<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Creeva&#039;s World 2.0 &#187; Symantec</title>
	<atom:link href="http://creeva.com/tag/symantec/feed/" rel="self" type="application/rss+xml" />
	<link>http://creeva.com</link>
	<description>My life unfolding and being told online - 1 byte of information at a time.</description>
	<lastBuildDate>Thu, 09 Feb 2012 18:30:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Things You Should Be Able To Answer When Contacting A Consultant</title>
		<link>http://creeva.com/2009/02/10/things-you-should-be-able-before-to-answer-contacting-a-consultant/</link>
		<comments>http://creeva.com/2009/02/10/things-you-should-be-able-before-to-answer-contacting-a-consultant/#comments</comments>
		<pubDate>Tue, 10 Feb 2009 11:37:59 +0000</pubDate>
		<dc:creator>Creeva</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Band]]></category>
		<category><![CDATA[Consultant]]></category>
		<category><![CDATA[design]]></category>
		<category><![CDATA[e-mail]]></category>
		<category><![CDATA[Environment]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[I want]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[NES]]></category>
		<category><![CDATA[Picture]]></category>
		<category><![CDATA[Sad]]></category>
		<category><![CDATA[Symantec]]></category>

		<guid isPermaLink="false">http://creeva.com/?p=4172</guid>
		<description><![CDATA[Someone I know came to me the other day about a consulting project that may or may not happen.   What essentially he wants done is an overhaul of IT infrastructure.   They want more automation to their operation and they deal with physical goods.  So from receiving to shipping, to everything in between they are looking [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="aligncenter" src="http://farm4.static.flickr.com/3223/2997832101_46b5e3f5aa.jpg?v=0" alt="" width="500" height="353" /></p>
<p style="text-align: center;">
<p style="text-align: left;">Someone I know came to me the other day about a consulting project that may or may not happen.   What essentially he wants done is an overhaul of IT infrastructure.   They want more automation to their operation and they deal with physical goods.  So from receiving to shipping, to everything in between they are looking to streamline.    They want to do more with less, less equipment if possible, less people if possible, less stress if possible.   In other words they want what every other company in the world wants.</p>
<p style="text-align: left;">Currently they have a software package that does some of this, but it doesn&#8217;t do everything they want it to be able to do.   I don&#8217;t have implicit knowledge of the package, other then I&#8217;ve created firewall rules when I was consulting with Symantec to pass the traffic.   So my first question is the scope of the project.   The person I was talking to didn&#8217;t exactly no what I meant by that.   They were more worried about the big picture ideal instead of what a consultant would need to work with.  A vision of the end goal is great, but without specific tasks to get there it definitely puts an implementer at a disadvantage.   He stated that we would have to do a sit down and discuss the issue and layout of the business process.   This is a good step, but part of why I&#8217;m writing this is to help others know the answer they should have when going into something of this magnitude.</p>
<p style="text-align: left;"><span style="text-decoration: underline;"><strong>Easy, Hard and Correct</strong></span></p>
<p style="text-align: left;">The first question is why do you want to do this?  There are easy answers, there are hard answers, and there is correct answers to this question.    Some of the easy answers include &#8211; I want everything to work together better, we want to build to the future, and I have to spend my budget before the end of the fiscal cycle and want to try out this product.    Hard answers include we want something more manageable for our IT staff, we want it to run faster in our environment, we want something we can understand.</p>
<p style="text-align: left;">There are reasons that these are the easy answers and hard answers.  The first and foremost thought is to remember to sit down with a consultant or someone who understands the technology thoroughly enough before ever sitting down with a salesperson.   To sales people, these are all easy and correct answers.   They will tell you your toast can be used to transport computer network traffic with the right purchase, they are there to get your money.  It&#8217;s the one reason I can never be a salesperson.  I like people using the correct solution, not necessarily the solution that I am selling.   Even when I worked at Symantec, I knew Symantec products were not the best products for all customers.   Some customers only changed products because they had money to spend and ended up worse off for it.    Salespeople are tricky creatures that guard their bonuses like Disney guards it&#8217;s copyrights.</p>
<p style="text-align: left;">Easy answers are normally very vague,  they tell a salesperson of consultant that you haven&#8217;t really though to much about the problem.  You have a basic idea of what you want, but you don&#8217;t know any specifics.  The problem with the easy answers is that they are also the most expensive answers &#8211; this allows those that are implementing something to sell you what they think is best, regardless of how it will fit into your business six months down the road when they are gone.  You will have to make some decisions on your own, and this should not be listening to the best sales pitch from two competing vendors.  The best sales pitch does not necessarily equate into the best product.</p>
<p style="text-align: left;">Why are the hard answers difficult?  What that&#8217;s because everything is relative.   Going back to my examples can show you this.  We want something more manageable by our IT staff, well how trained is your IT staff?   Do your employees know alternative operating systems?  Does your staff only run Microsoft products?  Is this faster for your environment?  What about a year down the road and the nightmare efficient system breaks because of infrastructure changes you were forced to make?  Everything comes down to you knowing your environment and your plans for the future.   A consultant only gets a glimpse of time into your configuration and is not going to be the full time employee running this stuff.   They won&#8217;t know how your future plans could be effected if you don&#8217;t tell them your future plans.</p>
<p style="text-align: left;">The correct answer?  That include being as specific as possible.  Let&#8217;s say this is to implement an Exchange Server migrating from a Lotus Notes architecture.   Why would I want to do this?   Lotus Notes has been long in the process of being a headache for us.   The administrator that runs it is retiring in six months and we have other employees that could scale up quicker to learn  Exchange then Lotus Notes.   The collaborative features in exchange work in Outlook, which our company already loads on all the desktop since we have a full Microsoft Office License on all of the desktops.  About 30% of our users already use outlook to retrieve their e-mail, even though they all have the Notes client installed on their desktops also.   Being able to consolidate this would save us thousands a year since we would no longer need a support contract or license fees paid to IBM to support the old Lotus infrastructure.    The more complete and specific the answer, the better the consultant can answer your questions.</p>
<p style="text-align: left;"><span style="text-decoration: underline;"><strong>Do You Listen To Alternatives?</strong></span></p>
<p style="text-align: left;">Even in the Exchange scenario seems complete.  How rigid are you to suggestions?  What if the consultant offers up other alternatives such as a web based e-mail solution that would still allow Exchange to connect and retrieve e-mail? While a Linux/Apache approach may be cheaper, you could also implement it on top of IIS.   Building with some other technologies you could gain all the collaborative powers of Exchange for thousands of dollars less.   Those who didn&#8217;t want to use Outlook could use a browser.  If you combine this with a secure remote access solution this would allow for a possible quicker and less bandwidth connection for telecommuters if that is where your company is going.</p>
<p style="text-align: left;">Knowing what your plans and how rigid they need to be help a consultant decide what avenues may be the best approach for you.  While I offered up a free solution, another consultant may offer ways to augment your current Notes infrastructure to fit your needs.  The best consultants will offer alternatives to your current line of thinking.   You do not have to listen to them, you can stay focused, but hearing how open you are is important.</p>
<p style="text-align: left;">
<p style="text-align: left;"><span style="text-decoration: underline;"><strong>Timeline</strong></span></p>
<p style="text-align: left;">A timeline is something you should have in mind sitting down with the consultant.  He needs to know deadlines and what your expectations are.   Does this need to be done in a week or a year?  How are your current employees going to ramp up on the new solution?  While a consultant may reset your timelines to something more realistic, knowing what type of time frame you are trying to achieve is important to the success of the project.   It also tells the consultant if they are going ot need to bring in more outside help.</p>
