<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>network Archives -</title>
	<atom:link href="https://zymitry.com/tag/network/feed/" rel="self" type="application/rss+xml" />
	<link>https://zymitry.com/tag/network/</link>
	<description>Tech &#38; Other Stuff</description>
	<lastBuildDate>Sat, 28 Mar 2026 03:14:08 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.3</generator>

<image>
	<url>https://i0.wp.com/zymitry.com/wp-content/uploads/2016/11/favicon.png?fit=32%2C32&#038;ssl=1</url>
	<title>network Archives -</title>
	<link>https://zymitry.com/tag/network/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">120106411</site>	<item>
		<title>Fast Ethernet Specification &#8211; IEEE 802.3u</title>
		<link>https://zymitry.com/fast-ethernet-specification-ieee-8023u/</link>
					<comments>https://zymitry.com/fast-ethernet-specification-ieee-8023u/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Fri, 02 Feb 2018 00:30:31 +0000</pubDate>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[802.3u]]></category>
		<category><![CDATA[ethernet]]></category>
		<category><![CDATA[fast]]></category>
		<category><![CDATA[IEEE]]></category>
		<category><![CDATA[LAN]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[specification]]></category>
		<category><![CDATA[standard]]></category>
		<guid isPermaLink="false">https://zymitry.com/?p=995</guid>

					<description><![CDATA[<p>Fast Ethernet Specification &#8211; IEEE 802.3u 802.3, commonly known as Ethernet for Local Arena Network (LAN) operation, is a specification for speeds ranging from 1Mb/s to 100 Gb’s / sec using common Media Access Control specifications. IEEE 802.3u Fast Ethernet in the form of 100Base-T is one of the most widely used forms of Ethernet.… <span class="read-more"><a href="https://zymitry.com/fast-ethernet-specification-ieee-8023u/">Read More: Fast Ethernet Specification &#8211; IEEE 802.3u &#187;</a></span></p>
<p>The post <a href="https://zymitry.com/fast-ethernet-specification-ieee-8023u/">Fast Ethernet Specification &#8211; IEEE 802.3u</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Fast Ethernet Specification &#8211; IEEE 802.3u</p>
<p>802.3, commonly known as Ethernet for Local Arena Network (<a href="https://zymitry.com/security-terms-acronyms/" target="_blank" rel="noopener noreferrer">LAN</a>) operation, is a specification for speeds ranging from 1Mb/s to 100 Gb’s / sec using common Media Access Control specifications.</p>
<p>IEEE 802.3u Fast Ethernet in the form of 100Base-T is one of the most widely used forms of Ethernet. It is often considered universal for LAN applications because of its ease of use, and because systems can sense whether 10Base-T or 100Base-T speeds are being used. Additionally, 100Base-T systems can be mixed with existing 10Base-T equipment. 100BaseT Ethernet is defined under the 802.3 family of standards under 802.3u. In a 100BaseT network, all nodes within share the 100Mbps bandwidth. The designation for 100Base-T is derived from standard format for Ethernet connections with the first figure being the designation for the speed in Mbps. The base indicates the baseband the system operates at, and the letters indicate the cable or transfer medium. Cabling versions include the following:</p>
<ul>
<li>100Base-TX: Two pairs of Category (CAT) 5 UTP</li>
<li>100Base-T4: Four pairs of CAT 3 (now obsolete)</li>
<li>100Base-T2: Two pairs of CAT 3 (now obsolete)</li>
<li>100Base-FX: Uses two strands of multi-mode optical fibre for receive and transmit. Primarily intended for backbone use.</li>
<li>100Base-SX: Uses two strands of multi-mode optical fibre for receive and transmit. It is a lower cost alternative to using 100Base-FX.</li>
<li>100Base-BX: A version of Fast Ethernet over a single strand of optical fibre. Single-mode fibre is used, along with a special multiplexer which splits the signal into transmit and receive wavelengths.</li>
</ul>
<p>The theoretical maximum data bit rate of the system is 100 Mbps though the actual transfer rate is less than the theoretical maximum in real networks. This is attributed to the additional data in the form of the header and trailer addressing, error-detection bits on packets, and occasional corrupted packets which needs to be re-sent. Additionally, time is lost time waiting after each sent packet for other devices on the network to finish transmitting.</p>
<p>Fast Ethernet can be transmitted over many types of medium, but the most common medium is CAT 5 cable. CAT 5 has four sets of twisted wires. With 10Base-T and 100Base-T, one pair of wires is used for transmission and another for received data. Data is carried differentially over wires where the &#8220;+&#8221; and &#8220;-&#8221; wires carry opposite signals as a method to cancel out radiation.</p>
