<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>security notes from the field</title>
	<atom:link href="http://fieldtech.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://fieldtech.wordpress.com</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Sat, 13 Dec 2008 19:21:31 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='fieldtech.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/11adad3ab03c806a2428de41994e8631?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>security notes from the field</title>
		<link>http://fieldtech.wordpress.com</link>
	</image>
			<item>
		<title>PacketShaper and Proxies : together</title>
		<link>http://fieldtech.wordpress.com/2008/12/13/packetshaper-and-proxies-together/</link>
		<comments>http://fieldtech.wordpress.com/2008/12/13/packetshaper-and-proxies-together/#comments</comments>
		<pubDate>Sat, 13 Dec 2008 19:12:30 +0000</pubDate>
		<dc:creator>Tech in Field</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://fieldtech.wordpress.com/?p=14</guid>
		<description><![CDATA[Are you wondering where you should put your Blue Coat [Packeteer] PacketShaper and your in-line proxy / cache in your network?
The PacketShaper should be as close to the router (or firewall) as possible.  The proxy or cache (if it sits in-line) should sit on the LAN side of the PacketShaper.
INTERNET &#60;-&#62; ROUTER &#60;-&#62; FIREWALL [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fieldtech.wordpress.com&blog=3378139&post=14&subd=fieldtech&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Are you wondering where you should put your Blue Coat [Packeteer] PacketShaper and your in-line proxy / cache in your network?</p>
<p>The PacketShaper should be as close to the router (or firewall) as possible.  The proxy or cache (if it sits in-line) should sit on the LAN side of the PacketShaper.</p>
<p>INTERNET &lt;-&gt; ROUTER &lt;-&gt; FIREWALL &lt;-&gt; PACKETSHAPER &lt;-&gt; WEB CACHE/PROXY &lt;-&gt; LAN</p>
<p>Can the Shaper and Cache deployment be reversed?  Yes, but you will be shaping requests made to the cache.  There can be some advantages to this deployment if you are attempting to shape individual connections to the web.</p>
<p>I prefer the cache inside and to see all web connections originating from the proxy.</p>
<p>If your web cache/proxy [Blue Coat, Barracuda, Ironport, etc] supports WCCP v2, you can use your PacketShaper to hand off all port 80 requests to your web filter.   In this setup, you usually do not need your web proxy in-line any more.</p>
<p>For this article I use the terms web cache, web proxy and web filter interchangably &#8212; if you are using  a good one it is all of those things.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fieldtech.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fieldtech.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fieldtech.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fieldtech.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fieldtech.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fieldtech.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fieldtech.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fieldtech.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fieldtech.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fieldtech.wordpress.com/14/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fieldtech.wordpress.com&blog=3378139&post=14&subd=fieldtech&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://fieldtech.wordpress.com/2008/12/13/packetshaper-and-proxies-together/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9f3f7a2b888cd8fb2169686956ce118f?s=96&#38;d=identicon" medium="image">
			<media:title type="html">Tech in Field</media:title>
		</media:content>
	</item>
		<item>
		<title>WCCP update on Cisco ASA</title>
		<link>http://fieldtech.wordpress.com/2008/11/11/wccp-update-on-cisco-asa/</link>
		<comments>http://fieldtech.wordpress.com/2008/11/11/wccp-update-on-cisco-asa/#comments</comments>
		<pubDate>Tue, 11 Nov 2008 20:32:57 +0000</pubDate>
		<dc:creator>Tech in Field</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://fieldtech.wordpress.com/?p=10</guid>
		<description><![CDATA[I have decided to repost an update to my WCCP config for ASA&#8217;s.  This example here will reroute only subnet 192.168.1.0/24 to the web cache.