<p style="text-align: left;">
<p style="text-align: left;"><span style="text-decoration: underline;"><strong>Breakdown of Tasks</strong></span></p>
<p style="text-align: left;">Have you compartmentalized your tasks?  The person that contacted me was looking for a complete end to end solution, is this what best?   In a solution like that how are you going to handle the transition time?   You don&#8217;t want to migrate the whole solution at the touch of a button, since any big architecture change can effect your business continuity.  For some businesses any downtime at all is lost revenue.   A consultant wants to make this impact as minimal as possible.   Even when you do the best planning and compartmentalizing sometimes you will get stuck on a twenty-three hour conference call working through the issues of down time.   When this happens I can tell you it&#8217;s not fun.  That was also with a staged migration.</p>
<p style="text-align: left;">What segments of your business can be down for hours at a time?   When you can answer that you can start staging your tasks.  The tasks that can be down the longest generally should be the first ones migrated, since they should give you expectations for later tasks, and allow you to plan accordingly.   Do not re-architect the design so the whole system (no matter how small) to be done in one night if there are multiple groups effected in the transition.   Design the impact to be as small as possible.   Yes, this may increase time &#8211; which in turn increases expense, but without proper planning it may cost you more in the long run.</p>
<p style="text-align: left;">
<p style="text-align: left;"><span style="text-decoration: underline;"><strong>Cost</strong></span></p>
<p style="text-align: left;">The question that no likes asking or giving, what is your budget for this task.  You can wait for the consultant to make a cost estimate pitch first if you like &#8211; but at some point in the conversation cost is going to come up.   Do your homework ahead of time to see how much you expect it to cost and budget accordingly.   What are you going to do if things go over budget?  If your three quarters way through a project and haev no more money to finish it, how is that going to impact you?</p>
<p style="text-align: left;"><span style="text-decoration: underline;"><strong>In Closing</strong></span></p>
<p style="text-align: left;">This may seem like a list of things that I want as a consultant.   These are however fairly common truths on what a consultant needs to start a project properly instead of spinning their wheels.   In the next week or so I&#8217;m going to follow this up with how to spot a good consultant versus a bad one.</p>
<p style="text-align: left;">
<p style="text-align: left;">
<p style="text-align: left;">
]]></content:encoded>
			<wfw:commentRss>http://creeva.com/2009/02/10/things-you-should-be-able-before-to-answer-contacting-a-consultant/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Money Isn&#8217;t Everything</title>
		<link>http://creeva.com/2008/12/23/money-isnt-everything/</link>
		<comments>http://creeva.com/2008/12/23/money-isnt-everything/#comments</comments>
		<pubDate>Tue, 23 Dec 2008 15:49:50 +0000</pubDate>
		<dc:creator>Creeva</dc:creator>
				<category><![CDATA[Personal Writing]]></category>
		<category><![CDATA[Band]]></category>
		<category><![CDATA[Environment]]></category>
		<category><![CDATA[Family]]></category>
		<category><![CDATA[Father]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[I want]]></category>
		<category><![CDATA[Lucky]]></category>
		<category><![CDATA[Music]]></category>
		<category><![CDATA[photos]]></category>
		<category><![CDATA[Picture]]></category>
		<category><![CDATA[Rant]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[Test]]></category>

		<guid isPermaLink="false">http://creeva.com/?p=3817</guid>
		<description><![CDATA[Picture from here Money isn&#8217;t everything.   We treat it like is though.   Some people can&#8217;t understand when I say I don&#8217;t necessarily want more though.   I of course do want more money, but at the same time I don&#8217;t.   What I truly want is more freedom, more time, and more enjoyment from what I do. [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="alignnone" src="http://farm2.static.flickr.com/1203/751221191_fdb8eae75c_m.jpg" alt="" width="240" height="240" /></p>
<p style="text-align: center;">Picture from <a href="http://flickr.com/photos/twcollins/751221191/">here</a></p>
<p>Money isn&#8217;t everything.   We treat it like is though.   Some people can&#8217;t understand when I say I don&#8217;t necessarily want more though.   I of course do want more money, but at the same time I don&#8217;t.   What I truly want is more freedom, more time, and more enjoyment from what I do.</p>
<p>I&#8217;ve had a couple jobs that I enjoyed more then anything else.   The first was working at a small PC shop.  It was my first break into the IT industry, in which I&#8217;ve done well climbing the ladder.   I interacted with people, I was a problem solver.  I was one of hte go to people that could fix almost anything.   I&#8217;m the type of guy that you throw problems at and I&#8217;ll swat them away like annoying insects.   It was my forte, the only thing I was really lacking at the time was high end networking.   I could make computers talk, but as I learned in my next favorite job I truly knew nothing.</p>
<p style="text-align: center;"><img class="aligncenter" src="http://farm4.static.flickr.com/3246/2948605423_2378a2baf2_m.jpg" alt="" width="240" height="86" /></p>
<p>The next job I can say now that I truly loved was working at Symantec&#8217;s enterprise firewall support call center.   Like the small PC shop after a year or so I came into my own and had my own groove.   After three years being on the team I had closed more tickets then anyone else in level one and level two support (I left being the team lead).    I also held the record for the most calls handled in one day.   The irony about having the most tickets closed is that 30-40% of the time I didn&#8217;t even open a ticket for the call.   Our call center software was so slow that it took 5-7 minutes to actually open and write up a ticket.  I made a deal with my managers (I&#8217;m sure some higher ups wouldn&#8217;t be happy) &#8211; that if I could handle the call in under five minutes and be almost positive that they wouldn&#8217;t be calling in on the same issue that I could just skip the ticket process.   So for volume, by the time I left I handled far above and beyond what everyone else had ever handled.    Symantec has since dicontinued the product, it lasted about another year and half after I migrated into consulting that it went kaput.  I wonder if anyone caught up to me in the call record or number of handled cases before it was gone.</p>
<p>This isn&#8217;t about bragging rights, I&#8217;m sure it sounds like it though.   What did both of these jobs have in common though?  They were both hectic chicken running with it&#8217;s head cut off problem squashing affairs.   I work best where I have a new issue every fifteen minutes or a nagging issue that would keep me up at night trying to solve.   As you move up the ladder you loose that.  You are working on long and engaging projects where the problem takes five minutes to engineer, yet in turn takes six months to implement.   I&#8217;m still good at what I do, but it&#8217;s not exactly the best fit for my skill set.   This in turn leads me into a spiral or more money versus more enjoyment.</p>
<p style="text-align: center;"><img class="alignnone" src="http://farm4.static.flickr.com/3248/2690000455_c05658f8d0.jpg?v=0" alt="" width="345" height="296" /></p>
<p style="text-align: center;">Me and my Grandfather (Not a Recent Picture)</p>
<p>I had a conversation with my grandfather a few weeks ago, he told me how lucky it was that I had a job in today&#8217;s economy (I am), and that it would be difficult to move up in the area I lived.  I started to explain to him that I could more then likely finding a better paying job, but it may not be as stable in the long term as my current one.   I also said for the right job I would work for less then I currently do.  Somehow in his mind that didn&#8217;t compute.   In an abstraction of what he said, essentially he thought climbing the ladder should be what is important.   I told him with the right job, I would take a 20% pay reduction.  Granted that wasn&#8217;t my end goal, but for the right job in the right environment I would take my family down to the bare level where we could maintain everything.   Why?  I would be happier.</p>
<p style="text-align: center;"><img class="aligncenter" src="http://farm4.static.flickr.com/3142/2997830657_e3bb05da77_m.jpg" alt="" width="240" height="202" /></p>
<p>We are taught early that you need to learn so you can better then&#8221;random example&#8221;.   So you can go to college and maintain that edge and not be a janitor.   So you can get the huge house and be better then your neighbors.   If you neighbor buys a Lexus you are taught that you should buy a BMW.  It&#8217;s a mad dash to prove that your better then everyone else.   To prove that capitalism runs the world.  If we are not working to that we are either considered un-American, stupid, or lazy.   Granted I am a bit lazy, but I can work.    I was born July 4, 1976 so I don&#8217;t consider myself un-American (I&#8217;m a Constitutionalist).   I&#8217;m not stupid either.</p>