<p>&nbsp;</p>
<p>References</p>
<p>IEEE Standards Association. (2015). <em>802.3 – 2015 – IEEE Standard for Ethernet. </em>Retrieved July 27, 2017, from <a href="https://web.archive.org/web/20180317042501/http://standards.ieee.org:80/findstds/standard/802.3-2015.html" target="_blank" rel="noopener noreferrer">https://standards.ieee.org/findstds/standard/802.3-2015.html</a>.</p>
<p>Radio Electronics. (n.d.). <em>100 Mbps Ethernet / IEEE 802.3u including 100 Base-T.</em> Retrieved July 27, 2017, from http://www.radio-electronics.com/info/telecommunications_networks/ethernet/100-mbps-ieee-802-3u-base-t.php.</p>
<p>&nbsp;</p>
<p><a href="https://zymitry.com/zymitry-disclaimer/" target="_blank" rel="noopener noreferrer">Disclaimer</a></p>
<p>The post <a href="https://zymitry.com/fast-ethernet-specification-ieee-8023u/">Fast Ethernet Specification &#8211; IEEE 802.3u</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/fast-ethernet-specification-ieee-8023u/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">995</post-id>	</item>
		<item>
		<title>Compression of Network Data and Performance Issues</title>
		<link>https://zymitry.com/network-data-compression-performance/</link>
					<comments>https://zymitry.com/network-data-compression-performance/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Thu, 01 Feb 2018 00:56:24 +0000</pubDate>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[algorithm]]></category>
		<category><![CDATA[bandwidth]]></category>
		<category><![CDATA[compression]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[performance]]></category>
		<guid isPermaLink="false">https://zymitry.com/?p=986</guid>

					<description><![CDATA[<p>Network-Compression. Today&#8217;s networks will always have data limitations. Data sets continue to grow on pace with increasing bandwidth availability making network-compression an important service in improving network performance. The network-compression used is actually a combination of compression and caching. It has been found that TCP rate control combined with network-compression provides the best value in… <span class="read-more"><a href="https://zymitry.com/network-data-compression-performance/">Read More: Compression of Network Data and Performance Issues &#187;</a></span></p>
<p>The post <a href="https://zymitry.com/network-data-compression-performance/">Compression of Network Data and Performance Issues</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span style="text-decoration: underline;">Network-Compression.</span></p>
<p>Today&#8217;s networks will always have data limitations. Data sets continue to grow on pace with increasing bandwidth availability making network-compression an important service in improving network performance. The network-compression used is actually a combination of compression and caching. It has been found that TCP rate control combined with network-compression provides the best value in terms of optimizing networks.</p>
<p>Compression reduces the size of data frames transmitted over networks. Reducing frame size results in frames taking up less bandwidth allowing greater volumes of network traffic. Data compression is normally classified as Hardware or Software compression&#8217;s. Software compression can be further broken down into two types, CPU-intensive or Memory-intensive.</p>
<p><span style="text-decoration: underline;">Stacker compression</span> is based on the Lempel-Ziv algorithm and uses an encoded dictionary that replaces a continuous stream of characters with codes. This scheme is known for its flexibility, particularly in regards to Local Area Network (LAN) data since many different applications might be transmitting over the network at any given time. The dictionary approach can change to accommodate and adapt to traffic variables.</p>
<p><span style="text-decoration: underline;">Predictor compression</span> attempts to predict the next sequence of characters in a data stream using an index to lookup the compression sequence. By examining the next sequence, it can see if it matches the index. If so, the sequence replaces the looked-up sequence in the dictionary. If there is no match, the algorithm locates the next character sequence in the index and the process begins again. The Predictor compression ratio is not as good as other algorithms, but it remains one of the fastest algorithms available. Predictor is more memory-intensive and less CPU-intensive.</p>
