<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Aldan Security Blog</title>
	<atom:link href="http://aldansec.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://aldansec.wordpress.com</link>
	<description>Security tools, tricks, tips and hands on</description>
	<lastBuildDate>Wed, 24 Aug 2011 10:26:03 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='aldansec.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Aldan Security Blog</title>
		<link>http://aldansec.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://aldansec.wordpress.com/osd.xml" title="Aldan Security Blog" />
	<atom:link rel='hub' href='http://aldansec.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Problems to apply HFA60 on Flash-based systems</title>
		<link>http://aldansec.wordpress.com/2010/05/18/problems-to-apply-hfa60-on-flash-based-systems/</link>
		<comments>http://aldansec.wordpress.com/2010/05/18/problems-to-apply-hfa60-on-flash-based-systems/#comments</comments>
		<pubDate>Tue, 18 May 2010 22:29:12 +0000</pubDate>
		<dc:creator>daniel_aldan</dc:creator>
				<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[Check Point]]></category>
		<category><![CDATA[nokia]]></category>

		<guid isPermaLink="false">https://aldansec.wordpress.com/2010/05/18/problems-to-apply-hfa60-on-flash-based-systems/</guid>
		<description><![CDATA[Recently, I needed to install HFA60 in Nokia IP290 (Flash-based) 1GB with NGX R65. I followed all procedures of HFA Release Notes document: To install NGX R65 HFA 60 on IPSO Flash-based: If using 1GB RAM systems, run the following command to extend the /opt RAM disk partition: /sbin/mount -u -o extend_partition /dev/null /opt To [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=aldansec.wordpress.com&amp;blog=8660413&amp;post=354&amp;subd=aldansec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Recently, I needed to install HFA60 in Nokia IP290 (Flash-based) 1GB with NGX R65. I followed all procedures of HFA Release Notes document:</p>
<p><em>To install NGX R65 HFA 60 on IPSO Flash-based:</em></p>
<ol>
<li><em>If using 1GB RAM systems, run the following command to extend the /opt RAM disk partition: /sbin/mount -u -o extend_partition /dev/null /opt        <br />To verify that the /opt partition was extended to at least 500000 KB, run the df command.</em></li>
<li><em>Verify that there is enough free disk space for the installation of the HFA packages:       <br />* For /preserve, you need at least 455000 KB free.        <br />(To find absolute free space: run the df -k /preserve command and subtract the 3rd column Used from the 2nd column 1K-blocks).        <br />* For /opt and /var, you need at least 382000 KB free.</em></li>
<li><em>Create a temporary directory on /opt: mkdir /opt/hfa</em></li>
<li><em>Navigate to the new directory: cd /opt/hfa</em></li>
<li><em>Download Check_Point_NGX_R65_HFA_60.ipso.tgz (</em><a href="http://supportcontent.checkpoint.com/file_download?id=10349"><em>http://supportcontent.checkpoint.com/file_download?id=10349</em></a><em>) to /opt/hfa and extract the contents.</em></li>
<li><em>Delete the *.tgz file to save disk space.</em></li>
<li><em>Execute: ./UnixInstallScript</em></li>
<li><em>Reboot the machine.</em></li>
</ol>
<p>Unfortunately, I had a lot if problems:</p>
<ol>
<li>After make a copy of hfa file, I didn’t extract it, because of lack of disk space.</li>
<li>Looking for log files, I deleted some audit log from Nokia Voyager that allow me to extract all content from hfa file.</li>
<li>When I tried to execute: ./UnixInstallScript , I got the error: “<i>Can&#8217;t open /opt/CPshared/5.0/tmp/.CPprofile.sh</i>”. I searched for this error on User Center and Google, and I didn’t find anything related with my problem.</li>
<li>Looking for the Check Point packages, I found the CPInfo package, that I immediately deleted. Reboot. I tried again, getting the same error.</li>
<li>I decided then to remove CPsuite-R65 (maybe this procedure will clean all temp files and directories). I rebooted and try to install the CPsuite-R65 again, using IPSO_wrapper_R65.tgz (according Check Point site: <i>NGX R65 Package for Flash Based Platforms with 1GB of RAM or Disk Based Platforms on IPSO 4.1 and 4.2</i>) with 186MB. I did the upload, extract and install. Didn’t install. </li>
<li>After a few hours, I found the package fw1_R65_IPSO.tgz (<i>NGX R65 Package for Flash Based Platforms with 512 MB of RAM on IPSO 4.1 and 4.2</i>) with 77MB. So, I uploaded, extracted and installed, rebooted, and in the end, everything works.</li>
<li>Immediately I applied the HFA60, following the procedures above, with success.</li>
<li>I lost almost 4 hours with this little problem.</li>
</ol>
<p><strong>Conclusion</strong></p>
<p>The Check Point site shows some confusing information about packages, ipso, and missing for Release Notes files.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/aldansec.wordpress.com/354/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/aldansec.wordpress.com/354/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/aldansec.wordpress.com/354/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/aldansec.wordpress.com/354/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/aldansec.wordpress.com/354/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/aldansec.wordpress.com/354/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/aldansec.wordpress.com/354/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/aldansec.wordpress.com/354/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/aldansec.wordpress.com/354/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/aldansec.wordpress.com/354/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/aldansec.wordpress.com/354/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/aldansec.wordpress.com/354/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/aldansec.wordpress.com/354/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/aldansec.wordpress.com/354/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=aldansec.wordpress.com&amp;blog=8660413&amp;post=354&amp;subd=aldansec&amp;ref=&amp;feed=1" width="1" height="1" /><div class="sharedaddy sd-rating-enabled"></div>]]></content:encoded>
			<wfw:commentRss>http://aldansec.wordpress.com/2010/05/18/problems-to-apply-hfa60-on-flash-based-systems/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4ee6dcb53c62f6d6de67801cd3141f5c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">daniel_aldan</media:title>
		</media:content>
	</item>
		<item>
		<title>Configuring DHCP Relay with Check Point</title>
		<link>http://aldansec.wordpress.com/2010/04/07/configuring-dhcp-relay-with-check-point/</link>
		<comments>http://aldansec.wordpress.com/2010/04/07/configuring-dhcp-relay-with-check-point/#comments</comments>
		<pubDate>Wed, 07 Apr 2010 15:14:45 +0000</pubDate>
		<dc:creator>daniel_aldan</dc:creator>
				<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Check Point]]></category>
		<category><![CDATA[dhcp]]></category>
		<category><![CDATA[ipso]]></category>

