Showing posts with label silva. Show all posts
Showing posts with label silva. Show all posts

Tuesday, January 26, 2021

How Ransomware Has Evolved to Be Faster, Stealthier, and Strike Harder

 

Ransomware attacks have reached the boiling point. They’ve gone from nuisance to significant financial burden—as well as a mortal threat to critical infrastructure. Financial damage from ransomware attacks is in the hundreds of millions of dollars for some organizations. And, of course, our F5 Labs threat researchers have something to say about it. So, let’s start the clock to explore How Ransomware Has Evolved to Be Faster, Stealthier, and Strike Harder. 

Full article: https://www.f5.com/labs/articles/threat-intelligence/ransomware-how-it-has-evolved-to-be-faster-stealthier-and-strike-harder

Saturday, December 26, 2020

How Cyber Attacks Changed During the Pandemic

 #F5 SIRT reviewed all the reported security incidents from January through August 2020 to see how the pandemic changed the cyberthreat landscape. Hint: #DDoS attacks dominated the pandemic lockdown. Learn more: https://www.f5.com/labs/articles/threat-intelligence/how-cyber-attacks-changed-during-the-pandemic

So let’s start the clock to see How Cyber Attacks Changed During the #Pandemic.


Sunday, April 5, 2020

Connect to the F5 VPN with BIG-IP Edge Client

Your organization may have F5 BIG-IP APM for VPN access. See how you can connect to your org's VPN using the BIG-IP Edge Client along with Chrome, Microsoft Edge and Firefox browsers. How to authenticate, do MFA, check settings and what is split-tunneling. You can also get the F5 Access mobile app for iOS, Android and Windows Phone from the respective app stores.


 

ps

Remote Desktop Protocol (RDP) using an SSL VPN

Returning to the F5 DevCentral Lightboard, I explain why its a bad idea to expose RDP to the internet and how using a SSL VPN like BIG-IP APM is a much safer and better idea.



ps

Tuesday, October 29, 2019

90 Seconds of Security: Malware Primer

My latest 90 Seconds covers the different types of malware, how infections happen and what to do if you get infected. Slightly extended edition courtesy of F5's Security Incident Response Team. https://f5.com/sirt




ps

Friday, August 30, 2019

90 Seconds of Security: F5 Security at Black Hat USA 2019

Learn about RedTunnel, how to explore internal networks via the DNS rebinding tunnel, and how we used the new SODA (Simulation of DDoS Attacks) tool to defend against rapidly morphing DDoS attacks. You can also download the sessions the F5 Security team delivered at #BHUSA by going to f5.com/blackhat.


Friday, August 16, 2019

90 Seconds of Security: Security Stories for July 2019

A 90 second recap of some of the recent security stories for July 2019. The F5 SIRT (f5.com/sirt) shares some of the security incidents that caught their attention in July. In this episode we cover recent GDPR enforcements, yet another Magecart attack on S3 buckets and Overwhelmed IT personnel.


Thursday, July 18, 2019

90 Seconds of Security: Security Incidents for June 2019

A 90 second recap of some of the recent security incidents for June 2019. The F5 SIRT shares some of the security incidents that caught their attention in June. In this episode we cover the recent Mozilla vulnerability, the GandCrab decryptor and Linux Exim issue.


Friday, June 21, 2019

Grateful for 15 with F5


Today marks 15 years with F5. That’s 28.8% of my life and 50% of my professional career! And no, this is not a ‘thank you, goodbye’ note. In fact, the opposite.


As I write this, so many memories come to mind. Now, I could brag about the almost 500 F5 videos I’ve produced or the almost 1000 various articles and blog posts I’ve written over the years or the lost count of presentations, trade shows and other ‘speaker’ type engagements. And now that that’s out of the way, I’d really like to thank and recognize the many people who’ve helped me along this journey.


You can’t last anywhere for 15 years unless you’ve had help, direction, encouragement and support.

June 20, 2004, I flew from Honolulu to San Jose to secure an apartment and the following morning June 21, 2004, I flew to Seattle for my first day at F5. Officially, I was employee 651.

What you might not know is I interviewed for the first F5 BizDev SE position in February 2004. I didn’t get the job but apparently impressed some folks since I brought chocolate covered macadamias from the Islands. And, dressed in a suit. One of the less than 50 times that’s happened in my life. I kept in contact with HR (Rich James, if I remember correctly) and a couple months later, another opportunity opened. Initially it was to be the West Coast SE based in San Jose but during the interview process, John Bigelow called and said, ‘we’re starting a new security group, and you’ll be interviewing with me.’ Cool with me.

I had my technical interview with Ken Salchow. He was at Interop at the time and when he called, he told me that he had some challenges with some people at my previous company (Exodus) and hoped I wasn’t like them. He gave me the full ENE tech-out and while I did my best, there were certainly questions I didn’t know at the time like, what’s more secure – SSL or IPSEC. And I said so. I guess the honestly and follow up (sent all my missing answers in a thank you email) won him over. After emailing him, he told me that he told Bigelow that as much as he hated to do it, not hiring me would likely be the biggest hiring mistake he’d ever make. Ken is the Godfather of our daughter if you want to know how that relationship turned out. Above anyone, Ken has been a guiding light for me during my years at F5. He was also my boss for a few of those.

