Wednesday, December 26, 2007

I'm back and Server Updates

Well, I'm back from a nice Christmas break with the family. It's nice to be back at work and away from all the endless chaos that exists around my family and my wife's family. I'd much prefer the chaos that is Microsoft Server 2003. For a year now I've adjusted my schedule to come in early to apply Microsoft security updates once a week. I document the updates that I install in a Excel spreadsheet that sits in our documentation folder on the file server. That being said, I pretty much just install every patch that comes down the pipe. I don't have the luxury of having test servers or a test network that I can run the patches on first. After a year of this, I'm wondering if the bags under my eyes are worth it. At some point this year we will probably be purchasing a IPS to guard to entrance to our server farm. We will probably go with Enterasys Dragon because of our current investment in Enterasys hardware, but I've also had great success with TippingPoint as well. Any competent IPS should have Microsoft's security holes in it's signatures so any attempt to exploit them that way would be blocked....right???. Does anyone have any suggestions for a better way to manage the large security hole that is Microsoft???
-PC

Thursday, December 13, 2007

annoyance


One of the annoying things about my job is the existence of our Domino servers and mentality that surrounds them.  Early this week, one of our servers had barfed and was not running a process that archives images for us.  When I went looking for the reasons behind the vomit, I noticed that the domino services were using an inordinate amount of memory.  My boss informed me that yes.....the versions of domino that we are running have a known memory leak.  Rather than upgrade the server software to fix the leak and any unknown security holes, the solution is to reboot the server on a regular basis.
-PC

Wednesday, December 5, 2007

Cisco finally catches up

Enterasys has had this ability for years. It will be interesting to see how Cisco leverages this. Traditional ACLs have been Cisco's (and everyone who copies them) bread and butter for a long time. With this ability, Enterasys uniqueness becomes blase

Back from the dead!!!

Wow.....it's December already. I hope everyone had a great Thanksgiving holiday. I'm just now getting back to work after a week off for vacation. One site that I watch, that has absolutely nothing to do with network administration, that I recommend is Trevor Carpenter's blog. He is running a December challenge to photograph a portrait a day through the month.

Friday, November 16, 2007

We're expanding part two

Our VPN cloud is in the process of upgrading as well. Tired of the endless torture dealing with Juniper IPSEC Windows client, I managed to convince my boss to try something different. We've been scouring Ebay picking up used Netscreen 5GTs and placing them with out remote users. Most, if not all, of our remotes are not road warriors and don't have to be able to move around. At roughly $100-150 (They retail for like $500-600)a pop if one goes bad, I don't care. I throw it away and start over. This allows me a solid IPSEC VPN back home where I feel comfortable recommending expanding the VOIP network out to them. At some point I'm going to eventually have to upgrade our edge router and when I do, I think I'll look into Cisco's SSL VPN that's built into the IOS. That will give me the flexibility for my road warriors.
I would be curious to hear what anyone else thinks of the idea and if you have a better idea

We're expanding

We are going to be adding racks to our two So. California data centers because we've run out of room in one. I'll be spreading my LAN equipment away from the WAN stuff and making some room. Our brand spanking new AS/400 (Or whatever the new model is called. That's not really my bag) is going in another. This means I have to call in our local electrical slob to run some circuits for me from the UPS. This should be interesting. The last time he showed up he was sporting a Sex Wax t-shirt and talking like a sailor.

Tuesday, November 13, 2007

Active Directory Project Update

We've just about finished with the roll-over. We have a few remote VPN users that we need to convert over and our mailroom still needs some TLC. After I roll them over, I'll will do a final archive backup of the remaining servers on the old NT domain and kill them swiftly. I still haven't decided if I want a domain controller at our remote office in Arizona. The office only has 3 people in it, but I was considering making the server a combo file server as well and backing it up.