		<guid isPermaLink="false">http://aldansec.wordpress.com/2010/04/07/configuring-dhcp-relay-with-check-point/</guid>
		<description><![CDATA[I&#8217;ve trying to configure DHCP relay and I found at least 3 KB’s from Check Point UserCenter about DHCP Relay Agent. For this reason I decided to write this post. In my case, I&#8217;m using Nokia (IPSO) with Check Point NGX R65. Basically I have 5 networks: 4 for Users and 1 for servers. My [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=aldansec.wordpress.com&amp;blog=8660413&amp;post=350&amp;subd=aldansec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve trying to configure DHCP relay and I found at least 3 KB’s from Check Point UserCenter about DHCP Relay Agent. For this reason I decided to write this post.</p>
<p>In my case, I&#8217;m using Nokia (IPSO) with Check Point NGX R65. Basically I have 5 networks: 4 for Users and 1 for servers. My DHCP Server (Microsoft) is in Servers Network. My Check Point is the default gateway for all these VLAN’s.</p>
<p>1) In Nokia Voyager (IPSO 4.2) &#8211;&gt; Router Service &#8211;&gt; BootP/DHCP Relay add the IP for your DHCP Server in all Clients Networks. Set “Wait Time” to 0.</p>
<p><a href="http://aldansec.files.wordpress.com/2010/04/ipso_dhcp.jpg"><img style="display:block;float:none;margin-left:auto;margin-right:auto;border-width:0;" title="ipso_dhcp" border="0" alt="ipso_dhcp" src="http://aldansec.files.wordpress.com/2010/04/ipso_dhcp_thumb.jpg?w=644&#038;h=72" width="644" height="72" /></a></p>
<p>2) If you are using VRRP, you need to change one file in your Smart Center Server. Edit this file $FWDIR/lib/table.def and add UDP port 67 and 68 to the no_hide_services_ports section of table.def.</p>
<p>Modified line should appear like the following (post changes made):</p>
<p>no_hide_services_ports = { &lt;500, 17&gt;, &lt;259, 17&gt;, &lt;1701, 17&gt;, &lt;67, 17&gt;, &lt;68, 17&gt; };</p>
<p>3) Create 3 rules</p>
<p><a href="http://aldansec.files.wordpress.com/2010/04/rules_dhcp.jpg"><img style="display:block;float:none;margin-left:auto;margin-right:auto;border-width:0;" title="rules_dhcp" border="0" alt="rules_dhcp" src="http://aldansec.files.wordpress.com/2010/04/rules_dhcp_thumb.jpg?w=531&#038;h=130" width="531" height="130" /></a></p>
<p>I leave Services field in Any, because I had some problems using only dhcp-req-localmodule.</p>
<p>More information:</p>
<ul>
<li><a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;solutionid=sk41515&amp;js_peid=P-114a7ba5fd7-10001&amp;partition=Public&amp;product=VPN-1" target="_blank">sk41515</a> </li>
<li><a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;solutionid=sk41237&amp;js_peid=P-114a7ba5fd7-10001&amp;partition=Public&amp;product=IPSO," target="_blank">sk41237</a> </li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/aldansec.wordpress.com/350/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/aldansec.wordpress.com/350/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/aldansec.wordpress.com/350/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/aldansec.wordpress.com/350/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/aldansec.wordpress.com/350/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/aldansec.wordpress.com/350/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/aldansec.wordpress.com/350/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/aldansec.wordpress.com/350/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/aldansec.wordpress.com/350/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/aldansec.wordpress.com/350/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/aldansec.wordpress.com/350/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/aldansec.wordpress.com/350/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/aldansec.wordpress.com/350/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/aldansec.wordpress.com/350/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=aldansec.wordpress.com&amp;blog=8660413&amp;post=350&amp;subd=aldansec&amp;ref=&amp;feed=1" width="1" height="1" /><div class="sharedaddy sd-rating-enabled"></div>]]></content:encoded>
			<wfw:commentRss>http://aldansec.wordpress.com/2010/04/07/configuring-dhcp-relay-with-check-point/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4ee6dcb53c62f6d6de67801cd3141f5c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">daniel_aldan</media:title>
		</media:content>