From 2004-06, I was a Security Systems Architect in F5’s original Security Business Unit. Ken and Charlie Cano were the other two. During this time, I was part of a handful of people sharing F5's first security story. Part of the NA security overlay for sales helping close security business deals. Back then, we were positioning our FirePass SSLVPN and why it was better than the IPSECs of the era…and talking about TrafficShield, our Web Application Firewall at the time. It was a fun time training folks on hacking techniques like Forceful Browsing, Parameter Tampering and SQL Injections. But really, I owe a lot to the San Jose PD team like James Goodwin, Igor Plotnikov, Serge Charapaev and many other developers who shared their expertise with me along with Joel Dujsik & Joe Taylor in Support. On the WAF front, folks like Tom Spector, John George & Ido Breger shared intrusion techniques that I then turned into WOW moments for customers. We were a small but tight crew and were on the bleeding edge at the time.

As security solutions became part of sales, the SBU eventually disbanded and the SE managers needed a headcount and asked if I would relinquish mine. I was thinking of moving into support or another role but had 30 days to find that. Ken had moved on to Marketing by then and became the first Technical Marketing Manager at F5. When my role was eliminated, he brought me on to his TMM team.

From 2006-13, I was the Security TMM. During this time, I was the primary spokesperson for F5's security solutions covering access, SSL-VPN, application security/WAF and other evolving security topics. Our TMM team included Ken (‘til 2011 when he started Certification) Lori MacVittie, Alan Murphy & soon after, David Freedel. I learned so much from them and their specialized areas. We blew out whitepapers by the dozens, presented at all our conferences/events and told technical stories that regular folks could understand.

This is when I also started writing articles, blogs and producing videos. YouTube started in 2005 and with my theater background, I thought it would be a good way to share F5 stories. You might remember my opening of, ‘ALOHA!’ Big thanks to my good buddy Jonathan George who for many years was my camera guy. I also need to thank Erik Giesa since it was in 2009 when one day, he said to me, ‘I want you writing on DevCentral.’ OK, cool. And another thanks to Ken, for believing in the video stuff back then when many wondered, why is he doing that? Soon, videos were part of all our campaigns and that’s when I also developed the ‘In 5 Minutes or Less’ series. Let’s walk through a configuration in 5 minutes. Wildly popular and even had competitors drop some ‘in 4 minutes’ stuff. Name that tune!

Something else happened in 2007. Our daughter was diagnosed with a rare genetic disorder called HI/HA GDH. She was only 10 months old and we were in the hospital for two weeks. I still remember getting an email from Dan Matte, SVP Marketing at the time, telling me to take as much time as I need to care for my family, work will be there when I return. Deeply touched and what solidified my commitment to the company. They cared. And when we wanted to move to SoCal from San Jose for family reasons in 2010, they were fully supportive.

Folks like Alane Moran and Christine Pomeroy were excellent mentors for ‘spokesperson’ type stuff. How to engage with analysts, press and other entities that I had no experience with up to that point. Thanks ladies - really appreciate your guidance.

From 2013-16 after a promotion to Sr. I was one of the primary technical spokespeople for all F5 solutions along with covering emerging technologies like IoT, Mobile, Identity Theft and cloud. This was an amazing time. Traveling monthly to various trade shows and interviewing bunches of smart folks about technology. It’s pretty cool that we have a video record of what F5 was sharing over the years at these events. How the booth changed, the signage, messaging and even the t-shirts and giveaways.

Probably one of my most memorable video interviews was with John McAdam, F5 CEO at the time, during MWC 2015. He was gracious, insightful and funny. Another was Jeremiah Grossman, Security Luminary and fellow Island Boy. For 5 years straight (2010-15) Jer was gracious enough to get on camera with me at RSA and talk security. Our RSA2015 editionwas probably the best of the bunch.

Around the 2013-14 timeframe, I was lucky to be on what was called the Marketing Architecture Team led by Dean Darwin. We were a group of tech folks with marketing backgrounds and we built out a bunch of Reference Architectures for various solutions. From DNS to Cloud to Federation to NFV and others. We designed topologies, deployment scenarios, presentations and architecture diagrams. From high level to deep in the weeds, we created some cool solutions.

Like anything, the official TMM team eventually faded and we all joined up with other groups, primarily in Marketing. I think there was a point in 2015/16 where I was the only one still with a TMM title. But that too would change.

Late 2015, while I was planning some cool career moves within F5, my boss at the time suddenly left. And I was left with no real path as to what I’d do now that my manager was gone. Luckily, Steven Webster, who was running Digital Marketing at the time suggested I join the DevCentral team. They needed someone but I was initially reluctant since many technical skills had dwindled or vanished. I wasn’t configuring boxes daily; I wasn’t deep in the hands-on weeds of this stuff. I knew the ins and outs, but high-level business value is a much different story than this is how you do it. All I wanted to do was keep writing, speaking and producing videos. I cried for about 20 minutes to purge all that and embraced the chance to join the DevCentral crew.

And I’m glad I did.

From 2016-2018, I was a Sr. Solution Developer and during this time, I was part of the DC Community helping F5 customers get into the guts of F5 technologies and ensuring they have a positive experience within the community. It was an excellent move going from outbound talk-story to working with those who already know it. Sometimes, better than I. I needed to get back into the weeds a bit to keep some tech skills while learning new ones. I even passed Certification’s Exam 101 - Application Delivery Fundamentals!