<p>I think this mindset first hit my family when I wanted to go to college for music performance and creative writing.   They always said I wouldn&#8217;t make any money with that.  I was seventeen and brave enough to say that if I was happy I could be living on a street corner in a box as long I was writing and playing music.   They never understood that.  If I didn&#8217;t have my wife, and a love for electronics (I didn&#8217;t have that love back then), I could probably still do it.   My life hasn&#8217;t greatly changed at the core in the last decade though when I was first with my wife.   We live essentially the same way, we have a few nicer things, a house, a car payment &#8211; but our basic lives are still the same.  I&#8217;d say the greatest difference is that we can not stand hamburger helper anymore.   I still eat the occasional cheap ass boil it  ramen, and she enjoys Kraft Macaroni and Cheese still.</p>
<p>Too many people in this world work for money.   Money is needed to survive (I have a friend that would argue that), but at the same time it shouldn&#8217;t be your singular goal.   When I was younger I had a certain goal financially I wanted to make, I did through different means.   I&#8217;m not at that level right now (I have no stock options to sell anymore), but it didn&#8217;t make it me any happier.   These days I write more, I play in two bands, I&#8217;m learning new instruments, and I have a baby that should arrive in the next couple months.   I&#8217;m juggling the things that make me happy with work, what if I could be blissful with my job too?  Some days I hate my job, most the time I&#8217;m just meh.   If I could get the hair pulling problem solving hectic life going again it would be great (must be my undiagnosed ADD).  If I could do it at the same pay level or better, that would be awesome.</p>
<p style="text-align: center;"><img class="aligncenter" src="http://farm4.static.flickr.com/3063/2688352352_02992710b1.jpg?v=0" alt="" width="323" height="500" /></p>
<p style="text-align: center;">I really need to get some more recent pictures of myself</p>
]]></content:encoded>
			<wfw:commentRss>http://creeva.com/2008/12/23/money-isnt-everything/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Where Were You When Moments &#8211; My Answers</title>
		<link>http://creeva.com/2008/12/02/where-were-you-when-moments-my-answers/</link>
		<comments>http://creeva.com/2008/12/02/where-were-you-when-moments-my-answers/#comments</comments>
		<pubDate>Tue, 02 Dec 2008 19:21:43 +0000</pubDate>
		<dc:creator>Creeva</dc:creator>
				<category><![CDATA[Personal Writing]]></category>
		<category><![CDATA[Family]]></category>
		<category><![CDATA[Grandmother]]></category>
		<category><![CDATA[Hits]]></category>
		<category><![CDATA[I want]]></category>
		<category><![CDATA[Links]]></category>
		<category><![CDATA[LOL]]></category>
		<category><![CDATA[Mother]]></category>
		<category><![CDATA[Movie]]></category>
		<category><![CDATA[Music]]></category>
		<category><![CDATA[Oregon]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[photos]]></category>
		<category><![CDATA[Picture]]></category>
		<category><![CDATA[Rant]]></category>
		<category><![CDATA[Sad]]></category>
		<category><![CDATA[story]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[Test]]></category>
		<category><![CDATA[TV]]></category>
		<category><![CDATA[Video]]></category>
		<category><![CDATA[Xie]]></category>
		<category><![CDATA[youtube]]></category>

		<guid isPermaLink="false">http://creeva.com/?p=3749</guid>
		<description><![CDATA[Picture from here Yesterday on the radio they were ranking which was the most important moments in history in which you can remember what you were doing. I found the link to the quiz they were using, which was originally put up by Slate. While I do rememebr some of the events, others seem to [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="alignnone" src="http://farm4.static.flickr.com/3106/2377182628_69f693374b_m.jpg" alt="" width="240" height="180" /></p>
<p style="text-align: center;">Picture from <a href="http://www.flickr.com/photos/timcaynes/2377182628/">here</a></p>
<p>Yesterday on the radio they were ranking which was the most important moments in history in which you can remember what you were doing.   I found the <a href="http://www.slate.com/features/bracketologist/wherewere/index.html">link to the quiz they were using</a>, which was originally put up by <a href="http://slate.com">Slate</a>.  While I do rememebr some of the events, others seem to go by without notice.   I wanted to comment on the moments that happened within my lifetime.   At least it will give my future son an idea of what I thought about the events that we consider important in history.   This list is not in order of importance, it&#8217;s just the descending order in the slate list.</p>
<p><center><br />
<object type="application/x-shockwave-flash" width="425" height="344" data="http://www.youtube.com/v/s5JdY8ENfVg&amp;rel=0&amp;fs=1"><param name="movie" value="http://www.youtube.com/v/s5JdY8ENfVg&amp;rel=0&amp;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="wmode" value="transparent" /></object><br />
</center></p>
<p><a title="Berlin Wall" href="http://en.wikipedia.org/wiki/Berlin_Wall">Berlin Wall</a> comes tumbling down &#8211; I can&#8217;t say I truly remember the actual day the Berlin Wall fell down.  It was a vague thing, something that was expected for awhile that was built up over time.  I could be wrong on that.   The one thing I thought was kind of cool about this was the fact that at Higbee&#8217;s you could purchase pieces of the Berlin Wall in a sack.   These days that type of action would make me immensely sad, it&#8217;s a sign of America&#8217;s need to profit off of an event.   In retrospect how did we know that they were pieces of the actual wall?</p>
<p><center><br />
<object type="application/x-shockwave-flash" width="425" height="344" data="http://www.youtube.com/v/e2mgyCuLOlQ&amp;rel=0&amp;fs=1"><param name="movie" value="http://www.youtube.com/v/e2mgyCuLOlQ&amp;rel=0&amp;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="wmode" value="transparent" /></object><br />
</center></p>
<p><a title="Mount St. Helen" href="http://en.wikipedia.org/wiki/Mount_St._Helens">Mount St. Helen</a><a title="s" href="http://en.wikipedia.org/wiki/Mount_St._Helens">s</a> Erupts &#8211; Though I was four I remember this.  I also remember President Carter on TV so I have a good young memory.   This was a scary thing to me.   I think I had this thought that volcano&#8217;s didn&#8217;t exist any more, that they were something that was from the time of dinosaurs.  That it could happen in real life was very scary to me. I&#8217;m sure I watched this at my grandmother&#8217;s house on her floor model console TV. </p>
<p><center><object type="application/x-shockwave-flash" width="425" height="344" data="http://www.youtube.com/v/pvoEiBnpCc8&amp;rel=0&amp;fs=1"><param name="movie" value="http://www.youtube.com/v/pvoEiBnpCc8&amp;rel=0&amp;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="wmode" value="transparent" /></object></center></p>
<p><a title="Katrina" href="http://en.wikipedia.org/wiki/Hurricane_Katrina">Katrina</a> Hits New Orleans &#8211; For Hurrican Katrina Xie and I were at home, we were playing SWG and attempting to get a hold of our friend that lived in New Orleans.   We managed a day or so later to get a hold of him and <a href="http://creeva.com/2005/09/01/en-chi-and-hurricane-katrina/">post a picture of his house</a>.  It was scary knowing someone that was going through the disaster.   We almost went down to help but didn&#8217;t.   The evacuations and such were keeping people at bay we didn&#8217;t know when to go or what to do.   We both wish we had gone, but that time has now passed.  We are left with what we did do. </p>
<p><center><br />
<object type="application/x-shockwave-flash" width="425" height="344" data="http://www.youtube.com/v/ioJk2MSxDkg&amp;rel=0&amp;fs=1"><param name="movie" value="http://www.youtube.com/v/ioJk2MSxDkg&amp;rel=0&amp;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="wmode" value="transparent" /></object><br />
</center><br />
<a title="O.J. Simpson Verdict" href="http://en.wikipedia.org/wiki/O._J._Simpson_murder_case">O.J. Simpson Verdict</a> &#8211; I was working at Beaver Park Marina that year.  We watched portions of the trial during our breaks in the &#8220;cafeteria&#8221; area.   I&#8217;m still not sure to this day why this trial was such a big event.  I understand the outcome and fears of racial violence from the verdict.  What I don&#8217;t understand is all the media hype and the 24&#215;7 news coverage of this trial. </p>
<p><center><br />
<object type="application/x-shockwave-flash" width="425" height="344" data="http://www.youtube.com/v/CGACsSW4Iqw&amp;rel=0&amp;fs=1"><param name="movie" value="http://www.youtube.com/v/CGACsSW4Iqw&amp;rel=0&amp;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="wmode" value="transparent" /></object><br />
</center></p>
<p><a title="Miracle On Ice" href="http://en.wikipedia.org/wiki/Miracle_on_Ice">Miracle On Ice</a> &#8211; Ok this happened while I was alive, but I remember nothing about it. </p>
<p><center><br />
<object type="application/x-shockwave-flash" width="425" height="344" data="http://www.youtube.com/v/Jva3q7OMDVI&amp;rel=0&amp;fs=1"><param name="movie" value="http://www.youtube.com/v/Jva3q7OMDVI&amp;rel=0&amp;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="wmode" value="transparent" /></object><br />
</center><center></p>
<p><a title="Oklahoma City Bombing" href="http://en.wikipedia.org/wiki/Oklahoma_City_bombing">Oklahoma City Bombing</a> &#8211;  America had lived through attacks previous to this one.   There was a few attack on the World Trade center, and it was thought this was done by foreign nationals.  To this day this is one of the events I point to when people point on the war on terrorism that takes place on foreign soil.  One of the largest attacks on our own soil happened by one of our own citizens. </p>
