Pages

Sunday, December 5, 2010

Photo Gallery of Aruba Airheads Conference 2010, Phuket Thailand

Aruba Airheads Conference, 1-3 December 2010, Phuket Thailand.


Dinner with Aruba's Co-founder Keerti Melkote.
Left: Me, Hitesh Sheth (COO), Keerti Melkote (CTO), Dr. Reza, Dr. Unggul
Back: Kevin Wong






Thursday, November 18, 2010

10 Best Security Apps for iPhone

Apple's App Store currently holds about 85,000 applications for you to download to your iPhone or iPod Touch. Of course, about 84,900 of those programs consist of free and 99-cent games that your seven-year-old would probably find more compelling than you do. So we've scoured reviews, App Store search sites, and recommendation directories to compile this concise list of some of the best security apps currently available.
EyeSpyFX has developed mobile applications that allow you to check surveillance cameras from Axis, Sony, D-Link, Linksys, Mobotix, and Vivotek. Each edition lets you set up a camera list and check the views for up to 100 cameras. You can also add cameras and bring up an edit screen to adjust camera details. When a camera goes offline, a status indicator will point that out. And the app will remember your passwords.
Price: $4.99 and less
Size: Under 0.5 MB

Thursday, October 28, 2010

How to manage AP Folder in AirWave

What is folder management ? Folder in layman term means something that we can represent as location or building or LAN Room where we can group our AP. In my case, I named it based on geographical location and buildings. Currently, I'm managing a nation wide wireless infrastructure. It is important to group all the APs in order to simplify all our works. It helps us to manage the reporting and also identifying which AP is currently down. 

Firstly you need to log on to your Airwave server. After you successfully login to the Airwave Management Platform server, you will see the user interface as below:


Wednesday, July 14, 2010

How to set the start-time of future user on Aruba Controller ?

Many wireless administrator looking for a solution on how to set the start-time or specifying the detail such as duration/expiry time for our future user on Aruba Controller. I never come across the solution on Airheads before. Normally, by using GUI based of Aruba controller powered with ArubaOS 3.3.1.22, we can add the user inside the internal database are as follows:
Go to Configuration tab, select Authentication under security section, and click Servers tab. Then click Internal DB.
Configuration > Authentication > Servers > Internal DB
After that, there will appear configuration windows as follows:

Monday, May 18, 2009

How to configure Ubuntu 8.10 / 9.04 for 802.1x WPA TKIP environment

IIUM wireless environment implement WPA authentication and TKIP encryption. The overall using 802.1x authentication method which deploy protected EAP (PEAP) using EAP token. User database stored in a Radius server by using FreeRadius running on FreeBSD platform. 


One of my user said, before upgrading his Ubuntu 8.10, he was using Ubuntu Hardy Heron 8.04. The previous Ubuntu is running well. Once he upgrade it to Ubuntu 8.10, he cannot get connected to our secure wireless environment anymore. 

Hmmmmm... while other user with other stardard OS e.g Windows XP, Mac OS and Windows Vista doesn't have any problem, so I suspect, the WPA configuration in Ubuntu 8.10 something need to change drastically. It seems like doesn't works well in a secured wireless environment. 

We have tried and yes, it does not work with IIUM wireless campus. I tried to switch to fedora 10, but the result is still the same. Then we tried to migrate to knoppix, my best linux distro ever, but still not working and become more worst when knoppix cannot detect Intel PRO/Wireless 3945ABG device. We dont want to use ndiswrapper since it finally could corrupt my entire OS. FYI, Suse linux will work smoothly with IIUM wireless.


Thursday, February 19, 2009

Why we need to deploy network access control (NAC) ?