#setup first access list to define the wccp server
#we will call this ACL &#8220;wccpserver&#8221;
#
access-list wccpserver extended permit ip host 192.168.42.42 any
#setup access list to define the subnets to be redirected and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fieldtech.wordpress.com&blog=3378139&post=10&subd=fieldtech&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p class="MsoPlainText">I have decided to repost an update to my WCCP config for ASA&#8217;s.  This example here will reroute only subnet 192.168.1.0/24 to the web cache.</p>
<p class="MsoPlainText">#setup first access list to define the wccp server<br />
#we will call this ACL &#8220;wccpserver&#8221;<br />
#<br />
access-list wccpserver extended permit ip host 192.168.42.42 any</p>
<p class="MsoPlainText">#setup access list to define the subnets to be redirected and filtered <br />
#for this example we will call the access list &#8220;filter&#8221; and only define<br />
#the subnet 192.168.1.0/24<br />
#<br />
access-list filter permit ip 192.168.1.0 0.255.255.255 any</p>
<p class="MsoPlainText">access-list filter deny ip any any</p>
<p class="MsoPlainText"> </p>
<p class="MsoPlainText"># Setup wccp v2 with no passwords, redirecting the &#8220;filter&#8221; ACL<br />
#to the wccp server defined in the ACL &#8220;wccpserver&#8221;.<br />
#<br />
wccp web-cache redirect-list filter group-list wccpserver<br />
wccp interface inside web-cache redirect in</p>
<p class="MsoPlainText"> </p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fieldtech.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fieldtech.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fieldtech.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fieldtech.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fieldtech.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fieldtech.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fieldtech.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fieldtech.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fieldtech.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fieldtech.wordpress.com/10/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fieldtech.wordpress.com&blog=3378139&post=10&subd=fieldtech&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://fieldtech.wordpress.com/2008/11/11/wccp-update-on-cisco-asa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9f3f7a2b888cd8fb2169686956ce118f?s=96&#38;d=identicon" medium="image">
			<media:title type="html">Tech in Field</media:title>
		</media:content>
	</item>
		<item>
		<title>NTFS and Unix Last Access Times</title>
		<link>http://fieldtech.wordpress.com/2008/09/06/ntfs-and-unix-last-access-times/</link>
		<comments>http://fieldtech.wordpress.com/2008/09/06/ntfs-and-unix-last-access-times/#comments</comments>
		<pubDate>Sat, 06 Sep 2008 22:54:11 +0000</pubDate>
		<dc:creator>Tech in Field</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://fieldtech.wordpress.com/?p=6</guid>
		<description><![CDATA[Disabling the attribute for Last Access Times is not a good idea for security or auditing.  But if you need to squeeze more performance out of a system, this is a way to do it.
http://technet.microsoft.com/en-us/library/cc758569.aspx
http://unixfoo.blogspot.com/2007/12/filesystem-noatime.html
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fieldtech.wordpress.com&blog=3378139&post=6&subd=fieldtech&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Disabling the attribute for Last Access Times is not a good idea for security or auditing.  But if you need to squeeze more performance out of a system, this is a way to do it.</p>
<p>http://technet.microsoft.com/en-us/library/cc758569.aspx</p>
<p>http://unixfoo.blogspot.com/2007/12/filesystem-noatime.html</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/fieldtech.wordpress.com/6/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/fieldtech.wordpress.com/6/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fieldtech.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fieldtech.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fieldtech.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fieldtech.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fieldtech.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fieldtech.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fieldtech.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fieldtech.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fieldtech.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fieldtech.wordpress.com/6/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fieldtech.wordpress.com&blog=3378139&post=6&subd=fieldtech&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://fieldtech.wordpress.com/2008/09/06/ntfs-and-unix-last-access-times/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9f3f7a2b888cd8fb2169686956ce118f?s=96&#38;d=identicon" medium="image">
			<media:title type="html">Tech in Field</media:title>
		</media:content>
	</item>
		<item>
		<title>How to setup WCCP on a Cisco ASA Firewall in 3 commands</title>
		<link>http://fieldtech.wordpress.com/2008/04/04/4/</link>
		<comments>http://fieldtech.wordpress.com/2008/04/04/4/#comments</comments>
		<pubDate>Fri, 04 Apr 2008 17:00:48 +0000</pubDate>
		<dc:creator>Tech in Field</dc:creator>
				<category><![CDATA[wccp]]></category>