<p></center><center><br />
<object type="application/x-shockwave-flash" width="425" height="344" data="http://www.youtube.com/v/GvaRNxSZr38&amp;rel=0&amp;fs=1"><param name="movie" value="http://www.youtube.com/v/GvaRNxSZr38&amp;rel=0&amp;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="wmode" value="transparent" /></object><br />
</center></p>
<p><a title="John Lennon Shot" href="http://en.wikipedia.org/wiki/Death_of_John_Lennon">John Lennon Shot</a> &#8211; This is another one of those where I was alive, but I don&#8217;t remember it. </p>
<p><center><br />
<object type="application/x-shockwave-flash" width="425" height="344" data="http://www.youtube.com/v/OgO9Pb-d5P0&amp;rel=0&amp;fs=1"><param name="movie" value="http://www.youtube.com/v/OgO9Pb-d5P0&amp;rel=0&amp;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="wmode" value="transparent" /></object><br />
</center></p>
<p><a title="Elvis Presley" href="http://en.wikipedia.org/wiki/Elvis_Presley">Elvis Presley</a> Dies at 42 &#8211; I definitely don&#8217;t remember this one since I was only one year old.  </p>
<p><center><br />
<object type="application/x-shockwave-flash" width="425" height="344" data="http://www.youtube.com/v/p6Z4Aih8aQM&amp;rel=0&amp;fs=1"><param name="movie" value="http://www.youtube.com/v/p6Z4Aih8aQM&amp;rel=0&amp;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="wmode" value="transparent" /></object><br />
</center></p>
<p><a href="http://en.wikipedia.org/wiki/1989_Loma_Prieta_earthquake">San Francisco World Series Earthquake</a> &#8211; If I had followed sports ever in my life I think I would have paid more attention to this.   I do remember the earthquake and wondered if California was going to fall into the Ocean.  If this was the proverbial big one.   I&#8217;m influenced in that thinking because of Superman II. </p>
<p><center><br />
<object type="application/x-shockwave-flash" width="425" height="344" data="http://www.youtube.com/v/qNsdvhh8_X0&amp;rel=0&amp;fs=1"><param name="movie" value="http://www.youtube.com/v/qNsdvhh8_X0&amp;rel=0&amp;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="wmode" value="transparent" /></object><br />
</center></p>
<p><a title="Princess Diana Dies" href="http://en.wikipedia.org/wiki/Death_of_Diana,_Princess_of_Wales">Princess Diana Dies</a> &#8211; I remember this.  I also wsan&#8217;t sure what the big deal was.  I know one of my uncles cried because of this.  To many people Diana was the last true royalty.  This was probably because she was the modern storybook princess. </p>
<p><center><br />
<object type="application/x-shockwave-flash" width="425" height="344" data="http://www.youtube.com/v/Fmmdh8Xlbvg&amp;rel=0&amp;fs=1"><param name="movie" value="http://www.youtube.com/v/Fmmdh8Xlbvg&amp;rel=0&amp;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="wmode" value="transparent" /></object><br />
</center></p>
<p><a title="Three Mile Island Nuclear Accident" href="http://en.wikipedia.org/wiki/Three_Mile_Island_accident">Three Mile Island Nuclear Accident</a> &#8211;  Once again, I was too young and do not remember this one. </p>
<p><center><br />
<object type="application/x-shockwave-flash" width="425" height="344" data="http://www.youtube.com/v/UoZeZprXnDg&amp;rel=0&amp;fs=1"><param name="movie" value="http://www.youtube.com/v/UoZeZprXnDg&amp;rel=0&amp;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="wmode" value="transparent" /></object><br />
</center></p>
<p><a href="http://en.wikipedia.org/wiki/Reagan_assassination_attempt">Reagan Shot</a> &#8211; We heard about this when I was at school.  Since it was a private christian school we all had a prayer session for the president.   Reagan was like a god to me back then, the invulnerable most powerful man.  This re-affirmed that when he survived, but I was on shaky ground at first.  I was young and scared for the life of our president.  To this day I still personally think he was one of four greatest presidents of the last one hundred years. </p>
<p><center><br />
<object type="application/x-shockwave-flash" width="425" height="344" data="http://www.youtube.com/v/EaKSrOpLJPo&amp;rel=0&amp;fs=1"><param name="movie" value="http://www.youtube.com/v/EaKSrOpLJPo&amp;rel=0&amp;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="wmode" value="transparent" /></object></p>
<p><object type="application/x-shockwave-flash" width="425" height="344" data="http://www.youtube.com/v/5JKIZ7j20EA&amp;rel=0&amp;fs=1"><param name="movie" value="http://www.youtube.com/v/5JKIZ7j20EA&amp;rel=0&amp;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="wmode" value="transparent" /></object><br />
</center></p>
<p><a title="Shuttle Challenger Explodes" href="http://en.wikipedia.org/wiki/Space_Shuttle_Challenger_disaster">Shuttle Challenger Explodes</a> &#8211; I was in school again when this happened.  It was a big media event with the first school teacher going up with the shuttle.  This was the event that shocked the nation. We got out of school early that day and I do remember being upset.   For what seemed to be weeks they showed that footage on the news.   </p>
<p><center><br />
<object type="application/x-shockwave-flash" width="425" height="344" data="http://www.youtube.com/v/WKyvCSxu73w&amp;rel=0&amp;fs=1"><param name="movie" value="http://www.youtube.com/v/WKyvCSxu73w&amp;rel=0&amp;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="wmode" value="transparent" /></object><br />
</center></p>
<p><a href="http://en.wikipedia.org/wiki/John_F._Kennedy,_Jr.#Death">JFK Jr. Dies in a Plane Crash</a> &#8211; I&#8217;m not sure why this made the list.  I remember it, and I was sad in the abstract, but it didn&#8217;t really pull at my heart strings.  Around the same time I remember John Denver dying &#8211; I think the guy that who sang with Kermit the frog being gone affected me more. </p>
<p><center><br />
<object type="application/x-shockwave-flash" width="425" height="344" data="http://www.youtube.com/v/zVTzuJftzgc&amp;rel=0&amp;fs=1"><param name="movie" value="http://www.youtube.com/v/zVTzuJftzgc&amp;rel=0&amp;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="wmode" value="transparent" /></object><br />
</center></p>
<p><a title="Shuttle Columbia Disintegrates on Re-entry" href="http://en.wikipedia.org/wiki/Space_Shuttle_Columbia_disaster">Shuttle Columbia Disintegrates on Re-entry</a> &#8211; I woke up early that day and was watching TV in the family room in the Oregon house.  I was shocked and hurt when I saw this.  I started crying.  I thought this was the worst disaster that I had witnessed since it would hurt human&#8217;s getting back to the stars which I felt was our future.  I woke up Xie and told her, she didn&#8217;t understand why I was upset.  I just was.  This event truly affected me. </p>
<p><center><br />
<object type="application/x-shockwave-flash" width="425" height="344" data="http://www.youtube.com/v/pK3_NayjnII&amp;rel=0&amp;fs=1"><param name="movie" value="http://www.youtube.com/v/pK3_NayjnII&amp;rel=0&amp;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="wmode" value="transparent" /></object><br />
</center></p>
<p><a title="9/11 Attacks" href="http://en.wikipedia.org/wiki/September_11_attacks">9/11 Attacks</a> &#8211; I was driving to work at Symantec on the beltway and a radio announcer talked about plane hitting the trade center.  I&#8217;m not sure if the second plane had hit or not at that point.   I thought it was some weird joke by the disc jockey&#8217;s.  It turned out it wasn&#8217;t.  When I arrived at work ewe were told that if it was too much for us, then we could return home (paid).  I went on with my day following events online.  I called Griffaw and Xie at home to turn on the TV at home to see what was happening.  We kept in contact through out the day via IM.   Griffaw didn&#8217;t move form that TV for four days watching everything as it unfolded.  I&#8217;ll leave my own political comments about this time out of this post.  </p>
<p><center><br />
<object type="application/x-shockwave-flash" width="425" height="344" data="http://www.youtube.com/v/k4nprJmtzSM&amp;rel=0&amp;fs=1"><param name="movie" value="http://www.youtube.com/v/k4nprJmtzSM&amp;rel=0&amp;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="wmode" value="transparent" /></object><br />
</center></p>
<p><a title="Asian Tsunami" href="http://en.wikipedia.org/wiki/2004_Indian_Ocean_earthquake">Asian Tsunami</a> &#8211; We didn&#8217;t watch a lot of news at this time.  I was aware of the event and read about it online, but it wasn&#8217;t an in your face major thing for me. </p>
<p><center><br />
<object type="application/x-shockwave-flash" width="425" height="344" data="http://www.youtube.com/v/Ymwl940wo2g&amp;rel=0&amp;fs=1"><param name="movie" value="http://www.youtube.com/v/Ymwl940wo2g&amp;rel=0&amp;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="wmode" value="transparent" /></object><br />
</center></p>
<p><a title="Dale Earnhardt Dies at Daytona" href="http://en.wikipedia.org/wiki/Death_of_Dale_Earnhardt">Dale Earnhardt Dies at Daytona</a> &#8211; Really?  I don&#8217;t know why this made the list.  I don&#8217;t know where I was or even if I cared at all.  I don&#8217;t follow NASCAR so someone dying in a car crash is a risk that I was aware that drivers took. </p>
<p>There is one more I would like to do that isn&#8217;t on that list:</p>
<p><center><br />