		<media:content url="http://aldansec.files.wordpress.com/2010/04/ipso_dhcp_thumb.jpg" medium="image">
			<media:title type="html">ipso_dhcp</media:title>
		</media:content>

		<media:content url="http://aldansec.files.wordpress.com/2010/04/rules_dhcp_thumb.jpg" medium="image">
			<media:title type="html">rules_dhcp</media:title>
		</media:content>
	</item>
		<item>
		<title>Problems to enable SNAC Enforcer DHCP plug-in</title>
		<link>http://aldansec.wordpress.com/2010/02/26/problems-to-enable-snac-enforcer-dhcp-plug-in/</link>
		<comments>http://aldansec.wordpress.com/2010/02/26/problems-to-enable-snac-enforcer-dhcp-plug-in/#comments</comments>
		<pubDate>Fri, 26 Feb 2010 20:31:49 +0000</pubDate>
		<dc:creator>daniel_aldan</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[dhcp]]></category>
		<category><![CDATA[enforcer]]></category>
		<category><![CDATA[plugin]]></category>
		<category><![CDATA[snac]]></category>
		<category><![CDATA[symantec]]></category>

		<guid isPermaLink="false">http://aldansec.wordpress.com/2010/02/26/problems-to-enable-snac-enforcer-dhcp-plug-in/</guid>
		<description><![CDATA[After a long time, I got SNAC Enforcer (DHCP plug-in) works. Let me start from the beginning. When I installed the Enforcer on my MS-DHCP Server, my first problem happened: &#34;Enforcer Cannot Bind To The Agent Authentication Port&#34;, but I can fix it just disable the SNAC Agent (I found a solution here). My second [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=aldansec.wordpress.com&amp;blog=8660413&amp;post=344&amp;subd=aldansec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>After a long time, I got SNAC Enforcer (<em>DHCP plug-in</em>) works. Let me start from the beginning.</p>
<p>When I installed the Enforcer on my MS-DHCP Server, my first problem happened: &quot;Enforcer Cannot Bind To The Agent Authentication Port&quot;, but I can fix it just disable the SNAC Agent (<em>I found a solution </em><a href="http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008020608273348" target="_blank"><em>here</em></a>).</p>
<p>My second problem was the “Encryption Password” (<em>password defined during SEP Manager installation and necessary to start a communications between Enforcer and SEP Manager</em>), because I didn’t know the password. I asked some people here (<em>nobody knew</em>), and we started to try a “lot of possible” passwords. </p>
<p><a href="http://aldansec.files.wordpress.com/2010/02/enforcer1.jpg"><img title="enforcer1" style="display:block;float:none;margin-left:auto;margin-right:auto;border-width:0;" height="166" alt="enforcer1" src="http://aldansec.files.wordpress.com/2010/02/enforcer1_thumb.jpg?w=244&#038;h=166" width="244" border="0" /></a>     <br />After a few hours we found this password and the communications were started successfully (<em>the I-DHCP group appeared in SEP Manager</em>), and the quarantine scope options were added on all my DHCP scopes.</p>
<p><a href="http://aldansec.files.wordpress.com/2010/02/enforcer2.jpg"><img title="enforcer2" style="display:block;float:none;margin-left:auto;margin-right:auto;border-width:0;" height="76" alt="enforcer2" src="http://aldansec.files.wordpress.com/2010/02/enforcer2_thumb.jpg?w=244&#038;h=76" width="244" border="0" /></a></p>
<p>All configurations were “default”, I just added the IP for my SEP Manager Server in “Automatic Quarantine” options.</p>
<p>After a few minutes, some users began to complain about a “network problems”. For all cases I found that users got Quarantine IP (<em>without Default Gateway and mask 255.255.255.255</em>). I tried to using “ipconfig /release” and “ipconfig /renew” many times without success. I checked the antivirus status and everything was Ok. </p>
<p>The Enforcer log showed me the message “Symantec is not running or running an incompatible version”.</p>
<p>So, I decided to stop the Enforcer and delete the quarantine scope options.</p>
<p>I opened a case in Symantec to investigate this issue, and after some questions, they found the problem:</p>
</p>
<p>I needed to add the IP of my Enforcer/DHCP in “Automatic Quarantine” section in Enforcer plug-in configuration. Works.</p>
<p>I would never realize that this kind of configuration was really necessary, because for me is so obvious. Anyway my problem was solved.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/aldansec.wordpress.com/344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/aldansec.wordpress.com/344/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/aldansec.wordpress.com/344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/aldansec.wordpress.com/344/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/aldansec.wordpress.com/344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/aldansec.wordpress.com/344/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/aldansec.wordpress.com/344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/aldansec.wordpress.com/344/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/aldansec.wordpress.com/344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/aldansec.wordpress.com/344/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/aldansec.wordpress.com/344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/aldansec.wordpress.com/344/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/aldansec.wordpress.com/344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/aldansec.wordpress.com/344/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=aldansec.wordpress.com&amp;blog=8660413&amp;post=344&amp;subd=aldansec&amp;ref=&amp;feed=1" width="1" height="1" /><div class="sharedaddy sd-rating-enabled"></div>]]></content:encoded>
			<wfw:commentRss>http://aldansec.wordpress.com/2010/02/26/problems-to-enable-snac-enforcer-dhcp-plug-in/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4ee6dcb53c62f6d6de67801cd3141f5c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">daniel_aldan</media:title>
		</media:content>