And one of my dreams came true. A home studio.

While many ‘guys’ want their man-cave or home theater or game room, whatever. I had always wished, ‘if I only had a studio in my house.’ Well, Tony Hynes, Community Director, wanted me to produce LightBoard Lessonslike the ones John Wagnon and Jason Rahm produced and asked if I had a space to set up a studio. Hell yes I do! And fortunately, my wife agreed. I turned one of our spare bedrooms into a video studio complete with backdrops, pro lights, acoustic panels, nice camera and a 4ft x 6ft pane of Starfire glass with frame. It took about a month to get it right, especially with the lighting, but I’ve been able to produce over 20 LightBoard Lessons covering topics like DDoS, HTTP, DNS, Proxy's, IoT, VDI, Bots, MQTT, SAML and many others. During my DC days, I was also the liaison for the DevCentral MVPs (fantastic group) and handled the Social Media accounts. Great fun, great group and while I love 'em all, Chase Abbott was always my favorite. Morning sunshine!

Which brings me to July 2018. And, my last article entry here on LinkedIn called Me:Recently. I can wait while you read that.

OK, cool? 😊

Basically, I got caught in a RIF and was essentially unemployed. I was stunned to say the least. The company offered those who wanted, 30 days to find something internal. I took that and suffice to say, it worked out or I wouldn’t be writing this now. Huge appreciation to Preston Hogue for saving my skin and longtime friend Steve McChesney for helping shepherd it along. Incredibly & eternally grateful.

Since August 2018, I’ve been on the Security Marketing Team continuing what I enjoy – telling stories about information security by writing, producing videos & evangelizing. It is also somewhat surreal that I’m back in the Security Business Unit some 15 years later. As Steven Wright says, ‘Right now I'm having amnesia and deja vu at the same time. I think I've forgotten this before.’ And my current boss Kristen Grant has been a wonderful manager.

While I’ve been spewing my F5 15, what you might not know is that my wife Judy & I’s 15-year wedding anniversary is also this month. We got married June 15, 2004, and as I mentioned at the top, 5 days later on June 20, 2004 I flew from Honolulu to San Jose and June 21, I flew to Seattle for my first day at F5. Judy stayed in Hawaii for the next month packing up our stuff and shipping it to SJC.

Last week I was in Seattle for our Global Services Tech Summit. In honor of both 15’s, I had this crazy idea to renew our vows (to my wife’s surprise) in the new F5 Tower to celebrate both. With the help of some great folks in Corp Ops, Internal Comms and of course Ken Salchow officiating, we pulled it off. F5 helped arrange a spot on the 33rd floor Hub overlooking Puget Sound for our Vow Renewal. What an incredible experience being able to celebrate our milestone(s) with the company that’s been part of our ‘ohana for 15 years.

I’ve been so fortunate to have worked with lots of special people, many now close friends. Like Cecile DeLeon, Jacque Allison & Cindy Borovick. Had to include them.

Lucky to have been able to travel and experience Tokyo, London, Barcelona, Vienna, Singapore, Shanghai, Paris, Rome, Edinburgh and of course, Seattle.  

Thankful for a fantastic career, thus far, with an amazing company.

I’m thrilled and humbled to say, I made it 15 years. 



Next goal: 20

ps

Wednesday, May 29, 2019

90 Seconds of Security: In the Wild Malware for April 2019

A 90 second recap of 'In the Wild' Vulnerabilities, Exploits, and Malware Driving Attack Campaigns in April 2019.

Get the details at: https://www.f5.com/labs/articles/threat-intelligence/vulnerabilities--exploits--and-malware-driving-attack-campaigns-in-april-2019




ps

Thursday, January 3, 2019

SSL Visibility with SSL Orchestrator

Are You Equipped to Decrypt?

Over 80% of page loads are encrypted with SSL/TLS and Attackers commonly use encryption to hide malicious payloads. If you’re not inspecting SSL/TLS traffic, you will miss attacks, and leave your organization vulnerable. I light up how SSL Orchestrator provides robust decryption/encryption of SSL/TLS traffic.



ps

Friday, September 21, 2018

Me:Recently

(Or, How I Mandela’d Myself Back into a Job)

Almost every week for over a decade, I’d tap some words out on a keyboard and push the story out for folks to read. And much to my glee, you did engage, share, comment and seemed to genuinely enjoy what I had to say. I wrote about technology topics like information security, IoT, mobile, access, high availability, application delivery and many others tied to my job at F5. I shared my life experiences like my daughter’s rare genetic disorder (HI/HA GDH), getting lost in Italy or certain milestones in my existence. I’ve also reported on societal topics like identity theft, regulations, social engineering and the still popular, ‘Does Social Media Reflect Society?’ I also produced and published hundreds of videos covering some of the same technology topics since I really enjoy that medium.

A time where I could share my areas of interest and you would return for more every week. It was a wonderful relationship and I was very grateful for the opportunity to expand my creative energy. As the audience grew, I felt even more compelled to keep the consistent cadence of material since it was readily consumed.

That exchange abruptly ended two months ago in the last week of July and I’m sorry to have recently disappeared.

But there is a happy ending.