<object type="application/x-shockwave-flash" width="425" height="344" data="http://www.youtube.com/v/h8WmiqnvXjw&amp;rel=0&amp;fs=1"><param name="movie" value="http://www.youtube.com/v/h8WmiqnvXjw&amp;rel=0&amp;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="wmode" value="transparent" /></object><br />
</center></p>
<p><a href="http://en.wikipedia.org/wiki/Death_of_Kurt_Cobain">Kurt Cobain&#8217;s Death</a> &#8211; I didn&#8217;t watch MTV so I wasn&#8217;t immediately informed of Kurt Cobain&#8217;s death.  At this time period I didn&#8217;t even like Nirvana&#8217;s music (they are one of my favorites now).   I was one of those kids the next day mocking the other kids that were crying.  I understand this now though.  Some people may disagree but in a way Cobain was a Lennon for our generation.  A voice that spoke out and said what we were feeling.  Someone who we could identify with.  I have never had a living musician that I felt that way about, but I understand why everyone else was upset.  Wisdom is granted with age. </p>
<p>If you don&#8217;t see all the video links make sure you view this a <a href="http://creeva.com">creeva.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://creeva.com/2008/12/02/where-were-you-when-moments-my-answers/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Small World After All</title>
		<link>http://creeva.com/2008/10/31/small-world-after-all/</link>
		<comments>http://creeva.com/2008/10/31/small-world-after-all/#comments</comments>
		<pubDate>Fri, 31 Oct 2008 17:10:54 +0000</pubDate>
		<dc:creator>Creeva</dc:creator>
				<category><![CDATA[Family and Friends]]></category>
		<category><![CDATA[Personal Writing]]></category>
		<category><![CDATA[Oregon]]></category>
		<category><![CDATA[Picture]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[Vermilion]]></category>

		<guid isPermaLink="false">http://creeva.com/?p=3609</guid>
		<description><![CDATA[One of the guys at work noticed that I wore my Vermilion Haunted School House shirt in today.  He asked me if I knew Jason (pictured) above. I explained yes, that he use to live with me in Oregon after I conned him to move out there and I got him a job at Symantec. [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="aligncenter" src="http://farm1.static.flickr.com/144/359288598_62c91f9f99_m.jpg" alt="" width="240" height="180" /></p>
<p>One of the guys at work noticed that I wore my Vermilion Haunted School House shirt in today.  He asked me if I knew Jason (pictured) above.  I explained yes, that he use to live with me in Oregon after I conned him to move out there and I got him a job at Symantec.   I guess this guy worked with him at Circuit City &#8211; it&#8217;s a small world after all&#8230;&#8230;.</p>
<p>Plus this little sidenote gave me a chance ot use that photo today&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://creeva.com/2008/10/31/small-world-after-all/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Kiosk Series &#8211; Part Four &#8211; Surferquest</title>
		<link>http://creeva.com/2008/05/08/the-kiosk-series-part-four-surferquest/</link>
		<comments>http://creeva.com/2008/05/08/the-kiosk-series-part-four-surferquest/#comments</comments>
		<pubDate>Thu, 08 May 2008 14:02:25 +0000</pubDate>
		<dc:creator>Creeva</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Centralize]]></category>
		<category><![CDATA[Centralized Management]]></category>
		<category><![CDATA[Environment]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Kiosk]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Music]]></category>
		<category><![CDATA[Picture]]></category>
		<category><![CDATA[steadystate]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[Test]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://creeva.com/?p=2718</guid>
		<description><![CDATA[Going further into my reviews of kiosk systems we acquired the Surferquest system here at work.   Unlike my piece on SteadyState I&#8217;m not going to have a bunch of screen shots to show you this time.   However I will give you my analysis and what I&#8217;ve found out. The Surferquest system is an off the [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img src="http://farm3.static.flickr.com/2399/2430482785_30e1cebd8f_o.jpg" alt="" width="320" height="256" /></p>
<p>Going further into my reviews of kiosk systems we acquired the Surferquest system here at work.   Unlike <a href="http://creeva.com/2008/04/09/the-kiosk-series-part-three-microsoft-steadystate-vs-group-policies/">my piece on SteadyState</a> I&#8217;m not going to have a bunch of screen shots to show you this time.   However I will give you my analysis and what I&#8217;ve found out.</p>
<p>The Surferquest system is an off the shelf software with minimal customization.  We ordered an evaluation unit and I was tasked to try it out.   I can say for our needs as a company that requires centralized management and control of machines in our environment that the Surferquest system was not quite a correct fit for us.</p>
<p>In our environment we don&#8217;t normally place a machine on our network until it is fully tested and verified secure, but this product is pretty much useless until it has a network connection.   I had to contact support and they gave me an unlock code that would allow me to make changes to installed software.  The unlock code lasted only 24 hours, but they sent me a utility later on that would allow me generate unlock codes for myself.</p>
<p>Almost all of the customization that can be done is performed remotely by Surferquest.  This means if there is a major application change that needs to be completed you need to contact them.   Do you wish to customization your login screen?  You must contact them or upload the images to their server.    You can not perform these changes locally on the box or locally within your environment.  Wish to change the active desktop they used?  Same steps apply as changing the login screen.</p>
<p><strong>Restrictions applied to the software</strong>:</p>
<blockquote><p><em>Disable Windows Updates<br />
Remove from Start Menu:<br />
My Music<br />
My Pictures<br />
Favorites<br />
Recent Documents<br />
Frequently Used Programs<br />
Recent Network Docs<br />
Network Places<br />
Help<br />
Run<br />
My Documents<br />
Configure Programs<br />
Disable Windows Keys<br />
Lock Taskbar<br />
Disable Control Panel<br />
Disable Balloon Tips<br />
Remove OEM Link<br />
Disable Task Manager<br />
Disable Registry<br />
Disable Find Files with F3 in Explorer<br />
Prevents Control Panel, Printers, and Network and Dial-up Connections from running, and removes the corresponding menu items.<br />
Removes Shut Down from the Start menu and disables the Shut Down button in the Windows Security dialog box.<br />
Disable System Restore<br />
Clears Recent Documents on Exit<br />
Disable access to Recent Network Documents<br />
CTRL key disabled</em></p></blockquote>
<p>As you can see, though they use a different product to achieve the same goal, it has similar technology to the Microsoft Steadystate product I reviewed in part 3.</p>
<p>You can put the software within you domain, but the software will still be phoning home to the Surferquest company.  While I&#8217;m positive that there is nothing sensitive being pushed across, like any company that you would have do remote assistance make sure you trust them in case of any possible data leakage.  The official answer is that it only sends out IP address information and the last time connected.  You can view this information on the stat web page they provide you</p>
<p>If the drive in the unit should fail or there is a hardware issue in need of support, no software is supplied.   You must receive new hardware from the vendor and return your old unit.  They state that turn around time is usually 24 hours.   Any remote management or patching must be performed by the vendor and is done via remote monitoring software that they have access to.    The software is caused Netsupport and it sneaks out your firewall on port 22 &#8211; now all you admins that left it open for SSH can feel silly (actually that&#8217;s how the firewall support team snuck out the corporate firewall there and back to their home computers when I worked at Symantec on that team).</p>
<p>Quick Notes</p>
<ul>
<li>Idle timeouts can be configured, but they default at 10 minutes.</li>
<li>They use the Deep Freeze product to maintain their disk image</li>
<li>When we received the unit PXE booting was enabled (and we didn&#8217;t have a BIOS password &#8211; they stated this was a mistake)</li>
<li>The unit we received had PowerDVD installed, ironically no DVD drive (another oversight they admit)</li>
<li>Unlock Steadystate there is no method for restricting USB drive usage</li>
</ul>
<p style="text-align: center;"><img src="http://farm4.static.flickr.com/3155/2475291606_7a3230a72b.jpg?v=0" alt="" width="500" height="375" /></p>
<p style="text-align: center;"><em>Box the unit shipped in</em></p>
<p style="text-align: center;"><img src="http://farm3.static.flickr.com/2135/2474474173_f91f706f34.jpg?v=0" alt="" width="500" height="375" /></p>
<p style="text-align: center;"><em>Front of the unit</em></p>
<p style="text-align: center;"><img src="http://farm4.static.flickr.com/3235/2475291708_5e71b3077c.jpg?v=0" alt="" width="500" height="375" /></p>
<p style="text-align: center;"><em>Top of the unit</em></p>
<p style="text-align: center;"><img src="http://farm4.static.flickr.com/3080/2475291658_fef907b9f7.jpg?v=0" alt="" width="500" height="375" /></p>
<p style="text-align: center;"><em>Rear of the unit</em></p>
<p style="text-align: center;">