		<media:content url="http://aldansec.files.wordpress.com/2010/02/enforcer1_thumb.jpg" medium="image">
			<media:title type="html">enforcer1</media:title>
		</media:content>

		<media:content url="http://aldansec.files.wordpress.com/2010/02/enforcer2_thumb.jpg" medium="image">
			<media:title type="html">enforcer2</media:title>
		</media:content>
	</item>
		<item>
		<title>Symantec Network Access Control: First Impressions</title>
		<link>http://aldansec.wordpress.com/2010/01/07/symantec-network-access-control-first-impressions/</link>
		<comments>http://aldansec.wordpress.com/2010/01/07/symantec-network-access-control-first-impressions/#comments</comments>
		<pubDate>Thu, 07 Jan 2010 19:19:00 +0000</pubDate>
		<dc:creator>daniel_aldan</dc:creator>
				<category><![CDATA[Others]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[endpoint]]></category>
		<category><![CDATA[snac]]></category>
		<category><![CDATA[symantec]]></category>

		<guid isPermaLink="false">http://aldansec.wordpress.com/2010/01/07/symantec-network-access-control-first-impressions/</guid>
		<description><![CDATA[A few weeks ago, we purchased SNAC (Symantec Network Access Control) licenses for our SEPv11 infrastructure.&#160; My first goal: Install SNAC in my existing console. With my Serial Number, I downloaded SNAC software from https://fileconnect.symantec.com/licenselogin.jsp?localeStr=en_US. After, I read the PDF documentation and for my surprise, there wasn’t installation procedure for my case (an existing SEP [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=aldansec.wordpress.com&amp;blog=8660413&amp;post=335&amp;subd=aldansec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A few weeks ago, we purchased SNAC (Symantec Network Access Control) licenses for our SEPv11 infrastructure.&#160; </p>
<p>My first goal: Install SNAC in my existing console. With my Serial Number, I downloaded SNAC software from <a title="https://fileconnect.symantec.com/licenselogin.jsp?localeStr=en_US" href="https://fileconnect.symantec.com/licenselogin.jsp?localeStr=en_US">https://fileconnect.symantec.com/licenselogin.jsp?localeStr=en_US</a>. </p>
<p>After, I read the PDF documentation and for my surprise, there wasn’t installation procedure for my case (an existing SEP console). So, I tried install SNAC by myself, just executing setup.exe. The installation works fine (my console was updated from 11.0.4xxx to 11.0.5002 version) and show the “Host Integrity” option in Policies tab.</p>
<p><a href="http://aldansec.files.wordpress.com/2010/01/image.png"><img title="image" style="border-right:0;border-top:0;display:block;float:none;margin-left:auto;border-left:0;margin-right:auto;border-bottom:0;" height="208" alt="image" src="http://aldansec.files.wordpress.com/2010/01/image_thumb.png?w=209&#038;h=208" width="209" border="0" /></a></p>
<p>After almost a full day of testing, I discovered that Host Integrity only really blocks non-compliance computers with a Firewall Policy enabled and with Peer-to-Peer authentication (I didn’t find this in any PDF documentation).</p>
<p><a href="http://aldansec.files.wordpress.com/2010/01/image1.png"><img title="image" style="border-right:0;border-top:0;display:block;float:none;margin-left:auto;border-left:0;margin-right:auto;border-bottom:0;" height="117" alt="image" src="http://aldansec.files.wordpress.com/2010/01/image_thumb1.png?w=324&#038;h=117" width="324" border="0" /></a> </p>
<p>The block tests works very well, so <strong>I missed an option to “Monitor Only” (without blocks) in Peer-to-Peer Authentication</strong>. I afraid to implement SNAC and block any valid traffic (in my production servers), causing problems.</p>
</p>
<p>The second step in my plan was install the DHCP plug-in (Microsoft DHCP). All my DHCP servers are in MS-Cluster and I didn’t find a documentation for installation in clustered environments. I asked Symantec about this, and Symantec wrote me: “… the DHCP plug-in has not been tested with clustered environments and is therefore not supported …”</p>
<p><strong>Conclusion</strong></p>
<p>I hope Symantec test DHCP plug-in with clustered environments and make a documentation review about SNAC (I still think that is a good product). </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/aldansec.wordpress.com/335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/aldansec.wordpress.com/335/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/aldansec.wordpress.com/335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/aldansec.wordpress.com/335/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/aldansec.wordpress.com/335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/aldansec.wordpress.com/335/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/aldansec.wordpress.com/335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/aldansec.wordpress.com/335/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/aldansec.wordpress.com/335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/aldansec.wordpress.com/335/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/aldansec.wordpress.com/335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/aldansec.wordpress.com/335/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/aldansec.wordpress.com/335/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/aldansec.wordpress.com/335/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=aldansec.wordpress.com&amp;blog=8660413&amp;post=335&amp;subd=aldansec&amp;ref=&amp;feed=1" width="1" height="1" /><div class="sharedaddy sd-rating-enabled"></div>]]></content:encoded>
			<wfw:commentRss>http://aldansec.wordpress.com/2010/01/07/symantec-network-access-control-first-impressions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4ee6dcb53c62f6d6de67801cd3141f5c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">daniel_aldan</media:title>
		</media:content>