<p>Additionally, there are also proprietary compression&#8217;s such as Cisco IOS software and Cisco hardware compression&#8217;s. Cisco IOS software supports several third-party algorithms, including Hi/fn Stac Limpel Zif Stac (LZS), Predictor, and Microsoft Point-to-Point Compression (MPPC). Compression can be used on the entire-packet, header-only, or on a payload-only basis. Cisco hardware compression is specifically designed for receiving multiple compression streams coming from remote Cisco routers using Cisco IOS software-based compression. The combination of IOS and hardware compression is designed to improve overall network performance.</p>
<p>In summary, compression overall improves network transmission efficiency, but much of the overall efficiency relies on other parts of the network. Slow, or problem hardware or devices anywhere in the network can still cause bottlenecks that will decrease performance of a network. Additionally, network device and software performance is dependent on computing resources available, namely sufficient memory and CPU resources. If a device or software performing compression/decompression does not have sufficient computing power it results in bottlenecks that degrade the overall performance of the network.</p>
<p>&nbsp;</p>
<p>References</p>
<p>Cisco Understanding Data Compression. (2008, January 15). Understanding Data Compression. Retrieved July 20, 2017, from http://www.cisco.com/c/en/us/support/docs/wan/data-compression/14156-compress-overview.html.</p>
<p>Withers, S. (2005, February 10). <em>10 ways to improve network performance.</em> Retrieved July 20, 2017, from <a href="http://www.zdnet.com/article/10-ways-to-improve-network-performance/">http://www.zdnet.com/article/10-ways-to-improve-network-performance/</a>.</p>
<p>&nbsp;</p>
<p><a href="https://zymitry.com/zymitry-disclaimer/" target="_blank" rel="noopener">Disclaimer</a></p>
<p>&nbsp;</p>
<p>The post <a href="https://zymitry.com/network-data-compression-performance/">Compression of Network Data and Performance Issues</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/network-data-compression-performance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">986</post-id>	</item>
		<item>
		<title>Virtual Private Network (VPN) Security and Monitoring Controls</title>
		<link>https://zymitry.com/vpn-security-monitoring-controls/</link>
					<comments>https://zymitry.com/vpn-security-monitoring-controls/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Thu, 25 Jan 2018 01:33:24 +0000</pubDate>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[controls]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[monitoring]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[private]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://zymitry.com/?p=909</guid>

					<description><![CDATA[<p>A Virtual Private Network (VPN) is a group of network hosts that can transfer encrypted data between themselves on a Virtual Private Network. The technology creates a safe encrypted connection, usually over public networks such as the internet, that allows remote users and locations such as branch offices, to securely access and share resources. The… <span class="read-more"><a href="https://zymitry.com/vpn-security-monitoring-controls/">Read More: Virtual Private Network (VPN) Security and Monitoring Controls &#187;</a></span></p>
<p>The post <a href="https://zymitry.com/vpn-security-monitoring-controls/">Virtual Private Network (VPN) Security and Monitoring Controls</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>A Virtual Private Network (VPN) is a group of network hosts that can transfer encrypted data between themselves on a Virtual Private Network. The technology creates a safe encrypted connection, usually over public networks such as the internet, that allows remote users and locations such as branch offices, to securely access and share resources. The main benefit is providing an adequate level of security and encryption to safely transmit private data across unprotected networks. Even though modern Virtual Private Networks use advanced encryption to protect data, additional controls should be utilized to protect them from vulnerabilities that might be introduced through other system componoents and configuration weaknesses.</p>
<p>The following is a list of recommended Virtual Private Network monitoring and security controls:</p>
<ul>
<li>Use firewalls and Intrusion Detection/Prevention Systems <a href="https://zymitry.com/ids-idps-detection-methods/" target="_blank" rel="noopener noreferrer">(IDS/IDPS)</a> in order to <a href="https://zymitry.com/active-passive-network-monitoring-basics/" target="_blank" rel="noopener noreferrer">monitor</a> VPN connections.</li>
<li>Use anti-malware and personal firewalls on remote clients and servers.</li>
<li>All VPN connections require authentication.</li>
<li>Logging enabled and auditing performed on a regular basis in order to detect possible attacks.</li>
<li>Establish user and administrator security training requirements.</li>