<p style="text-align: left;">If you deploying this in your environment you need to make certain you can accept the security and loss of control you have over this unit compared to other machine in your environment.   I see this fitting more in the public space kiosk scenarios suchs as libraries or hotels.   Because they do lack the centralized control that you would normally deploy in corporate environments I say give this one a pass or at least look hard at what you are trying to accomplish.   For the public space this is a great product, extremely low maintenance, the ability to monetize but charging a fee (customized through the stat page),  and extremely well versed and fast techinical support.   If you want to deploy an Internet Cafe in your area this is the product for you.</p>
<p>The <a class="st_tag internal_tag" title="Posts tagged with Kiosk" rel="tag nofollow" href="http://creeva.com/tag/kiosk">Kiosk</a> Series:</p>
<p><a title="Article-Link (Permalink)" rel="bookmark" href="http://creeva.com/2008/04/09/2008/04/08/the-kiosk-series-part-one-choices-for-your-environment">The Kiosk Series &#8211; Part One &#8211; Choices For Your Environment</a></p>
<p><a title="Article-Link (Permalink)" rel="bookmark" href="http://creeva.com/2008/04/09/2008/04/08/the-kiosk-series-part-two-management-considerations-for-your-environment">The Kiosk Series &#8211; Part Two &#8211; Management Considerations For Your Environment</a><a title="Article-Link (Permalink)" rel="bookmark" href="http://creeva.com/2008/04/09/the-kiosk-series-part-three-microsoft-steadystate-vs-group-policies"></a></p>
<p><a title="Article-Link (Permalink)" rel="bookmark" href="http://creeva.com/2008/04/09/the-kiosk-series-part-three-microsoft-steadystate-vs-group-policies">The Kiosk Series &#8211; Part Three &#8211; Microsoft SteadyState vs Group Policies</a></p>
]]></content:encoded>
			<wfw:commentRss>http://creeva.com/2008/05/08/the-kiosk-series-part-four-surferquest/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Co-Worker Passed Away Last Night</title>
		<link>http://creeva.com/2008/04/23/a-co-worker-passed-away-last-night/</link>
		<comments>http://creeva.com/2008/04/23/a-co-worker-passed-away-last-night/#comments</comments>
		<pubDate>Wed, 23 Apr 2008 15:06:42 +0000</pubDate>
		<dc:creator>Creeva</dc:creator>
				<category><![CDATA[Family and Friends]]></category>
		<category><![CDATA[Friends]]></category>
		<category><![CDATA[Personal Writing]]></category>
		<category><![CDATA[Sad]]></category>
		<category><![CDATA[Symantec]]></category>

		<guid isPermaLink="false">http://creeva.com/?p=2744</guid>
		<description><![CDATA[One of my co-workers passed away in his sleep last night.  He was a nice guy that was always there and willing to help you out.   He was a smoking buddy for me and someone with whom I could discuss cars with.   While his loss will be missed, most people here are taking it harder [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img src="http://farm1.static.flickr.com/36/87198917_a7b48924ca.jpg" alt="" width="376" height="500" /></p>
<p>One of my co-workers passed away in his sleep last night.  He was a nice guy that was always there and willing to help you out.   He was a smoking buddy for me and someone with whom I could discuss cars with.   While his loss will be missed, most people here are taking it harder then I am.   After being a pallbearer for my best friend, I&#8217;m not sure I could get upset with the loss of a co-worker/casual friend the same way ever again.</p>
<p>When I was working for tech support at Symantec we once had someone pass away in their cubicle.   It was almost surreal after the fact.   I knew who the guy was but he wasn&#8217;t on my team so I didn&#8217;t really talk to him. But from my understanding he was sitting there for over an hour hunched over and people thought he was asleep.   This was about 1 cubicle row over from me.   It was odd but not upsetting to me.</p>
<p>I can say for my co-worker that passed away last night, that I&#8217;m happy he was away from the office and hopefully passed away in his sleep.    The last conversation we had was about Dodge cars made in the 60&#8242;s and 70&#8242;s  &#8211; he also talked about how he used to tour the strip in his hometown for girls when he was a teenagers driving these cars that were destined to be the classic iconography of the American automobile.</p>
<p>Hopefully now he is sitting again in his 1969 Dodge Charger that he owned in his younger years and cruising that same strip.  Reliving the happiest moments of his life.   He will be missed and honored.</p>
]]></content:encoded>
			<wfw:commentRss>http://creeva.com/2008/04/23/a-co-worker-passed-away-last-night/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>The Kiosk Series &#8211; Part Two &#8211; Management Considerations For Your Environment</title>
		<link>http://creeva.com/2008/04/08/the-kiosk-series-part-two-management-considerations-for-your-environment/</link>
		<comments>http://creeva.com/2008/04/08/the-kiosk-series-part-two-management-considerations-for-your-environment/#comments</comments>
		<pubDate>Tue, 08 Apr 2008 16:15:26 +0000</pubDate>
		<dc:creator>Creeva</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Centralize]]></category>
		<category><![CDATA[Centralized Management]]></category>
		<category><![CDATA[design]]></category>
		<category><![CDATA[Environment]]></category>
		<category><![CDATA[Kiosk]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Smart Card]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[Test]]></category>
		<category><![CDATA[Updates]]></category>

		<guid isPermaLink="false">http://creeva.com/?p=2685</guid>
		<description><![CDATA[Recently I&#8217;ve been put forth to design a kiosk solution for our internal environment.   This is the second part of my kiosk series which is going to examine testing and deployment of such a system.  To read the first section go to Part One &#8211; Choices For Your Environment. Kiosk System Management Strategy There are [...]]]></description>
			<content:encoded><![CDATA[<p>Recently I&#8217;ve been put forth to design a kiosk solution for our internal environment.   This is the second part of my kiosk series which is going to examine testing and deployment of such a system.  To read the first section go to<a title="Article-Link (Permalink)" rel="bookmark" href="http://creeva.com/2008/04/08/the-kiosk-series-part-one-choices-for-your-environment"> Part One &#8211; Choices For Your Environment</a>.</p>
<p>Kiosk System Management Strategy</p>
<p>There are multiple issues involved with managing a “kiosk system&#8221;.   We have to look at the problems we will face whether they are considered to be internal or external.  From a security and management scope of this document we are going to assume they are located on the company guest network.  If the machines are located within the internal network the current maintenance procedures will apply.</p>
<p>While this is still in the design period the final abilities of both the kiosk system and the where it falls have not been decided upon.   Until another strategy is decided upon we are going to assume that these systems will be a member of the domain.</p>
<p><strong>Hotfixing and Patching:</strong> Within the internal network we currently use a mixture of <a href="http://technet.microsoft.com/en-us/wsus/default.aspx">WSUS</a>, <a href="http://www.microsoft.com/smserver/default.mspx">SMS</a>, and <a href="http://www.symantec.com">Antivirus</a> servers to keep computers up to date.   Something similar would have to be replicated either on the guest or <a href="http://creeva.com/wp-admin/compnetworking.about.com/cs/networksecurity/g/bldef_dmz.htm">DMZ</a> network.   If it is located on the DMZ network controls would have to be in place that the communication is pushed to the client for updates instead of the client pulling the information.  If the information absolutely must be pulled, this will be addressed in the section below titled “Securing Connections”.</p>
<p><strong>Break/Fix Issues: </strong> Next to the computer there will have to be a phone located so users can report any issues that a kiosk should have.   Upon receiving the call and logging it, normal break/fix procedures would apply.</p>
<p><strong>Remote Desktop: </strong> Going from the DMZ to the guest network we should be able to <a href="http://en.wikipedia.org/wiki/Remote_Desktop_Protocol">RDP</a> into the kiosk unit.</p>
<p><strong>Remote Monitoring:</strong> For the best security standpoint all of these units should include full auditing.   The audit trail could be maintained locally with a remote server from the DMZ pulling in the logs via either a script or an off the shelf utility designed for pulling log files off of the machine.</p>
<p><strong>Utilization Report:</strong> Similar to the Audit log we can get a utility that monitors the utilization with these units and pull them into the internal network.  This can be done after tracking down a third party program that allows for utilization monitoring or by parsing the audit log and turning that into a utilization report.</p>
<p><strong>Seat Type:</strong> A new seat type would have to be established to accommodate the additional costs incurred from the environment set up and maintenance of these units including but not limited the additional costs possibly incurred by having a phone nearby to inform the help desk of any issues.</p>
<p><strong>Security Plan:</strong> A new security plan would have to be established since there will configuration settings that do not fit into the current security plans that the company has established.  While these will fall under a site security plan, none of our existing would not be able to fit these systems under their configuration options.</p>