I happened to get caught up in a ‘reduction of workforce’ situation but had the opportunity to potentially secure another open position. I figured I’d at least give that a go since I truly enjoyed the company, people and believed in the services we offer. Plus, I was dreading having to make a potential two-hour commute in each direction, each day to get to an office. I’ve been a remote employee for almost a decade, but I would have of course, if it came down to that. However, I wanted to avoid that nightmare.

And, I believed and visualized in my mind that it would work out. This is important.

That Wednesday night my wife and I went through the typical shock mumbling things like, ‘What are we gonna do,’ ‘Are we going to be fine,’ and ‘What about insurance,’ among many others. We also poured out, ‘We’re gonna be ok,’ ‘Things will work out,’ ‘Everything happens for a reason,’ and so forth.

I’m one of those people who believe in the Law of Attraction and the notion that if you visualize, feel the good energy and put it out there, it happens. Whether through prayer, meditation, chanting, etc, you can make your future. There are many of those inspirational quotes about making it happen. Emerson said, ‘Once you make a decision, the universe conspires to make it happen.’ Michael Jordan noted, ‘Some people want it to happen, some wish it would happen, others make it happen.’ Eckhart Tolle said, ‘You are the universe becoming conscious of itself.’ Hiro Boga said, Immerse yourself in the energy of what you desire.’ And of course, Buddha taught, ‘The mind is everything. What you think, you become.’

I lamented that evening that since I believed in the ‘make it happen’ routine, that maybe, I had done it to myself. If I truly lived by that code, then I can’t just choose to accept the good things that occur…I must also concede to some of the bad stuff too. I admitted to my wife that recently I hadn’t really felt as secure as I should and had worried that something could happen. Not due to poor performance but more along the lines of, ‘Geeze, what would I do if I lost my job?’ Or, ‘Wow, I’m so fortunate to have what I have cuz I’d hate to be doing, whatever it was that I was looking at, at the time.’ Typical, normal human anxiety thoughts...or maybe I was receiving advanced notice. I’d even shoo those thoughts away when worrying saying, ‘Knock it off - if you keep thinking that, then it’ll happen!
I told my wife, ‘Well, I’ll just have to Mandela myself back into a job,’ and I fell asleep chanting, ‘I’m gonna make it back,’ with the logo visualization in my mind.

For those wondering what ‘Mandela’ myself means. There’s a phenomenon called the Mandela Effect. It’s when a large swath of the population seem to remember something being a certain way, often different than what history indicates. It got the moniker from researcher Fiona Broome about her false memory of the death of South African leader Nelson Mandela when, in fact, he was still alive. She says, ‘The Mandela Effect is evidence that you may have experienced events from a different reality. Finding others with similar memories can affirm that.’ There are many, many examples of this from food items to car logos to TV shows to geography.

So, the idea was to change my history and make my future, harnessing the universe’s power, to get me back to the place I desired.

The next day, Thursday, I got up like any other day going through my normal routine. I wasn’t going to sit around and wait for something…or take my time to see what’s out there…I was going to make something happen. My early morning walk which includes some chanting, mediation and praying allowed me to further send my intentions out. I envisioned myself back working with my colleagues and specifically thought about a certain Sr. Director that I might contact to see if he had any headcount. I’ve known and worked with this person for years but never side-by-side. And I will admit that we’ve had some philosophical differences over the years, but our discussions were always respectful, pleasant and we walked away with a better understanding of each other. I always knew it wasn't personal and we were both coming from a place of passion for the good of all. During that morning walk, I really pushed my energies to be able to connect since my job that day, was to find a job.

Many folks who face and have faced this same dilemma talk about relaxing a bit, taking your time to find what’s out there, maybe even change careers completely or start their own business. That new doors open when others shut and most times, it’s for the better. I agree wholeheartedly with that yet my situation is a bit different and I really didn’t have the luxury to ‘find myself’ over the course of six months. You may be aware that my daughter has a rare genetic disorder and medical insurance is a critical part of her survival. Cobra is nuts expensive and I would have had to apply to keep her around. I would have done whatever was necessary to keep my family safe and had a little time to figure it out but for me personally, I needed to jump on finding something without delay.
I prepared my resume, which after working for the same company for 14 years was a bit daunting. Like, what do resumes look like these days? There had to have been some improvement or advances over the last decade. There’s that but also, how do I capture my accomplishments over that time? Honestly, I used my LinkedIn profile. I had updated it over the years as my positions changed and it included the info I needed.

That day I also started messaging/emailing/contacting many friends, both internal and external, to let them know I was seeking employment. We all make a lot of friends over the course of our career and studies suggest that those relationships can help with new opportunities. Plus, I’d like to think that they know my skills, knowledge and ability to help similar organizations.

And all the while that day I was chanting, ‘Like a fuckin’ phoenix rising from the ashes…’ I also started to put out there, ‘Wouldn’t be cool if I could secure something by the end of the week!’ Over and over.

That first day I applied to a couple internal positions and a few external. I used the entire day to see what’s out there, get the word out, prepare my resume and…keep the faith. I felt I had a productive day until later in the afternoon when I explained to my daughter the impact of this. ‘You know Daddy lost his job yesterday.’ With the innocence of a 12-year-old she asks, ‘So how are you gonna get it back?’ ‘I don’t know…I’ll try for something else with the same company or I’ll need to find something with another company, but we’ll be OK,’ I said hoping to dampen any anxiety on her part. She then told me that I needed to make sure I didn’t have to go to an office every day, so I could still drop her off at school, which I’ve been doing since pre-school. I replied that I hoped it would still be that way, but I’d needed to go where my work takes me.

