026473213875412241/posts/default/2146870674736398523'/><link rel='alternate' type='text/html' href='http://respectmysecuritah.blogspot.com/2008/02/wsus-212-ie7-for-all-joy-and-merriment.html' title='WSUS, 2/12, IE7 for all! Joy and merriment!'/><author><name>astroman</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16460411560237356039'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_lXN1kcRPYsU/R6sK4zUNnWI/AAAAAAAAABs/k5jqZDQoyW4/s72-c/astromangroupshot.jpg' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3026473213875412241.post-4251470614596605510</id><published>2007-12-20T12:29:00.000-08:00</published><updated>2007-12-20T13:16:48.015-08:00</updated><title type='text'>InfoSec Policy - why not?</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: verdana;"&gt;Policy.&lt;br /&gt;&lt;br /&gt;Ugh.&lt;br /&gt;&lt;br /&gt;Most people in the IT field dread anything that relates to documenting "how" to do something related to their positions. Why should we? It's all up here (point to your forehead - i.e. the steel trap).&lt;br /&gt;&lt;br /&gt;I'll be honest. Documentation isn't my FAVORITE thing to do. But then again, neither is working, period. So why am I writing about infosec policy? Because time and time again, we come up short; whether that means our infosec policies don't exist at all, or they cover only "Acceptable Internet Use", or they're:&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: verdana;"&gt;Super long&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: verdana;"&gt;Super hard to read&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: verdana;"&gt;A super waste of paper and hard drive space&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-size:85%;"&gt;Why do we all fall short in the area of actually writing information security policy? I've got a couple opinions, and the masses can disagree with me if they want (I know you're out there).&lt;br /&gt;&lt;br /&gt;First opinion: we get lost in thoughts of the policy having to cover everything. That's like saying, "I don't want to create any laws because I want to make sure that no one commits any crime." Not possible! But wouldn't we be better off having 5 laws versus no laws? Don't murder, don't steal, don't lie, don't litter, and don't be a jerk. I would think the world would be a better place having those 5 laws versus NO laws whatsoever. Same goes with an infosec policy. You might as well get started now, because anything you outline and document is better than nothing at all.&lt;br /&gt;&lt;br /&gt;What does policy mean? "A definite course of action adopted for the sake of expediency, facility, etc."&lt;br /&gt;&lt;br /&gt;How do I define it? It's a blueprint. Plain and simple. You wouldn't build a house without a plan, right? Why would you build a holistic security strategy without a plan on what you're going to do, how you're going to do it, who will be responsible for which parts, etc. It's that simple. Seriously.&lt;br /&gt;&lt;br /&gt;But wait, here comes the second opinion. Blueprints are big. REALLY big! Not necessarily, my peoples. They're a guide. The blueprint doesn't have to be the SIZE of the actual house. Neither does your infosec policy. I was at a security seminar a few years ago, and the guy (can't remember his name) asked the audience if their companies had an information security policy. 25% of the audience raised their hand. Then he asked how big the policies were and what they covered. I'll never forget this dude from IBM raising his hand and telling everyone that their infosec policy was 5,000 pages long.&lt;br /&gt;&lt;br /&gt;C'mon, seriously. Whoever or whatever team wrote that pile of crap obviously liked to hear themselves type or were a bunch of reefer addicts. I would take that thing out into a parking lot and light it on fire, and then start over with something that someone &lt;span style="font-weight: bold;"&gt;WOULD ACTUALLY WANT TO READ&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Isn't that the point? For people to read it, understand it, and follow it's direction?&lt;br /&gt;&lt;br /&gt;So my goal, and what I was taught, is that it should be clear, concise, and written at a 7th grade reading level. I shouldn't have to bust out the dub-dub-dub dictionary.com in order to understand what I'm being held accountable for. Right? Thanks for agreeing...&lt;br /&gt;&lt;br /&gt;What is the point of this post? Start working on something now. And don't do it because HIPAA, SOX, or PCI made you. Do it because you need and want to do the best thing for the positioning of your security posture. Stop talking about it. Stop saying, "We don't have an information security policy." Start doing.&lt;br /&gt;&lt;br /&gt;A general information security policy could start by putting together a quick one or two page outline of how the organization takes security seriously, and it's goals. Then start on the sub-policies that actually define specific areas.&lt;br /&gt;&lt;br /&gt;What are sub-policies?&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-size:85%;"&gt;How do you administer changes to the firewall? Who approves the changes? Now you have a Firewall Administration policy.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-size:85%;"&gt;What can I do with my computer? Am I allowed to hack Switzerland? Now you have an Acceptable Computer Use policy.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-size:85%;"&gt;Do you have third-party organizations connecting to your WAN/LAN? How should they connect? Now you have a Third-Party Communications policy.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-size:85%;"&gt;Am I allowed to use a signature including my e-mail address, phone number, title, and address when I post to my favorite tech forum? Now you have an Information Dissemination policy.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-size:85%;"&gt;I know I'm making it sound ridiculously simple. But then again, it kinda is. It's NOT rocket science. Why? Because rocket science IS rocket science. Infosec policy writing, isn't.&lt;br /&gt;&lt;br /&gt;If we just start doing, instead of talking, we can all get through this process. We have to. Every solid security organization depends on it. I promise.