		<category><![CDATA[webfilter]]></category>
		<category><![CDATA[wccp webfilter asa cisco]]></category>

		<guid isPermaLink="false">http://fieldtech.wordpress.com/2008/04/04/4/</guid>
		<description><![CDATA[########
# Setup WCCP version 2 on Cisco ASA firewall to a Web Filter (192.168.42.42)
#
#
# Create Access List called &#8220;wccpserver&#8221; for Web Filter
#
access-list wccpserver extended permit ip host 192.168.42.42 any
#
# Setup wccp v2 with no passwords,
# assumes all web traffic hitting internal interface will be rerouted
#
wccp web-cache group-list wccpserver
wccp interface inside web-cache redirect in
#
#########
And done. There [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fieldtech.wordpress.com&blog=3378139&post=4&subd=fieldtech&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>########<br />
# Setup WCCP version 2 on Cisco ASA firewall to a Web Filter (192.168.42.42)<br />
#<br />
#<br />
# Create Access List called &#8220;wccpserver&#8221; for Web Filter<br />
#<br />
access-list wccpserver extended permit ip host 192.168.42.42 any</p>
<p>#<br />
# Setup wccp v2 with no passwords,<br />
# assumes all web traffic hitting internal interface will be rerouted<br />
#<br />
wccp web-cache group-list wccpserver<br />
wccp interface inside web-cache redirect in<br />
#<br />
#########</p>
<p>And done. There are more WCCP option, but this should get you started.</p>
<p>Cisco&#8217;s documentation on WCCP (that fails to explain access lists) can be found here:  <a href="http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/dhcp.html#wp1094445" target="_blank">http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/dhcp.html#wp1094445</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/fieldtech.wordpress.com/4/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/fieldtech.wordpress.com/4/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fieldtech.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fieldtech.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fieldtech.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fieldtech.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fieldtech.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fieldtech.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fieldtech.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fieldtech.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fieldtech.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fieldtech.wordpress.com/4/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fieldtech.wordpress.com&blog=3378139&post=4&subd=fieldtech&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://fieldtech.wordpress.com/2008/04/04/4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9f3f7a2b888cd8fb2169686956ce118f?s=96&#38;d=identicon" medium="image">
			<media:title type="html">Tech in Field</media:title>
		</media:content>
	</item>
		<item>
		<title>New blog</title>
		<link>http://fieldtech.wordpress.com/2008/04/04/hello-world/</link>
		<comments>http://fieldtech.wordpress.com/2008/04/04/hello-world/#comments</comments>
		<pubDate>Fri, 04 Apr 2008 16:02:34 +0000</pubDate>
		<dc:creator>Tech in Field</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I am a security tech in the field.  I install firewalls, anti-spam, anti-virus, web content filtering any many other products.  I also like to tinker with my Linux and BSD servers.  The Internet is chock full of information, too bad a lot of it is not what I&#8217;m looking for.  I hope some of the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fieldtech.wordpress.com&blog=3378139&post=1&subd=fieldtech&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I am a security tech in the field.  I install firewalls, anti-spam, anti-virus, web content filtering any many other products.  I also like to tinker with my Linux and BSD servers.  The Internet is chock full of information, too bad a lot of it is not what I&#8217;m looking for.  I hope some of the information I post helps somebody along the way.  Comments, thank yous and corrections are greatly appreciated.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/fieldtech.wordpress.com/1/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/fieldtech.wordpress.com/1/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fieldtech.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fieldtech.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fieldtech.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fieldtech.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fieldtech.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fieldtech.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fieldtech.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fieldtech.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fieldtech.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fieldtech.wordpress.com/1/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fieldtech.wordpress.com&blog=3378139&post=1&subd=fieldtech&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://fieldtech.wordpress.com/2008/04/04/hello-world/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9f3f7a2b888cd8fb2169686956ce118f?s=96&#38;d=identicon" medium="image">
			<media:title type="html">Tech in Field</media:title>
		</media:content>
	</item>
	</channel>
</rss>