The one thing I didn’t do that day is contact the Sr. Director I was thinking about earlier that morning, but I did feel, as mentioned earlier, that I had a productive day so let that percolate and see what happens.

The next day, Friday, we had to be in LA for some personal stuff related to our civil matter. Around 1:00 PM out of the blue, I get a text from that Sr. Director that I’d been thinking about. Holy Shit. He asks if I had some time to chat after 3:00p that day and I’m like, ‘Sure!’ I got nothing going on.
My phone rings around 2:00p and since we’re in the car heading home, I quickly find a place to park to take the call. He says he just heard what happened and that he has an open headcount but for first quarter. AND, he thinks I’m perfect for the role! There were still some departmental, procedural and other hurdles but that he was going to do whatever it takes to ensure it gets done within my grace period, so I can keep continuous employment…but to relax and know there something there for me.
I’m stunned.

With tears welling my eyes I tell him, ‘Dude, you’re gonna save my ass!’ He replies, ‘No, you’ve been a top performer for years and I can’t wait to have you on the team.’ I look at the clock in the car and say, ‘You know, it’s been almost exactly 48 hours since I got the call about the separation. You have no idea how thankful I am!’ We talk a bit more about the role and what needs to happen but by the end we had a verbal pinky shake. To my amazement, he even followed up with a summary text of what we discussed! I’m blown away both by the opportunity and the fact that he put it in writing. This guy is sticking his neck out to help me. I had to pull over again to read it and gather my excitement.

I turn to my daughter and say, ‘I got my job back!’ Didn’t matter that it was slightly different, but the fact that I was able to return to the company and people that I’ve loved for almost 15 years was incredible. In a position that is somewhat of a homecoming for me. Within 46 hours of being cut and before the week was over, it happened exactly as I asked, up to and including the specific Manager.
I was part of the original Security Business Unit at F5 back in 2004 as one of the original Security Solution Architects positioning F5 as a security company with FirePass (SSLVPN that became BIG-IP APM) & TrafficShield (WAF that became BIG-IP ASM). During this time, I was part of a handful of people sharing F5's first security story. I was giddy that after all this time, I’d be able to return to my roots of evangelizing the benefits of our security solutions.

I couldn’t stop smiling on the way home and immersed in the notion that I set it motion, including the individual, just a couple days earlier. Speechless.

I slept better than I had in months that night. Security is also peace of mind.

Saturday rolls around and you know the routine, did that really happen? YES! It did. Of course, I thought that it could fall through but kept going back to that text he sent and pushed that out to make sure the events would follow.

Over the course of the next few weeks he kept in constant contact, even touching base just to see how things were and to make certain, insisting in fact, that I was taking the time to relax so I’m fresh when I start. I can’t say enough about him and he followed through – above and beyond - on everything.

A couple weeks after the initial contact I signed my offer letter and officially started up again, this time doing Security Marketing and am thrilled to join such an amazing team.

And too, this break was a blessing in disguise. I had the time to focus on some family matters and take care of some things that I probably wouldn’t have been able to; I got to relax on Tuesday mornings while the rest of you labored (Ha!); I got to spend more time with my wife and kid as summer vacation was winding down; I was secure knowing a job was waiting for me; and it reinforced, for me, that you really can change your path with your thoughts and energy. With a little help, of course.

So that’s what’s been going on. Sorry I’ve been away but soon I’ll be back to my regular cadence and hope you continue to follow. I delayed writing this and debated posting it but thought that probably 98% of us will go through something similar and if my experience helps, no shame. In fact, I’m quite proud and somewhat astonished that it happened like this.

Oh, and that Sr. Director who pulled me from the ashes? Preston Hogue. A person with a heart of gold, impressive security knowledge, great sense of humor and a man of his word. Thank you, Preston, for the warm welcome.

And for those who might be in the same situation: Seriously - see it, feel it, believe it.

It will happen.

ps

Wednesday, January 10, 2018

The DevCentral Chronicles Volume 1, Issue 1

Welcome to 2018! If the kids in the back seat have been chanting, ‘Are we there yet?, Are we there yet?’ you can tell them, ‘Yes! Now, Get out the car!

If, like me, you’ve taken a couple weeks off to enjoy the holidays and New Year, you might be wondering where to start again or what to catch up on. Let me help you.

First, the biggest ‘industry’ news so far in this early 2018 has got to be the Spectre and Meltdown vulnerabilities found in computer processors and affects almost every chip (mostly Intel) in the world. From operating systems to chip makers to cloud providers, there’s been a massive effort to get the word out and patch things up. Want to understand the situation better? Check out John Wagnon’s Lightboard Lesson Explaining the Spectre and Meltdown Vulnerabilities. And probably one of the best tweets about the vulnerabilities comes from @infosecgoon


According to F5’s David Holmes, Everything old is new again in 2018. And in Return of Bleichenbacher - the ROBOT Attack CVE-2017-6168, David explains the attack, how it affects BIG-IP, how to tell if you are vulnerable and how to mitigate. So, what is the real impact of ROBOT? David notes that the Bleichenbacher attack only affects RSA sessions not protected with the ephemeral keys offered by forward secrecy. All modern browsers and mobile clients have preferred ephemeral keys for several years.