&lt;br /&gt;&lt;br /&gt;Respect it.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3026473213875412241-4251470614596605510?l=respectmysecuritah.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://respectmysecuritah.blogspot.com/feeds/4251470614596605510/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=3026473213875412241&amp;postID=4251470614596605510' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3026473213875412241/posts/default/4251470614596605510'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3026473213875412241/posts/default/4251470614596605510'/><link rel='alternate' type='text/html' href='http://respectmysecuritah.blogspot.com/2007/12/infosec-policy-why-not.html' title='InfoSec Policy - why not?'/><author><name>astroman</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16460411560237356039'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3026473213875412241.post-6322919108861428565</id><published>2007-11-12T14:14:00.000-08:00</published><updated>2007-11-12T14:16:59.505-08:00</updated><title type='text'>Knoppix-NSM</title><content type='html'>Just downloaded &lt;a href="http://www.securixlive.com"&gt;Knoppix-NSM&lt;/a&gt;, a bootable Debian .iso for network security monitoring. I saw an article about it in the October issue of Information Security Magazine. Includes stuff like Snort, Sguil, BASE, etc. Very clean and trimmed down from what I've seen so far. I'm going through the HDD install right now, and will soon throw it on my home network.&lt;br /&gt;&lt;br /&gt;I'll update the masses.&lt;br /&gt;&lt;br /&gt;I know you're out there.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3026473213875412241-6322919108861428565?l=respectmysecuritah.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://respectmysecuritah.blogspot.com/feeds/6322919108861428565/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=3026473213875412241&amp;postID=6322919108861428565' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3026473213875412241/posts/default/6322919108861428565'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3026473213875412241/posts/default/6322919108861428565'/><link rel='alternate' type='text/html' href='http://respectmysecuritah.blogspot.com/2007/11/knoppix-nsm.html' title='Knoppix-NSM'/><author><name>astroman</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16460411560237356039'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3026473213875412241.post-6148803693413546553</id><published>2007-10-30T18:00:00.000-07:00</published><updated>2007-10-30T18:56:33.626-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft IAS'/><category scheme='http://www.blogger.com/atom/ns#' term='PEAP'/><category scheme='http://www.blogger.com/atom/ns#' term='wireless'/><title type='text'>Microsoft IAS &amp; PEAP. What fun...</title><content type='html'>&lt;span style="color: rgb(0, 153, 0);"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;I started deploying my first large(r) &lt;a href="http://www.microsoft.com/ias"&gt;Microsoft Internet Authentication Service&lt;/a&gt; implementation at a client a couple weeks ago, and it's been a work in progress. At first, the client was using RADIUS as a second set of authentication for their remote VPN client connections. After their wireless security was tested (and rated poorly), they decided to go with a PEAP/WPA2 auth/encryption architecture. Sounds good! Unbelievably, Microsoft has an entire certificate solution laid out for this sort of thing, with &lt;a href="http://http//www.verisign.com/ssl/buy-ssl-certificates/wireless-lan-security/index.html"&gt;Verisign&lt;/a&gt;. Stop the world!&lt;br /&gt;&lt;br /&gt;All in all, it's working out well. There's roughly 70 devices using AAA now; I have a primary IAS box, with a secondary IAS box for redundancy at the same physical site. I wish IAS config was replicated automatically, but the manual process is pretty easy. And what's with IAS proxies? WHEN DO YOU ACTUALLY NEED TO USE THEM? Are there any benchmarks to go off of?&lt;br /&gt;&lt;br /&gt;The one area I found to be challenging was the creating specific profiles with the Remote Access Policies. Getting the right attributes as "match" criteria within the policies, AND putting the policies in the correct order for application can be difficult. Lots of trial and error. Unfortunately there isn't a ton of documentation out there on the subject, especially if you want to use the same IAS box to authenticate wireless users, VPN users, and network administrators gaining access to LAN/WAN hardware.&lt;br /&gt;&lt;br /&gt;George Ou from TechRepublic posted his "Ultimate Guide to to Enterprise Wireless LAN Security" earlier this year, and there are a number of step-by-step guides on deploying PEAP using MS IAS as the RADIUS server. I don't know about you, but using the word "Ultimate" in a title of anything info/net sec related just makes me sweaty. Seriously, "Ultimate"? &lt;a href="http://www.willhackforsushi.com/"&gt;Maybe if Joshua Wright wrote it.&lt;/a&gt; Then again, "ultimate" is a strong word in our field.&lt;br /&gt;&lt;br /&gt;PEAP w/ MS-CHAPv2. Secure? Sure. Most secure? Obviously not. But, if a weak password policy was a problem before implementing a wireless PEAP auth strategy, it'll always be a problem.&lt;br /&gt;&lt;br /&gt;So there you go. My first post. Don't hate! Respect it.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3026473213875412241-6148803693413546553?l=respectmysecuritah.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://respectmysecuritah.blogspot.com/feeds/6148803693413546553/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=3026473213875412241&amp;postID=6148803693413546553' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3026473213875412241/posts/default/6148803693413546553'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3026473213875412241/posts/default/6148803693413546553'/><link rel='alternate' type='text/html' href='http://respectmysecuritah.blogspot.com/2007/10/microsoft-ias-peap-what-fun.html' title='Microsoft IAS &amp; PEAP. What fun...'/><author><name>astroman</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16460411560237356039'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry></feed>