<p><strong>Privacy Controls:</strong> Depending on the kiosk solution we go with – whether it be a login based solution where they have a full application suite or a web kiosk something must be done to maintain user privacy.   After an inactivity time (amount to be specified later) which would either clear the process from memory or log the user out of the kiosk completely depending on which kiosk method we are using in a couple methods. One would be an off the shelf software product to this, at this point I would assume we would use all of their privacy and utilization reports. Another option would be to setup a script to kill the process or automatically log out the user and utilize the screensaver in the kiosk to run this functionality and monitor idle time.</p>
<p><strong>Securing Connections:</strong> If the machines must pull information from the machines in the DMZ, then the best method would be to utilize <a href="http://en.wikipedia.org/wiki/IPsec ">IPSEC</a>.  This would limit the amount of ports needed and allow us to lockdown communication to only the specific server that the kiosk would need to talk to.</p>
]]></content:encoded>
			<wfw:commentRss>http://creeva.com/2008/04/08/the-kiosk-series-part-two-management-considerations-for-your-environment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Draft Overload</title>
		<link>http://creeva.com/2008/03/18/draft-overload/</link>
		<comments>http://creeva.com/2008/03/18/draft-overload/#comments</comments>
		<pubDate>Tue, 18 Mar 2008 17:42:32 +0000</pubDate>
		<dc:creator>Creeva</dc:creator>
				<category><![CDATA[Personal Writing]]></category>
		<category><![CDATA[Band]]></category>
		<category><![CDATA[Community Band]]></category>
		<category><![CDATA[Father]]></category>
		<category><![CDATA[fdcc]]></category>
		<category><![CDATA[Life Caching]]></category>
		<category><![CDATA[Life Notes]]></category>
		<category><![CDATA[Music]]></category>
		<category><![CDATA[Picture]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[ubuntu]]></category>

		<guid isPermaLink="false">http://creeva.com/2008/03/18/draft-overload/</guid>
		<description><![CDATA[You ever get one of those time that you step away from your blog for a few days (ok a couple weeks for me) and it seems that you need to go through the steps to clean up your drafts, finish your writing, and then you may feel complete?  I&#8217;m having one of those days. [...]]]></description>
			<content:encoded><![CDATA[<p>You ever get one of those time that you step away from your blog for a few days (ok a couple weeks for me) and it seems that you need to go through the steps to clean up your drafts, finish your writing, and then you may feel complete?  I&#8217;m having one of those days.</p>
<p>I&#8217;ve logged in and took out of drafted and posted all my life caching items, I&#8217;m startingto go throguh my other drafts and just feeling a little bit overwhelmed.   I have things in all sorts of different stages of draft form.  An article about my paternal grandfather is about 30% done.   A draft on my first day of work with symantec is about 10%.    I have a varied things to finish via life notes.   I have pictures I still need to scan from photo albums.</p>
<p>Arrrrggggg.</p>
<p>Then you have all the things outside of the blog and this writing that causes hassles.  I have house issues I need to worry about, pet issues, relationships issues, my laptop was crashed thanks to an automatic <a href="https://wiki.ubuntu.com/HardyHeron">Hardy Heron</a> update (fixed after 3 days of figuring it out myself thank you), community band, <a href="ttp://live.gnome.org/Conduit/Documentation">Gnome Conduit documentation</a> I need to finish, and <a href="http://fdcc.nist.gov/">work related projects</a>.   We&#8217;ll say that&#8217;s just a start &#8211; but geeze my life seems to be a whirlwind sometimes that doesn&#8217;t stop.</p>
<p>And then we&#8217;re back to the blog.   I&#8217;m actually bad.  I need to look and write on the blog more often.  It relaxes me.  It actually completesme in a Jerry Macguiresque way.  Getting more seriouswriting on my blog gives me the true fulfillment in my life that only two other things give me currently.   My wife, she is my stability, my rock, the one that inspires to be better then I am.  She has a higher view point of me then I do myself.   Even though I think she is wrong, I know her beliefs in my skills is not false from her point of view, just false from my belief in reality.   I love her deeply and compeltely.   The last thing that finishes off my triage of life and completes me is playing music in the two community bands I am a member of.</p>
<p>These are the three things that I attempt to focus on &#8211; to get out of draft &#8211; because it calms and centers me.  I hope the three of them are never finished.</p>
]]></content:encoded>
			<wfw:commentRss>http://creeva.com/2008/03/18/draft-overload/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Annoying &#8211; WordPress didn&#8217;t migrate all of my blogger posts</title>
		<link>http://creeva.com/2007/12/28/annoying-wordpress-didnt-migrate-all-of-my-blogger-posts/</link>
		<comments>http://creeva.com/2007/12/28/annoying-wordpress-didnt-migrate-all-of-my-blogger-posts/#comments</comments>
		<pubDate>Fri, 28 Dec 2007 15:03:58 +0000</pubDate>
		<dc:creator>Creeva</dc:creator>
				<category><![CDATA[Personal Writing]]></category>
		<category><![CDATA[Annoyed]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[Wordpress]]></category>

		<guid isPermaLink="false">http://creeva.com/2007/12/28/annoying-wordpress-didnt-migrate-all-of-my-blogger-posts/</guid>
		<description><![CDATA[I found that out when I linked to the Symantec Endpoint Protection article in my last post. That isn&#8217;t going ot stop my launch or cut over &#8211; but it means this weekend I&#8217;ll be tearing over information between the old blog and the new to see what didn&#8217;t make it over. More work for [...]]]></description>
			<content:encoded><![CDATA[<p>I found that out when I linked to the <a href="http://creeva.com/2007/09/11/symantec-endpoint-protection-110/">Symantec Endpoint Protection</a> article in my <a href="http://creeva.com/2007/12/28/i-find-it-odd/">last post</a>.  That isn&#8217;t going ot stop my launch or cut over &#8211; but it means this weekend I&#8217;ll be tearing over information between the old blog and the new to see what didn&#8217;t make it over.    More work for me&#8230;..fun fun&#8230;&#8230;&#8230;.</p>
<p>Grrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr &#8211; WordPress</p>
]]></content:encoded>
			<wfw:commentRss>http://creeva.com/2007/12/28/annoying-wordpress-didnt-migrate-all-of-my-blogger-posts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>I find it odd</title>
		<link>http://creeva.com/2007/12/28/i-find-it-odd/</link>
		<comments>http://creeva.com/2007/12/28/i-find-it-odd/#comments</comments>
		<pubDate>Fri, 28 Dec 2007 14:48:04 +0000</pubDate>
		<dc:creator>Creeva</dc:creator>
				<category><![CDATA[Personal Writing]]></category>
		<category><![CDATA[e-mail]]></category>
		<category><![CDATA[Hits]]></category>
		<category><![CDATA[Hulu]]></category>
		<category><![CDATA[Links]]></category>
		<category><![CDATA[Netflix]]></category>
		<category><![CDATA[Palantir]]></category>
		<category><![CDATA[Sites]]></category>
		<category><![CDATA[story]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[TV]]></category>
		<category><![CDATA[Video]]></category>

		<guid isPermaLink="false">http://creeva.com/2007/12/28/i-find-it-odd/</guid>
		<description><![CDATA[That two of my posts that go in spurts are the ones that deal with the government. Reversing the Netflix database (which was publicly announced as a major threat after I posted about it) I&#8217;m not taking credit the guys I pointed to in the original article are the ones that deserve any and all [...]]]></description>
			<content:encoded><![CDATA[<p>That two of my posts that go in spurts are the ones that deal with the government.  <a href="http://creeva.com/2007/11/07/netflix-privacy-issues-the-government-knows-your-rentals/">Reversing the Netflix database</a> (which was publicly announced as a major threat after I posted about it) I&#8217;m not taking credit the guys I pointed to in the original article are the ones that deserve any and all credit.  I just hope I caused a little more rumbling.</p>
<p>The other is on <a href="http://www.palantirtech.com/">Palantir</a> and there analysis platform which after worrying about my posts because of all the Washington D.C. hits and the hits from Palantir had me very curious.   The reason is I didn&#8217;t put out anything that was more technical or more scathing then some other sites I saw after the fact when I wrote that.</p>
<p>It seems some of my hits seem to be from people more interested specifically in Palantir and looking for more information.   I would assume that the Palantir hits were part of a bot program &#8211; but it seems some of these links originated from e-mail accounts &#8211; so they are sharing my humble story.</p>
<p>I do applaud Palantir on <a href="http://blog.palantirtech.com/2007/09/11/palantir-screenshots/">updating their screenshots</a> &#8211; it seems they are showing off some of what they have accomplished now.  The only thing I have to say to Palantir is the website has moved and some articles are now cross-posted &#8211; but I haven&#8217;t written anything new and it&#8217;s the same article you were tearing through months ago when I originally wrote the article.</p>