<li>VPN&#8217;s placed within a Demilitarized Zone (<a href="https://zymitry.com/security-terms-acronyms/" target="_blank" rel="noopener noreferrer">DMZ</a>) to isolate them from internal protected networks.</li>
<li>Split tunneling to allow local internet access on remote hosts should be prohibited.</li>
<li>Use strong authentication mechanisms to include certificates, smart cards, or tokens.</li>
<li>Access privileges granted on as-needed basis.</li>
<li>Use strong alternative authentication mechanisms such as Terminal Access Controller Access Control System (TACACS), and Remote Authentication Dial-In User Service (RADIUS).</li>
<li>Remote access computers physically secure.</li>
<li>Use strong industry proven encryption with sufficient key strength to protect confidentiality.</li>
</ul>
<p>It is important to note that even though Virtual Private Networks provide secure communications over insecure networks, client-side security must also be addressed in order to ensure end-to-end security.</p>
<p>&nbsp;</p>
<p>References</p>
<p>HKSAR-The Government of the Hong Kong Special Administrative Region. (2008, February). <em>VPN Security.</em> Retrieved September 20, 2017, from https://www.infosec.gov.hk/english/technical/files/vpn.pdf.</p>
<p>Oracle Docs. Defining a VPN. <a href="https://docs.oracle.com/cd/E19047-01/sunscreen32/806-6347/6jfa0g87q/index.html" target="_blank" rel="noopener noreferrer">https://docs.oracle.com/cd/E19047-01/sunscreen32/806-6347/6jfa0g87q/index.html</a>.</p>
<p>Tech Target. Virtual Private Network. <a href="https://web.archive.org/web/20210903022620/https://searchnetworking.techtarget.com/definition/virtual-private-network" target="_blank" rel="noopener noreferrer">http://searchnetworking.techtarget.com/definition/virtual-private-network</a>.</p>
<p>The post <a href="https://zymitry.com/vpn-security-monitoring-controls/">Virtual Private Network (VPN) Security and Monitoring Controls</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/vpn-security-monitoring-controls/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">909</post-id>	</item>
		<item>
		<title>Routing Protocols. RIP, EIGRP, OSPF, IS-IS</title>
		<link>https://zymitry.com/routing-protocols/</link>
					<comments>https://zymitry.com/routing-protocols/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Mon, 03 Apr 2017 20:05:13 +0000</pubDate>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[EIGRP]]></category>
		<category><![CDATA[IS-IS]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[OSPF]]></category>
		<category><![CDATA[protocols]]></category>
		<category><![CDATA[RIP]]></category>
		<category><![CDATA[routing]]></category>
		<guid isPermaLink="false">http://zymitry.com/?p=484</guid>

					<description><![CDATA[<p>Routing protocols are used to establish a path between routers. The most common routing protocols used are: Routing Information Protocol (RIP), Enhanced Interior Gateway Routing Protocol (EIGRP), Open Shortest Path First (OSPF), and Intermediate System to Intermediate System (IS-IS). Which protocol to use with a Local Area Network (LAN) depends on the following Factors: Administrative cost… <span class="read-more"><a href="https://zymitry.com/routing-protocols/">Read More: Routing Protocols. RIP, EIGRP, OSPF, IS-IS &#187;</a></span></p>
<p>The post <a href="https://zymitry.com/routing-protocols/">Routing Protocols. RIP, EIGRP, OSPF, IS-IS</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Routing protocols are used to establish a path between routers. The most common routing protocols used are: <strong>Routing Information Protocol (RIP)</strong>, <strong>Enhanced Interior Gateway Routing Protocol (EIGRP)</strong>, <strong>Open Shortest Path First (OSPF)</strong>, and <strong>Intermediate System to Intermediate System (IS-IS)</strong>. Which protocol to use with a Local Area Network (LAN) depends on the following Factors:</p>
<ul>
<li>Administrative cost of management.</li>
<li>Administrative cost of management.</li>
<li>Bandwidth usage for both baseline and during networks events.</li>
<li>Frequency of network failures.</li>
<li>Network recover time.</li>
<li>Convergence time.</li>
<li>Network topology.</li>
</ul>
<p>The protocol used usually involves a trade-off between these factors, gaining one of these factors often means accepting deficiencies in others. Topology of a network is important because it affects convergence times of different protocols. Network topology is a primary consideration when selecting a routing protocol (Weaver et al., 2012).</p>
