<?xml version="1.0" encoding="UTF-8"?><!-- generator="WordPress/2.6" -->
<rss version="0.92">
<channel>
	<title>Francois Ropert weblog</title>
	<link>http://blog.packetfault.org</link>
	<description>Binary packets in hostile digital world</description>
	<lastBuildDate>Wed, 19 Nov 2008 16:03:21 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>Numéros de systèmes autonomes BGP, l&#8217;autre pénurie du net</title>
		<description><![CDATA[Il existe une méthode encore plus radicale pour empêcher la world domination même en connaissant ces fameuses adresses IP, le système BGP (Border Gateway Protocol). Pour fonctionner, Internet utilise BGP dans le but de relier un réseau à un autre réseau, chacun s'emboitant les uns dans les autres à coup de peering et transit offrant une architecture décentralisé.]]></description>
		<link>http://blog.packetfault.org/protocols/bgp-asn-4bytes</link>
			</item>
	<item>
		<title>Cisco IOS Router Security mind map</title>
		<description><![CDATA[I just created a mind map about securing a Cisco IOS router. The map gives you information about how securing services and how to secure the device itself from attacks. It's like a cheat sheet but a graphic's one and very compact compared to hundreds of pages in various security best-practices guides.]]></description>
		<link>http://blog.packetfault.org/ccie/cisco-ios-router-security-mind-map</link>
			</item>
	<item>
		<title>Security before operations</title>
		<description><![CDATA[Many pro-IPv6 people would love to have IPv6 everywhere now and even yesterday. What I'm noticing is that most of common operating systems IPv6 stack have at least one vulnerability. I can call this phenomen by <em>pressure cause  imaturity</em>. Vendors, geeks, please don't forget the <em>security before operations</em> adage or you will get powned by yourself in a future day.]]></description>
		<link>http://blog.packetfault.org/ipv6/security-before-operations</link>
			</item>
	<item>
		<title>Cisco security advice of the day</title>
		<description><![CDATA[Hello there,
Today a new security alert about VTP (Vlan Trunking Protocol) was disclosed. In a Bisounours(Care Bears) world, people follow security best practices and the security work is done. Sometimes, things overcome best practices paper.
Please take a chair, sit down and put on Telemann music. 
The vulnerability do a denial of service on the VTP process [...]]]></description>
		<link>http://blog.packetfault.org/ios/cisco-security-advice-of-the-day</link>
			</item>
	<item>
		<title>SSH challenge #2 - Enable SSH without ip domain-name</title>
		<description><![CDATA[This SSH challenge is specific to Cisco devices.
In most litteratures, setting hostname and ip domain-name is a pre-requisite for enable SSH server on a Cisco IOS. Is that really true? ...]]></description>
		<link>http://blog.packetfault.org/ccie/ssh-challenge-2-enable-ssh-without-ip-domain-name</link>
			</item>
	<item>
		<title>[French] MISC40 Sécurité des réseaux, les nouveaux enjeux</title>
		<description><![CDATA[Oyé oyé! Le MISC40 avec un dossier sécurité des réseaux est disponible dans votre kiosque préféré depuis aujourd'hui. D'habitude je ne fais pas les sorties de nouveaux numéros mais là c'est différent car j'ai pu écrire un article dedans (Le très haut débit - un challenge pour la sécurité). Voici le sommaire complet ...]]></description>
		<link>http://blog.packetfault.org/publications/misc-40-securite-reseaux-nouveaux-enjeux</link>
			</item>
	<item>
		<title>SSH challenge #1 - Version 1 automatically enabled</title>
		<description><![CDATA[Welcome to SSH challenge number 1! Are you sure you really know SSH?
Assuming the next output, what is the root cause of the automagically presence of ip ssh version 1 in the show run output considering I never typed this in CLI?]]></description>
		<link>http://blog.packetfault.org/ccie/ssh-challenge-1-version-1-automatically-enabled</link>
			</item>
	<item>
		<title>GET VPN notes</title>
		<description><![CDATA[Here are my notes about GET VPN technology. My lab consists of a backbone, 3KS and 3GM.
<img src="http://blog.packetfault.org/getvpn-lab.png">]]></description>
		<link>http://blog.packetfault.org/ccie/get-vpn-notes</link>
			</item>
	<item>
		<title>Cisco Secure Firewall Services Module (FWSM) Ciscopress book review</title>
		<description><![CDATA[Cisco FWSM is the firewall module card which can be inserted into Catalyst 6500. Based on PIX algorithms and Finesse operating system, many concepts are similir to the one's you will find into PIX or ASA. The real added-value is that it's moduleable and can connected to a lot of other moduleable cards like CSM, ACE or MSFC.]]></description>
		<link>http://blog.packetfault.org/books/cisco-fwsm-ciscopress-book-review</link>
			</item>
	<item>
		<title>DNS based GSLB demystified (part 3/3)</title>
		<description><![CDATA[Active/Active topology should be considered. When taking a GSLB decision, any traditional method of load balancing are configurable: WRR (Weighted Round Robin), Least connections, Least bandwidth, Least packets/s… as long as the GSLB entity can communicate with each GSLB site to get all the needed information…]]></description>
		<link>http://blog.packetfault.org/protocols/dns-based-gslb-demystified-part-3</link>
			</item>
</channel>
</rss>