		<media:content url="http://aldansec.files.wordpress.com/2010/01/image_thumb.png" medium="image">
			<media:title type="html">image</media:title>
		</media:content>

		<media:content url="http://aldansec.files.wordpress.com/2010/01/image_thumb1.png" medium="image">
			<media:title type="html">image</media:title>
		</media:content>
	</item>
		<item>
		<title>How to proceed when Symantec Endpoint doesn&#8217;t detect a threat</title>
		<link>http://aldansec.wordpress.com/2009/12/17/how-to-proceed-when-symantec-endpoint-doesnt-detect-a-threat/</link>
		<comments>http://aldansec.wordpress.com/2009/12/17/how-to-proceed-when-symantec-endpoint-doesnt-detect-a-threat/#comments</comments>
		<pubDate>Thu, 17 Dec 2009 18:11:56 +0000</pubDate>
		<dc:creator>daniel_aldan</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Utilities]]></category>
		<category><![CDATA[endpoint]]></category>
		<category><![CDATA[symantec]]></category>

		<guid isPermaLink="false">http://aldansec.wordpress.com/2009/12/17/how-to-proceed-when-symantec-endpoint-doesnt-detect-a-threat/</guid>
		<description><![CDATA[As an administrator of a SEP (Symantec Endpoint Protection) environment with about 5000 computers (in different locations), I had two experiences with threats that Symantec didn’t detect. So, what the procedure to send this threat (file) to Symantec build a new set of definitions? Send the suspicious file to Symantec: https://submit.symantec.com/websubmit/essential.cgi Wait for an answer [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=aldansec.wordpress.com&amp;blog=8660413&amp;post=323&amp;subd=aldansec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>As an administrator of a SEP (Symantec Endpoint Protection) environment with about 5000 computers (in different locations), I had two experiences with threats that Symantec didn’t detect.</p>
<p>So, what the procedure to send this threat (file) to Symantec build a new set of definitions?</p>
<ol>
<li>Send the suspicious file to Symantec: <a title="https://submit.symantec.com/websubmit/essential.cgi" href="https://submit.symantec.com/websubmit/essential.cgi" target="_blank">https://submit.symantec.com/websubmit/essential.cgi</a></li>
<li>Wait for an answer from Symantec, and download the new definitions files (Symantec will send you a ftp site link to do this):<br />
symrapidreleasedefsi32.exe or/and symrapidreleasedefsi64.exe<br />
vd2fxxxx.jdb</p>
<p>The exe (x86 or x64) file is a Intelligent Updater, for manual updates.<br />
The .JDB file is a package to apply in your SEPM<br />
You can get more information about these files <a href="http://www.symantec.com/business/security_response/definitions/download/detail.jsp?gid=rr" target="_blank">here</a>.</li>
<li>Test using EXE file if this (new) definition detects the threat</li>
<li>If yes, apply it (.JDB file) into your SEPM following <a href="http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007100820002048" target="_blank">these instructions</a>.</li>
</ol>
<p><span class="short_text"><span style="background-color:#ffffff;" title="espero que isso possa ser util">I hope this will be useful.</span></span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/aldansec.wordpress.com/323/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/aldansec.wordpress.com/323/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/aldansec.wordpress.com/323/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/aldansec.wordpress.com/323/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/aldansec.wordpress.com/323/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/aldansec.wordpress.com/323/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/aldansec.wordpress.com/323/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/aldansec.wordpress.com/323/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/aldansec.wordpress.com/323/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/aldansec.wordpress.com/323/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/aldansec.wordpress.com/323/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/aldansec.wordpress.com/323/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/aldansec.wordpress.com/323/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/aldansec.wordpress.com/323/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=aldansec.wordpress.com&amp;blog=8660413&amp;post=323&amp;subd=aldansec&amp;ref=&amp;feed=1" width="1" height="1" /><div class="sharedaddy sd-rating-enabled"></div>]]></content:encoded>
			<wfw:commentRss>http://aldansec.wordpress.com/2009/12/17/how-to-proceed-when-symantec-endpoint-doesnt-detect-a-threat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4ee6dcb53c62f6d6de67801cd3141f5c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">daniel_aldan</media:title>
		</media:content>
	</item>
		<item>
		<title>Problem to push a policy after a SmartCenter migration</title>
		<link>http://aldansec.wordpress.com/2009/12/08/problem-to-push-a-policy-after-a-smartcenter-migration/</link>
		<comments>http://aldansec.wordpress.com/2009/12/08/problem-to-push-a-policy-after-a-smartcenter-migration/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 21:26:40 +0000</pubDate>
		<dc:creator>daniel_aldan</dc:creator>
				<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Check Point]]></category>
		<category><![CDATA[ng]]></category>
		<category><![CDATA[ngx]]></category>
		<category><![CDATA[SmartCenter]]></category>