<p>There  are  two  versions  of  <strong>RIP</strong>.  RIPv1  uses  classful  routing  and  does  not  include subnet  information  while sending  out routing table  updates.  RIPv2  is  classless and  includes subnet  information  supporting Classless Inter Domain Routing (CIDR). RIPv2 multicasts routing updates to other adjacent routers using the address 224.0.0.9. Network convergence happens much faster in RIPv2. <strong>RIP</strong> has the following advantages in small networks, It is easy to understand, it is easy to configure, and it is widely used and is supported  by almost all routers. The primary disadvantage of <strong>RIP</strong> is that it is limited to 15 hops. Any router beyond that distance is unreachable making it unsuitable for large networks. RIP can create a traffic bottleneck by  multicasting  all  the  routing tables every 30 seconds which is bandwidth intensive. <strong> RIP </strong> has  very slow network convergence in large networks. Additionally,  <strong>RIP</strong> doesn’t support multiple paths on the same route resulting in a higher chance of routing loops causing a higher loss of transferred data (Solarwinds Routing Protocols, 2014, pg. 4-5).</p>
<p><strong>EIGRP</strong> is a distance vector routing protocol that exchanges routing table information with  neighboring routers in an autonomous system.  Unlike RIP,  <strong>EIGRP</strong> shares routing table  information that  is not available in neighboring routers which reduces  traffic transmitted through routers. <strong>EIGRP</strong> uses a Diffusing  Update  Algorithm (DUAL) which reduces the time  taken for network convergence thereby improving operational efficiency. <strong>EIGRP</strong> was a proprietary protocol from Cisco that was made an open standard in 2013. The primary advantages of <strong>EIGRP</strong> is fast network convergence, low CPU utilization, and easy configuration. <strong>EIGRP</strong>  has more adaptability and versatility in large complex networks. <strong>EIGRP</strong> combines many features of both link state and distance vector. Since <strong>EIGRP</strong> is mostly deployed in large  networks, routers have a tendency to delay sending routing information at scheduled times  which can cause neighboring routers to query the information repeatedly increasing network traffic (Solarwinds Routing Protocols, 2014, pg. 5-7).</p>
<p><strong>OSPF</strong> is a link state routing protocol used in large Autonomous System (AS) networks. <strong>OSPF</strong> gathers link state information from available routers and determines the routing table information to forward packets to based on the destination IP address. This is done by the router when it creates a topology map of the network. Any change in the link is immediately detected and the information is forwarded to all other routers ensuring that all the network routers have same routing table information. Unlike RIP, OSPF only multicasts routing information when there is a change in the network. <strong>OSPF</strong> has a complete knowledge of the network topology which allows routers to calculate routes based on incoming requests. Additionally, <strong>OSPF</strong> has no limitations in hop count, has faster convergence than RIP, and  does a better job of load balancing. The primary disadvantage of <strong>OSPF</strong> is that it does not scale well if more routers are added to a  network. This is due to the router maintaining multiple copies of  routing information. An <strong>OSPF</strong> network with intermittent links can increase traffic every time a router sends information. This lack of scalability in <strong>OSPF</strong> makes it unsuitable for routing across the Internet (Solarwinds Routing Protocols, 2014, pg. 3-4 ).</p>
<p><strong>IS-IS</strong> was originally devised as a routing protocol for CLNP, but has been extended to include IP routing.  <strong>IS-IS</strong> is an Interior Gateway Protocol (IGP) used on the Internet to distribute IP routing information throughout a single AS in an IP network. <strong>IS-IS</strong> is a link-state routing protocol meaning routers exchange topology information with their nearest neighbors. The topology information is distributed throughout the AS so that every router within the AS has a complete picture of the topology of the AS. This is then used to calculate end-to-end paths through the AS usually using a variant of the Dijkstra algorithm. The main advantage of a link state routing protocol is that the complete knowledge of topology  which allows routers to calculate the best route in an AS. The primary disadvantage of IT-IT like other link state protocols is that it does not scale well as more routers are added to the routing domain. Increasing the number of routers increases the size and frequency of the topology updates (<a href="https://web.archive.org/web/20171107014229/https://www.metaswitch.com/resources/what-is-intermediate-system-to-intermediate-system-isis" target="_blank" rel="noopener">Metaswitch IS-IS, n.d</a>.).</p>