As more organizations migrate to the cloud – a hybrid one at that - in 2018, you’ll want to bookmark Chase Abbott’s Welcome to the F5 BIG-IP Migration Assistant. The F5® BIG-IP® Migration Assistant is a tool freely distributed by F5 to facilitate migrating BIG-IP configurations between different platforms. You can use Migration Assistant when you have an existing BIG-IP instance and you want to replace the current hardware with new hardware. Chase gives a great overview of the tool including What can go wrong. Lots of engaging comments on this one and Chase always tells it like it is!

Lastly, as we open 2018, DevCentral wants to recognize our 2017 MVPs! The DevCentral MVP Program shines a spotlight on the best, brightest and most active members of our community. We got some new contributors mixed with some old favorites and they are always willing to help with expertise, examples and war stories. Many of the new faces were Featured Members last year so check out their stories like December's Kevin Davies.

We got a lot coming in 2018 including more #Basics, Lightboards, Posts of the Week, articles and our always active Q/A forums and Code Share. If you’re a DevCentral member, we appreciate the contributions, if not a DevCentral member, sign up and join one of the most active communities in tech.

Welcome to the DC Chronicles and btw, 2018 will be the Year of the Dog, in case you were wondering.


ps

Friday, December 29, 2017

Blog Roll 2017

It’s that time of year when we gift and re-gift, just like this text from last year. And the perfect opportunity to re-post, re-purpose and re-use all my 2017 entries.

If you missed any of the 64 attempts including 16 videos, here they are wrapped in one simple entry. I read somewhere that lists in articles are good. I broke it out by month to see what was happening at the time and let's be honest, pure self-promotion. Check out our Featured Members for the year, dig into June's Cloud Month, catch up on some #Basics or sit back and watch some cool Lightboard videos.

I truly appreciate your engagement throughout 2017 and Have a Safe and Happy New Year!

​​​January 2017
February
March
April
May
June
July
August
September
October
November
December
ps

The History

Tuesday, April 25, 2017

Configure HA Groups on BIG-IP

Last week we talked about how HA Groups work on BIG-IP and this week we’ll look at how to configure HA Groups on BIG-IP.

To recap, an HA group is a configuration object you create and assign to a traffic group for devices in a device group. An HA group defines health criteria for a resource (such as an application server pool) that the traffic group uses. With an HA group, the BIG-IP system can decide whether to keep a traffic group active on its current device or fail over the traffic group to another device when resources such as pool members fall below a certain level.

First, some prerequisites:
  • Basic Setup: Each BIG-IP (v13) is licensed, provisioned and configured to run BIG-IP LTM
  • HA Configuration: All BIG-IP devices are members of a sync-failover device group and synced
  • Each BIG-IP has a unique virtual server with a unique server pool assigned to it
  • All virtual addresses are associated with traffic-group-1
To the BIG-IP GUI!

First you go to System>High Availability>HA Group List>and then click the Create button.
The first thing is to name the group. Give it a detailed name to indicate the object group type, the device it pertains to and the traffic group it pertains to. In this case, we’ll call it ‘ha_group_deviceA_tg1.’
Next, we’ll click Add in the Pools area under Health Conditions and add the pool for BIG-IP A to the HA Group which we’ve already created. We then move on to the minimum member count. The minimum member count is members that need to be up for traffic-group-1 to remain active on BIG-IP A. In this case, we want 3 out of 4 members to be up. If that number falls below 3, the BIG-IP will automatically fail the traffic group over to another device in the device group.
Next is HA Score and this is the sufficient threshold which is the number of up pool members you want to represent a full health score. In this case, we’ll choose 4. So if 4 pool members are up then it is considered to have a full health score. If fewer than 4 members are up, then this health score would be lower. We’ll give it a default weight of 10 since 10 represents the full HA score for BIG-IP A. We’re going to say that all 4 members need to be active in the group in order for BIG-IP to give BIG-IP A an HA score of 10. And we click Add.
We’ll then see a summary of the health conditions we just specified including the minimum member count and sufficient member count. Then click Create HA Group.
Next, we go to Device Management>Traffic Groups>and click on traffic-group-1.
Now, we’ll associate this new HA Group with traffic-group-1. Go to the HA Group setting and select the new HA Group from the drop-down list. And then select the Failover Method to Device with the Best HA Score. Click Save.
Now we do the same thing for BIG-IP B. So again, go to System>High Availability>HA Group List>and then click the Create button. Give it a special name, click Add in the Pools area and select the pool you’ve already created for BIG-IP B. Again, for our situation, we’ll specify a minimum of 3 members to be up if traffic-group-1 is active on BIG-IP B. This minimum number does not have to be the same as the other HA Group, but it is for this example. Again, a default weight of 10 in the HA Score for all pool members. Click Add and then Create HA Group for BIG-IP B.
And then, Device Management>Traffic Groups> and click traffic-group-1. Choose BIG-IP B’s HA Group and select the same Failover method as BIG-IP A – Based on HA Score. Click Save.
Lastly, you would create another HA Group on BIG-IP C as we’ve done on BIG-IP A and BIG-IP B. Once that happens, you’ll have the same set up as this:
As you can see, BIG-IP A has lost another pool member causing traffic-group-1 to failover and the BIG-IP software has chosen BIG-IP C as the next active device to host the traffic group because BIG-IP C has the highest HA Score based on the health of its pool.