		<guid isPermaLink="false">http://aldansec.wordpress.com/2009/12/08/problem-to-push-a-policy-after-a-smartcenter-migration/</guid>
		<description><![CDATA[After a successfully upgrade of Smart Center from NG to NGX (R55 to R65), I had some problems with one of my node clusters VRRP. When I tried to push a policy, the following error message appears: Reason: Load on Module failed &#8211; failed to load Security Policy.   ( message from member &#60;firewall-name&#62; ) I [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=aldansec.wordpress.com&amp;blog=8660413&amp;post=322&amp;subd=aldansec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>After a successfully upgrade of Smart Center from NG to NGX (R55 to R65), I had some problems with one of my node clusters VRRP.</p>
<p>When I tried to push a policy, the following error message appears:</p>
<p>Reason: Load on Module failed &#8211; failed to load Security Policy.   ( message from member &lt;firewall-name&gt; )</p>
<p>I tried everything to see an error message that told me something else, like:</p>
<ul>
<li>fw –d fetch &lt;smart-center-ip&gt; from Security Gateways</li>
<li>fwm load -d &lt;PolicyName&gt; &lt;security-gw&gt; from SmartCenter</li>
<li>Looking for all log files</li>
</ul>
<p>But nothing, help me. Although I had already seen this <a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;solutionid=sk33893" target="_blank">sk33893</a> before, I did not give due attention to it. My problem was exactly described in this kb article.</p>
<p>I had an interface in one of my Cluster members, duplicated with the other node, but, the Nokia (Voyager) configuration was right. I just correct the ip of this interface in the Firewall object and push a policy. Works.</p>
<p><strong><span style="font-size:small;">Conclusion</span></strong></p>
<p>I lost almost 3 days trying to analyze this problem, building a lab to try reproduce this, while the solution was very quickly and simple.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/aldansec.wordpress.com/322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/aldansec.wordpress.com/322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/aldansec.wordpress.com/322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/aldansec.wordpress.com/322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/aldansec.wordpress.com/322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/aldansec.wordpress.com/322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/aldansec.wordpress.com/322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/aldansec.wordpress.com/322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/aldansec.wordpress.com/322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/aldansec.wordpress.com/322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/aldansec.wordpress.com/322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/aldansec.wordpress.com/322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/aldansec.wordpress.com/322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/aldansec.wordpress.com/322/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=aldansec.wordpress.com&amp;blog=8660413&amp;post=322&amp;subd=aldansec&amp;ref=&amp;feed=1" width="1" height="1" /><div class="sharedaddy sd-rating-enabled"></div>]]></content:encoded>
			<wfw:commentRss>http://aldansec.wordpress.com/2009/12/08/problem-to-push-a-policy-after-a-smartcenter-migration/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4ee6dcb53c62f6d6de67801cd3141f5c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">daniel_aldan</media:title>
		</media:content>
	</item>
		<item>
		<title>Check Point: Merge objects and Import/Export policies</title>
		<link>http://aldansec.wordpress.com/2009/12/04/check-point-merge-objects-and-importexport-policies/</link>
		<comments>http://aldansec.wordpress.com/2009/12/04/check-point-merge-objects-and-importexport-policies/#comments</comments>
		<pubDate>Fri, 04 Dec 2009 17:00:25 +0000</pubDate>
		<dc:creator>daniel_aldan</dc:creator>
				<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Utilities]]></category>
		<category><![CDATA[Check Point]]></category>
		<category><![CDATA[SmartCenter]]></category>