The deployment plan of Network Access Control (NAC) technology in IIUM aims to protect IIUM heterogeneous wireless networks from the public back door (possibly done through 3G, bluetooth, firewire, UTP, USB etc), and often dangerous, Internet. It also provides protection from viruses and other types of malware that may be resident on the mobile gadgets that staff, students and visitors connected into IIUM wireless networks. NAC places a virtual shield around a network by guarding its endpoints, the places where heterogeneous wireless networks mesh with the outside world.
While NAC vendors take various approaches to NAC, the technology basically works by treating all endpoints with suspicion. Access to the wireless network is granted only after Aruba Wireless Controller, LDAP and NAC authenticates the user’s identity (username, password and MAC address), verifies the security state of the user’s endpoint and ensures that the user meets policies that define who should be allowed to use which resources and under what conditions (using role base idenfication offered by Aruba Controller).
A survey conducted earlier this year by Infonetics, a technology research firm located in San Jose, Calif., found that enterprises acquire NAC technology for various reasons, including blocking viruses (86 percent), intercepting external attacks (80 percent), stopping spyware/malware (73 percent) and blocking e-mail attacks (70 percent). Other motivations cited by the respondents included regulatory compliance (54 percent), adding LAN security (45 percent), blocking internal attacks (38 percent) and meeting customer and business partner demands (36 percent).
Much of NAC’s overall appeal comes from its simplicity, as well as its ability to provide enhanced security and more sanitized networks with little or no negative impact on the community productivity especially in IIUM. In fact, many instituition that have adopted NAC technology report improved productivity. By deploying this IIUM Community are now free to use devices that were formerly banned from any other enterprises networks due to security concerns. By deploying NAC, ITD is trying to secure the wireless connection even browsing via smartphone or PDA since this devices is not really have a good antivirus software.
NAC often arrives on customer premises in the form of a network appliance. This approach is appealing to many enterprises, and the solution that ITD is looking for: the appliance must simply be plugged into the wireless network, providing fast, painless, out-of-the-box security and avoid changes to the existing configuration. Many NAC appliances are multifunction security devices, offering capabilities such as network-based virus scanning and intrusion prevention systems (IPSs) along with NAC capabilities. The appliance must be capable to integrate with the existing equipments.
Non-appliance-based approaches to NAC are more complex and tend to require a bit more hands-on work. The available alternate choices are to enforce NAC with functionality that’s built into network devices, such as switches, or to enforce NAC using SSL VPN gateways.
No network is airtight—malware continues to get in, whether via mobile gadget (PDA, smartphone) of staff, student or guest laptops, or end users downloading dodgy content. Antivirus software at the gateway or on the desktop helps with computers under your control, but guests and unmanaged servers remain problematic. And let’s face it: Sometimes attackers are just smarter than we are. Even the companies following best practices get hit.
Deploying NAC don’t just mean a security best practices, either. Protecting the network from malicious hosts is, ultimately, a desktop management function. NAC is what puts teeth in our policies, providing an enforcement mechanism that helps ensure computers are properly configured. By weighing such factors as whether a user is logged in; their computer’s patch level; and if anti-malware or desktop firewall software is installed, running and current, ITD can decide whether to limit access to network resources based on condition or not. A host that doesn’t comply with your defined policy could be directed to remediation servers, or isolate it in a quarantine VLAN.
Remember Slammer? If a company could have determined that a host was running an unpatched version of MSDE 2000 and denied access until it was patched, Slammer would have had a much less dramatic effect.
After reviewing other reading materials,
NAC’s soaring popularity which has attracted numerous vendors to the market. NAC technology suppliers include such heavyweights as Bardford, Microsoft, Infoexpress, Juniper, Consentry, Cisco, Fortinet and Aruba Networks. Altogether, there are close to 50 +/- NAC vendors, large and small, meaning that enterprises have plenty of products and approaches to choose from.
With all the available choices, settling on the right NAC technology from the right vendor requires a significant amount of research. The final selection usually boils down to finding the product that most closely matches the IIUM’s NAC goals and the network’s size, complexity, budget and configuration.

Monday, December 1, 2008

IIUM Wireless : No. 1 Benchmark for Secure Wireless Depoyment in Malaysia ?

Unofficially, IIUM Wireless has become a reference model by other IPTA in Malaysia for campus wide wireless deployment. This rumours has been talked among the system integrators and vendors in Malaysia. FYI, UM has visited us for discussion and sharing experience which are related to wifi deployment. I have mentioned it  in my previous post. Click here.
IIUM has deployed a secured wireless infrastructure which is based on role-based identity authentication. IIUM is the first organization deploying this kind of authentication method in Malaysian. Thanks to Dr. Unggul for his experties and concern on wireless security issues in the beginning of design stage of wireless implementation. The facts can be obtained from this link. Click here.