Thanks to our TechPubs group for the basis of this article and check out a video demo here.

ps

Wednesday, April 19, 2017

Lightboard Lessons: The BIG-IP Profiles

BIG-IP can manage application-specific network traffic in a variety of ways, depending on the protocols and services being used. On BIG-IP, Profiles are a set of tools that you can use to intelligently control the behavior of that traffic.

In this Lightboard Lesson, I light up the BIG-IP Profiles. What they are, what they do and why you should care.



ps

Related:

Tuesday, April 4, 2017

Q/A with Betsson's Patrik Jonsson - DevCentral's Featured Member for April

Patrik Jonsson lives in Stockholm with his wife and son and works as a network engineer for a company providing online casino games across the world.

Outside work, he likes to spend time with his family, play around with his home VMware lab and enjoys watching movies. He also loves travelling and having a beer with friends.

Patrik is also a 2017 DevCentral MVP and DevCentral’s Featured Member for April! DevCentral got a chance to talk with Patrik about his work, life and his project the BIG-IP Report.

DevCentral: You’ve been a very active contributor to the DevCentral community and wondered what keeps you involved?
Patrik: One of the best, and fun ways to learn new things is to take on problems, or discussions presented by fellow technicians. It forces you to continuously challenge what you think you know and keeps your knowledge up to date. In addition, when I need input, or help myself, DevCentral has so many brilliant and helpful members ready to take on whatever you throw at them.
DC: Tell us a little about the areas of BIG-IP expertise you have.
PJ: The first time I ran into a BIG-IP was just after I graduated from university. It was a 1000 series running BIG-IP v4. When I quit that job 6 years later I considered asking to bring it home with me, but somehow my girlfriend at the time was not as keen to the idea. Still don’t know why. :-) 
I’ve been working mostly with BIG-IP LTM and iControl, but recently I’ve started to dabble a bit with APM, GTM/DNS and ASM as well.
DC: You are a Network Security Specialist at Betsson. Can you describe your typical workday?
PJ: At Betsson you never know what’s going to happen when you step into the office. The gaming industry has very tough competition and getting comfortable as one of the bigger players around is not an option since rivals are always ready to take your place. This, combined with awesome colleagues, makes it a joy to step into the office every morning.
DC: Describe one of your biggest BIG-IP challenges and how DevCentral helped in that situation.
PJ: Being a multinational company with offices supporting multiple brands, one of the biggest challenges we have is knowledge sharing. Giving the developers the correct information when they need it is vital for an efficient application delivery. In order to provide this, we have used iRules to present troubleshooting information in the form of custom headers so developers can see which pool and member that responded to their request and the current status of all members. We also have a smarter version of the traditional sorry page which shows information about the failed pool and what’s being monitored. And then of course, BIG-IP Report
All of these are using iRules and iControl and would not have been possible without the DevCentral API documentation and of course, my hero Joe Pruitt.
DC: What can readers learn from your blog: https://loadbalancing.se/ and what is the BIG-IP Report?
PJ: My blog is where I post ideas and projects that I have. There’s a BIG-IP APM + Google Authenticator guide, F5 Web UI augmentation script for version 11 and a few other things. 
BIG-IP Report was born out of a need to show people the load balancing configuration in a simple manner without giving them access to the BIG-IP interface. After implementing it we have gone from developers asking us where things are, to instead them telling us about bad configuration. We also discovered that it is awesome for us as well, as we can get an overview of the configuration across multiple devices. Finding a specific VIP, or pool is so much easier when the information is in one place. 
I guess the best way to understand it is to try it at http://loadbalancing.se/bigipreportdemo/ 
The blog is not updated that often, so it’s safe to subscribe without getting too much spam.
DC: Lastly, if you weren’t an IT admin – what would be your dream job? Or better, when you were a kid – what did you want to be when you grew up?
PJ: I think my dream would be working with a non-profit organization helping people in need. I love travelling and combining that with something meaningful would be really nice.

Thanks Patrik! Check out all of Patrik’s DevCentral contributions, check out his blog, or connect on LinkedIn. And visit Betsson on the web or follow on Twitter.

Wednesday, March 15, 2017

Lightboard Lessons: What is a Proxy?

The term ‘Proxy’ is a contraction that comes from the middle English word procuracy, a legal term meaning to act on behalf of another.

In networking and web traffic, a proxy is a device or server that acts on behalf of other devices. It sits between two entities and performs a service. Proxies are hardware or software solutions that sit between the client and the server and do something to requests and sometimes responses.

In this Lightboard Lesson, I light up the various types of proxies.



ps

Related:

Wednesday, February 8, 2017

Lightboard Lessons: IoT on BIG-IP

As more organizations deploy IoT applications in their data centers and clouds, they're going to need their ADC to understand the unique protocols these devices use to communicate.