		<guid isPermaLink="false">http://aldansec.wordpress.com/2009/12/04/check-point-merge-objects-and-importexport-policies/</guid>
		<description><![CDATA[Looking for a tool to do merge between objects from 2 or more SmartCenter Server, I discovered a Check Point command that could be helpful: cp_merge. Using cp_merge it’s possible to do merge, export and import policies. I used it, to do a merge between 2 Smart Centers Server and import a new policy. Works [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=aldansec.wordpress.com&amp;blog=8660413&amp;post=311&amp;subd=aldansec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Looking for a tool to do merge between objects from 2 or more SmartCenter Server, I discovered a Check Point command that could be helpful: <strong>cp_merge</strong>.</p>
<p>Using <strong>cp_merge</strong> it’s possible to do merge, export and import policies.</p>
<p>I used it, to do a merge between 2 Smart Centers Server and import a new policy. Works very well.</p>
<p>More information about it, see here: <a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;solutionid=sk33751" target="_blank">sk33751</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/aldansec.wordpress.com/311/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/aldansec.wordpress.com/311/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/aldansec.wordpress.com/311/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/aldansec.wordpress.com/311/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/aldansec.wordpress.com/311/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/aldansec.wordpress.com/311/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/aldansec.wordpress.com/311/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/aldansec.wordpress.com/311/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/aldansec.wordpress.com/311/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/aldansec.wordpress.com/311/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/aldansec.wordpress.com/311/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/aldansec.wordpress.com/311/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/aldansec.wordpress.com/311/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/aldansec.wordpress.com/311/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=aldansec.wordpress.com&amp;blog=8660413&amp;post=311&amp;subd=aldansec&amp;ref=&amp;feed=1" width="1" height="1" /><div class="sharedaddy sd-rating-enabled"></div>]]></content:encoded>
			<wfw:commentRss>http://aldansec.wordpress.com/2009/12/04/check-point-merge-objects-and-importexport-policies/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4ee6dcb53c62f6d6de67801cd3141f5c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">daniel_aldan</media:title>
		</media:content>
	</item>
		<item>
		<title>Helpful and Simple FTP Server</title>
		<link>http://aldansec.wordpress.com/2009/12/01/helpful-and-simple-ftp-server/</link>
		<comments>http://aldansec.wordpress.com/2009/12/01/helpful-and-simple-ftp-server/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 16:58:29 +0000</pubDate>
		<dc:creator>daniel_aldan</dc:creator>
				<category><![CDATA[Utilities]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[ftp]]></category>

		<guid isPermaLink="false">http://aldansec.wordpress.com/2009/12/01/helpful-and-simple-ftp-server/</guid>
		<description><![CDATA[Xlight FTP is a simple powerful FTP Server, that can be very important in some situations. It’s help me many times, when I needed to do some file transfers in environments that other type of file transfer weren’t possible. Xlight has a version that not require installation, it’s only a executable file (you can put [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=aldansec.wordpress.com&amp;blog=8660413&amp;post=309&amp;subd=aldansec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Xlight FTP is a simple powerful FTP Server, that can be very important in some situations. It’s help me many times, when I needed to do some file transfers in environments that other type of file transfer weren’t possible.</p>
<p>Xlight has a version that not require installation, it’s only a executable file (you can put it on USB drive).</p>
<p><a href="http://aldansec.files.wordpress.com/2009/12/image.png"><img style="display:block;float:none;margin-left:auto;margin-right:auto;border:0;" title="image" src="http://aldansec.files.wordpress.com/2009/12/image_thumb.png?w=244&#038;h=175" border="0" alt="image" width="244" height="175" /></a></p>
<p>More information about it, you can see <a href="http://www.xlightftpd.com/" target="_blank">here</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/aldansec.wordpress.com/309/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/aldansec.wordpress.com/309/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/aldansec.wordpress.com/309/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/aldansec.wordpress.com/309/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/aldansec.wordpress.com/309/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/aldansec.wordpress.com/309/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/aldansec.wordpress.com/309/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/aldansec.wordpress.com/309/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/aldansec.wordpress.com/309/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/aldansec.wordpress.com/309/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/aldansec.wordpress.com/309/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/aldansec.wordpress.com/309/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/aldansec.wordpress.com/309/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/aldansec.wordpress.com/309/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=aldansec.wordpress.com&amp;blog=8660413&amp;post=309&amp;subd=aldansec&amp;ref=&amp;feed=1" width="1" height="1" /><div class="sharedaddy sd-rating-enabled"></div>]]></content:encoded>
			<wfw:commentRss>http://aldansec.wordpress.com/2009/12/01/helpful-and-simple-ftp-server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4ee6dcb53c62f6d6de67801cd3141f5c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">daniel_aldan</media:title>
		</media:content>

		<media:content url="http://aldansec.files.wordpress.com/2009/12/image_thumb.png" medium="image">
			<media:title type="html">image</media:title>
		</media:content>
	</item>
		<item>
		<title>About new posts</title>
		<link>http://aldansec.wordpress.com/2009/11/24/about-new-posts/</link>
		<comments>http://aldansec.wordpress.com/2009/11/24/about-new-posts/#comments</comments>
		<pubDate>Tue, 24 Nov 2009 17:51:09 +0000</pubDate>
		<dc:creator>daniel_aldan</dc:creator>
				<category><![CDATA[Others]]></category>