<p>References</p>
<p>Metaswitch IS-IS. (n.d.). <em>What is Intermediate System &#8211; Intermediate System (IS-IS)?</em> Retrieved March 16, 2017, from <a href="https://web.archive.org/web/20171107014229/https://www.metaswitch.com/resources/what-is-intermediate-system-to-intermediate-system-isis" target="_blank" rel="noopener">http://www.metaswitch.com/resources/what-is-intermediate-system-to-intermediate-system-isis</a>.</p>
<p>Solarwinds Routing Protocols. (2014). <em>Network Routing Protocols – Back to Basics</em>. Retrieved March 16, 2017, from http://web.swcdn.net/creative/pdf/Whitepapers/Network_Routing_Protocols_Back_to_Basics_SS.pdf.</p>
<p>Weaver, R., Weaver, D., Farwood, D., &amp; Weaver, R. (2012). <em>Guide to Network Defense and Countermeasures (3rd ed.). </em>Boston, MA: Course Technology, Cengage Learning.</p>
<p>The post <a href="https://zymitry.com/routing-protocols/">Routing Protocols. RIP, EIGRP, OSPF, IS-IS</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/routing-protocols/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">484</post-id>	</item>
		<item>
		<title>Bastion Host Overview</title>
		<link>https://zymitry.com/bastion-host/</link>
					<comments>https://zymitry.com/bastion-host/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Mon, 03 Apr 2017 18:52:41 +0000</pubDate>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[bastion]]></category>
		<category><![CDATA[host]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://zymitry.com/?p=476</guid>

					<description><![CDATA[<p>A Bastion Host (BH) is a computer on a network perimeter which is running a hardened Operating System (OS). This protection includes patches, authentication, encryption, and eliminates unnecessary software and services  (Weaver, Weaver, Farwood, &#38; Weaver, 2012). Weaver et al.’s (2012) provides the following list of BH characteristics: A machine with adequate memory and processor… <span class="read-more"><a href="https://zymitry.com/bastion-host/">Read More: Bastion Host Overview &#187;</a></span></p>
<p>The post <a href="https://zymitry.com/bastion-host/">Bastion Host Overview</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>A Bastion Host (BH) is a computer on a network perimeter which is running a hardened Operating System (OS). This protection includes patches, authentication, encryption, and eliminates unnecessary software and services  (Weaver, Weaver, Farwood, &amp; Weaver, 2012).</p>
<p>Weaver et al.’s (2012) provides the following list of BH characteristics:</p>
<ul>
<li>A machine with adequate memory and processor speed.</li>
<li>All patches up to date.</li>
<li>BH fits the network configuration and is in a secured controlled physical environment.</li>
<li>Only necessary services installed. All other services disabled or uninstalled.</li>
<li>Service accounts such as the administrator account are removed or disabled. Administrative privileges should be given to another created account.</li>
<li>Machine is backed up to include configuration and log files.</li>
<li>Regular security audits.</li>
<li>Connected to the network.</li>
</ul>
<p>BH&#8217;s  are usually located outside the internal network and used with packet filtering devices such as routers and firewalls. on either side. This helps protect the BH from attack because packets are filtered before they reach the BH (Weaver et al., 2012).</p>
<p>Dillard (n.d.) states that BH&#8217;s typically host web, mail, DNS, and FTP services, and are configured differently from other computers and servers. Each BH fulfills a specific role, all unnecessary services, protocols, programs, and network ports are disabled or removed. A BH does not share authentication services with trusted hosts within the network so that if a BH is compromised the intruder will not have unrestricted access. In addition to other hardening already mentioned, Access Control Lists (ACLs) will be modified on the file system and other system objects. Logging of all security related events need to be enabled and steps need to be taken to ensure the integrity of the logs so that a successful intruder is unable to erase evidence of a breach.</p>
<p>References</p>
<p>Dillard, K. (n.d.). <em>IDFAQ: What is a bastion host?</em> Retrieved April 3, 2017, from https://www.sans.org/security-resources/idfaq/what-is-a-bastion-host/2/11.</p>
<p>Weaver, R., Weaver, D., Farwood, D., &amp; Weaver, R. (2012). <em>Guide to Network Defense and Countermeasures (3rd ed.). </em>Boston, MA: Course Technology, Cengage Learning.</p>
<p>The post <a href="https://zymitry.com/bastion-host/">Bastion Host Overview</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/bastion-host/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">476</post-id>	</item>
	</channel>
</rss>