In this Lightboard Lesson, I light up how IoT protocol MQTT (Message Queuing Telemetry Transport) works on BIG-IP v13. iRules allow you to do Topic based load balancing along with sensor authentication. And if you missed it, here is the #LBL on What is MQTT?



ps

Related:

Thursday, February 2, 2017

What is DNS?



What is the Domain Name System (DNS)?

Imagine how difficult it would be to use the Internet if you had to remember dozens of number combinations to do anything. The Domain Name System (DNS) was created in 1983 to enable humans to easily identify all the computers, services, and resources connected to the Internet by name—instead of by Internet Protocol (IP) address, an increasingly difficult-to-memorize string of information. Think of all the website domain names you know off the top of your head and how hard it would be to memorize specific IP addresses for all those domain names. Think of DNS as the Internet's phone book. A DNS server translates the domain names you type into a browser, like www.f5.com, into an IP address (104.219.105.148), which allows your device to find the resource you're looking for on the Internet.

DNS is a hierarchical distributed naming system for computers, services, or other resources connected to the Internet. It associates various information with domain names that are assigned to each of the participating DNS entries.

How DNS Works

The user types the address of the site (www.f5.com as an example) into the web browser. The browser has no clue where www.f5.com is, so it sends a request to the Local DNS Server (LDNS) to ask if it has a record for www.f5.com. If the LDNS does not have a record for that particular site, it begins a recursive search of the Internet domains to find out who owns www.f5.com.


First, the LDNS contacts one of the Root DNS Servers, and the Root Server responds by telling the LDNS to contact the .com DNS Server. The LDNS then asks the .com DNS Server if it has a record for www.f5.com, and the .com DNS Server determines the owner of www.f5.com and returns a Name Server (NS) record for f5.com. Check out the diagram below:


Next, the LDNS queries the f5.com DNS Server NS record. The f5.com DNS Server looks up the name: www.f5.com. If it finds the name, it returns an Address (A) record to the LDNS. The A record contains the name, IP address, and Time to Live (TTL). The TTL (measured in seconds) tells the LDNS how long to maintain the A record before it asks the f5.com DNS Server again.

When the LDNS receives the A record, it caches the IP address for the time specified in the TTL. Now that the LDNS had the A record for www.f5.com, it can answer future requests from its own cache rather than completing the entire recursive search again. LDNS returns the IP address of www.f5.com to the host computer, and the local browser caches the IP address on the computer for the time specified in the TTL. After all, if it can hold on to the info locally, it won't need to keep asking the LDNS.


The browser then uses the IP address to open a connection to www.f5.com:80 and sends a GET /... and the web server returns the web page response.


DNS can get a lot more complicated than what this simple example shows, but this gives you an idea of how it works.

DNS Importance

As arguably the primary technology enabling the Internet, DNS is also one of the most important components in networking infrastructure. In addition to delivering content and applications, DNS also manages a distributed and redundant architecture to ensure high availability and quality user response time—so it is critical to have an available, intelligent, secure, and scalable DNS infrastructure. If DNS fails, most web applications will fail to function properly. And DNS is a prime target for attack.

The importance of a strong DNS foundation cannot be overstated. Without one, your customers may not be able to access your content and applications when they want to—and if they can't get what they want from you, they'll likely turn elsewhere.

Growing Pains

DNS is growing especially with mobile apps and IoT devices requiring name resolution.  Add to that, organizations are experiencing rapid growth in terms of applications as well as the volume of traffic accessing those applications.

In the last five years, the volume of DNS queries on for .com and .net addresses has more than doubled. More than 10 million domain names were added to the Internet in 2016 and future growth is expected to occur at an even faster pace as more cloud, mobile and IoT implementations are deployed.

Security Issues

If DNS is the backbone of the Internet—answering all the queries and resolving all the numbers so you can find your favorite sites—it is also one of the most vulnerable points in your network. Due to the crucial role it plays, DNS is a high-value security target. DNS DDoS attacks can flood your DNS servers to the point of failure or hijack the request and redirect requests to a malicious server. To prevent this, a distributed high-performing, secure DNS architecture and DNS offload capabilities must be integrated into the network.

Generally, DNS servers and DNS cloud services can handle varying amounts of requests per second with the costs increasing as the queries-per-second increase.

To address DNS surges and DNS DDoS attacks, companies add more DNS servers, which are not really needed during normal business operations. This costly solution also often requires manual intervention for changes. In addition, traditional DNS servers require frequent maintenance and patching, primarily for new vulnerabilities.

The Traditional Solution

When looking for DNS solutions, many organizations select BIND (Berkeley Internet Naming Daemon), the Internet's original DNS resolver. Installed on approximately 80 percent of the world's DNS servers, BIND is an open-source project maintained by Internet Systems Consortium (ISC).

Despite its popularity, BIND requires significant maintenance multiple times a year primarily due to vulnerabilities, patches, and upgrades. It can be downloaded freely, but needs servers (an additional cost, including support contracts) and an operating system. In addition, BIND typically scales to only 50,000 responses per second (RPS), making it vulnerable to both legitimate and malicious DNS surges.

Next Step

If you're ready to learn more or dig deeper into DNS, check out these more advanced articles
  • DNS - DevCentral Wiki
  • Application Layer DNS Firewall
  • Lightboard Lessons: DNS Scalability & Security
  • DNS Express and Zone Transfers

  • DNS Does the Job