		<guid isPermaLink="false">http://aldansec.wordpress.com/2009/11/24/about-new-posts/</guid>
		<description><![CDATA[Starting from now, I’ll (try to) write my posts in English. There are some reasons for that, two of which are: Almost all products and technologies documentations are written in English. It’s so familiar for me and other IT professionals (to read); I’m still learning English, and for that, I need to training more. Some [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=aldansec.wordpress.com&amp;blog=8660413&amp;post=304&amp;subd=aldansec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Starting from now, I’ll (try to) write my posts in English. There are some reasons for that, two of which are:</p>
<ul>
<li>Almost all products and technologies documentations are written in English. It’s so familiar for me and other IT professionals (to read); </li>
<li>I’m still learning English, and for that, I need to training more. </li>
</ul>
<p><strong><font size="2">Some Considerations</font></strong></p>
<p>I know I made grammar mistakes and it doesn’t worry me,&#160; after all, it just happens when you try.</p>
<p>If you find a mistake, feel comfortable to correct me. I’ll be grateful.</p>
<p>Enjoy.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/aldansec.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/aldansec.wordpress.com/304/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/aldansec.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/aldansec.wordpress.com/304/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/aldansec.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/aldansec.wordpress.com/304/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/aldansec.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/aldansec.wordpress.com/304/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/aldansec.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/aldansec.wordpress.com/304/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/aldansec.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/aldansec.wordpress.com/304/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/aldansec.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/aldansec.wordpress.com/304/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=aldansec.wordpress.com&amp;blog=8660413&amp;post=304&amp;subd=aldansec&amp;ref=&amp;feed=1" width="1" height="1" /><div class="sharedaddy sd-rating-enabled"></div>]]></content:encoded>
			<wfw:commentRss>http://aldansec.wordpress.com/2009/11/24/about-new-posts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4ee6dcb53c62f6d6de67801cd3141f5c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">daniel_aldan</media:title>
		</media:content>
	</item>
		<item>
		<title>Custom detailed Report for Symantec Endpoint Protection</title>
		<link>http://aldansec.wordpress.com/2009/11/18/custom-detailed-report-for-symantec-endpoint-protection/</link>
		<comments>http://aldansec.wordpress.com/2009/11/18/custom-detailed-report-for-symantec-endpoint-protection/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 13:42:33 +0000</pubDate>
		<dc:creator>daniel_aldan</dc:creator>
				<category><![CDATA[Utilities]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[computers]]></category>
		<category><![CDATA[endpoint]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[t-sql]]></category>

		<guid isPermaLink="false">http://aldansec.wordpress.com/?p=300</guid>
		<description><![CDATA[Precisava gerar um relatório para a auditoria, com informações detalhadas de todos os computadores e servidores de um determinado grupo, com informações como nome de computador, usuário, memória, versão do agente, último scan, versão da definição de vírus, etc. Infelizmente não achei nenhum template de report nestes moldes, então resolvi fazer eu mesmo  uma query [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=aldansec.wordpress.com&amp;blog=8660413&amp;post=300&amp;subd=aldansec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Precisava gerar um relatório para a auditoria, com informações detalhadas de todos os computadores e servidores de um determinado grupo, com informações como nome de computador, usuário, memória, versão do agente, último scan, versão da definição de vírus, etc.</p>
<p>Infelizmente não achei nenhum template de report nestes moldes, então resolvi fazer eu mesmo  uma query SQL. Segue abaixo:</p>
<pre class="brush: sql;">
use sem7
select sc.computer_name, sc.current_login_user, sc.operation_system,
sc.processor_type, sc.memory, sc.bios_version, sc.ip_addr1_text, sa.agent_version,
dateadd(s,convert(bigint,sa.last_scan_time)/1000,'01-01-1970 00:00:00') as last_scan_time,
p.version as v_definitions, im.name
from sem_agent as sa
inner join
v_sem_computer as sc on sc.computer_id = sa.computer_id
inner join
pattern as p on sa.pattern_idx = p.pattern_idx
inner join
identity_map as im on sa.group_id = im.id
where
sa.group_id in (SELECT id FROM IDENTITY_MAP
where name like '%My Company%')
and sa.deleted=0
</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/aldansec.wordpress.com/300/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/aldansec.wordpress.com/300/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/aldansec.wordpress.com/300/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/aldansec.wordpress.com/300/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/aldansec.wordpress.com/300/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/aldansec.wordpress.com/300/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/aldansec.wordpress.com/300/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/aldansec.wordpress.com/300/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/aldansec.wordpress.com/300/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/aldansec.wordpress.com/300/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/aldansec.wordpress.com/300/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/aldansec.wordpress.com/300/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/aldansec.wordpress.com/300/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/aldansec.wordpress.com/300/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=aldansec.wordpress.com&amp;blog=8660413&amp;post=300&amp;subd=aldansec&amp;ref=&amp;feed=1" width="1" height="1" /><div class="sharedaddy sd-rating-enabled"></div>]]></content:encoded>
			<wfw:commentRss>http://aldansec.wordpress.com/2009/11/18/custom-detailed-report-for-symantec-endpoint-protection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4ee6dcb53c62f6d6de67801cd3141f5c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">daniel_aldan</media:title>
		</media:content>
	</item>
	</channel>
</rss>