<p>The other posts that are huge is my review on the <a href="http://creeva.com/2007/09/11/symantec-endpoint-protection-110/">Symantec Endpoint Protection</a>, my &#8220;<a href="http://creeva.com/2007/10/29/hulu-another-good-tv-links-replacement/">Hulu &#8211; Another good Tv-Links Replacement</a>&#8220;, and <a href="http://creeva.com/2007/10/22/teddys-place-tv-links-replacements/">My link to TV-Links replacement sites</a>.</p>
<p>I&#8217;m hoping with the launch of my new site in the next 24 hours that I start to receive a wider variety of people reading a wider variety of stuff.  Until then welcome those in public servant space, in the need for Symantec help, and those looking for online video.  You help keep up my readership.</p>
]]></content:encoded>
			<wfw:commentRss>http://creeva.com/2007/12/28/i-find-it-odd/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Palantir Technologies -The Intelligence Community&#8217;s New Analysis Platform</title>
		<link>http://creeva.com/2007/11/07/palantir-technologies-the-intelligence-communitys-new-analysis-platform/</link>
		<comments>http://creeva.com/2007/11/07/palantir-technologies-the-intelligence-communitys-new-analysis-platform/#comments</comments>
		<pubDate>Wed, 07 Nov 2007 15:53:00 +0000</pubDate>
		<dc:creator>Creeva</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Links]]></category>
		<category><![CDATA[Netflix]]></category>
		<category><![CDATA[Palantir]]></category>
		<category><![CDATA[story]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[TV]]></category>
		<category><![CDATA[Video]]></category>
		<category><![CDATA[Web 2.0]]></category>

		<guid isPermaLink="false">http://creeva.com/?p=549</guid>
		<description><![CDATA[The Intelligence Community&#8217;s New Analysis Platform is the webinar I am attending today. It is hosted by Carahsoft &#8211; the same people that hosted the Symantec Webinar I attended. The company whose products this is about is called Palantir Technologies. They have wide spread financial and government data analysis tools. Todays webinar focuses on the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.carahsoft.com/events/palantir/11-07-07/palantir11-07-07.html">The Intelligence Community&#8217;s New Analysis Platform</a> is the webinar I am attending today.  It is hosted by <a href="http://www.carahsoft.com/">Carahsoft</a> &#8211; the same people that hosted the <a href="http://www.creeva.com/2007/09/symantec-endpoint-protection-110.html">Symantec Webinar I attended</a>.   The company whose products this is about is called <a href="http://www.palantirtech.com/products.html">Palantir Technologies</a>.  They have wide spread financial and government data analysis tools.  Todays webinar focuses on the government sectors.</p>
<p>From a side note while we are waiting for this to start Palantir, <a href="http://en.wikipedia.org/wiki/Palant%C3%ADr">according to wikipedia</a>, is an artifact from the Tolkien mythos.  specifically: <i style="font-style: italic;">A palantír</i><span style="font-style: italic;"> (sometimes translated as </span><i style="font-style: italic;">Seeing Stone</i><span style="font-style: italic;"> but actually meaning &#8220;Farsighted&#8221; or &#8220;One that Sees from Afar&#8221;) is a stone that functions somewhat like a crystal ball.</span></p>
<p>Webinar started</p>
<p>They start with the standard thank you to their host carahsoft.</p>
<p>Palantir was started in 2004 by Alexander Carr (sp) and the paypal team.   They pointed out that the main part of Paypal was anti fraud and that&#8217;s how they relate to the intelligence community.   They spent sometime discussing Paypal and their competitors.  The reason paypal succeeded compared to their competitors was that they had analysts to sort the data compared to using pure computer work.   The analyst then built tools to work with the data at the conceptual level compared to the data level.   This allowed the analysts to help fight fraud better then the competition which allowed them to succeed.</p>
<p>Paypal then looked at what areas they could fit these types of tools.  They recognized that they would fit best in the high finance and the intelligence community.   They worked and created tools and today&#8217;s webcast was about the intelligence community tools. Planatir is a front end and backend tool</p>
<p>Data Integration &#8211; takes all your records and puts them into one unified view that allows an analyst to have an easy view of unified data.</p>
<p>Search and Discovery &#8211; see who the user communicated with &#8211; persistent search which alerts the analyst when new information becomes available.</p>
<p>Link Analysis- the database includes historical and auditible revision analysis &#8211; I assume this is it help ensure the integrity of the database.   Includes meta data for source, who added it, and where it came from, who updated it, essentially every step of change and data you could want.   This also allows the revisioning database to look quickly at the data history.   They then go on to show different views and history tracking they can utilize.</p>
<p>He shows how you could do different information extractions to track terrorist activities (once again using the terrorist threat to try to drive the point home /rolleyes).   While this would be a great tool in general I think this could have been done another way instead of driving the terrorist angle.   The data set that it can pull from is quite large and very interesting.</p>
<p>Very interesting drag and drop interface for entity resolution and analysis.   Very Web 2.0ish but yet seems they put too much emphasis on the fisher price like interface.  It&#8217;s not a bad thing just overly rounded &#8211; but I assume this may help things work faster &#8211; I have nothing to compare it to though.   They are offering a video at the end so I&#8217;m not going to describe all of the interface and his interaction with it. </p>
<p>This does make <a href="http://www.thepublicballot.org/">Jim Cropcho&#8217;s</a> discovery of a <a href="http://www.creeva.com/2007/08/vulnerabilities-in-ohio-voting-system.html">flaw in the ohio voting records</a> a very trivial discovery for this software and makes how we maintain our records especially our voting and documents that should be private (no your phone is not really considered private sorry) otherwise data discovery with tools like this is trivial.</p>
<p>The platform does support plug-ins.</p>
<p>When asked how many entities they can handle they stated over 100 million entities &#8211; they have pulled in all of IMDB, Wikipedia &#8211; and NETFLIX!!!! &#8211; so this company is looking at user checkouts and ratings on netflix &#8211; I&#8217;m going to follow up with netflix and find out what of my private data is available to these other companies.</p>
<p>More links</p>
<p><a href="http://expertvoices.nsdl.org/cornell-info204/2007/02/23/palantir-technologies-data-analysis-and-network-visualization/">here</a><br /><a href="http://www.google.com/url?sa=t&amp;ct=res&amp;cd=4&amp;url=http%3A%2F%2Fblog.palantirtech.com%2F2007%2F09%2F11%2Fpalantir-screenshots&amp;ei=bOQxR9q3MaGIpwTZmfGIAg&amp;usg=AFQjCNF_9iXTXaPBloxslFajqC7RRT3MJw&amp;sig2=jCCpOvrJvyS5HlGxQDIZow">here </a><br /><a href="http://www.palantirtech.com/demo/">Flash Demo</a></p>
<p>For more carahsoft webinar&#8217;s <a href="http://www.carahsoft.com/events/index.php">go here for sign up</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://creeva.com/2007/11/07/palantir-technologies-the-intelligence-communitys-new-analysis-platform/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Agents and Options for Symantec Backup Exec 11d: The Gold Standard in Data Recovery</title>
		<link>http://creeva.com/2007/09/13/agents-and-options-for-symantec-backup-exec-11d-the-gold-standard-in-data-recovery/</link>
		<comments>http://creeva.com/2007/09/13/agents-and-options-for-symantec-backup-exec-11d-the-gold-standard-in-data-recovery/#comments</comments>
		<pubDate>Thu, 13 Sep 2007 17:09:00 +0000</pubDate>
		<dc:creator>Creeva</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Centralize]]></category>
		<category><![CDATA[Centralized Management]]></category>
		<category><![CDATA[Environment]]></category>
		<category><![CDATA[Family]]></category>
		<category><![CDATA[I want]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[Quotes]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[Test]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Web 2.0]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://creeva.com/?p=453</guid>
		<description><![CDATA[So todays live blogging webinar (since my other one generated some interest by page loads) is Agents and Options for Symantec Backup Exec 11d: The Gold Standard in Data Recovery The company putting on this seminar is Carahsoft. The presenter is Monica Girolami Senior Product Marketing Manager from Symantec. When I dialed in I was [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal">So todays live blogging webinar (since my other one generated some interest by page loads) is <strong><i><span style="font-size: 10pt; font-family: Arial;">Agents and Options for <st1:personname st="on">Symantec</st1:personname> Backup Exec 11d: The Gold Standard in Data Recovery</span></i></strong><b><i><span style="font-size: 10pt; font-family: Arial;"><br /></span></i></b></p>
<p>The company putting on this seminar is Carahsoft. The presenter is Monica Girolami Senior Product Marketing Manager from Symantec.</p>
<p>When I dialed in I was the 26th caller &#8211; so take that for whatever level of review that you want.</p>
<p>The speaker started only 3 minutes late.</p>
<p>Valued of Backup Exec 11d Agents and Options:</p>
<p>Agenda:<br />Windows Recovery Challenge<br />Backup Exec 11d for windows servers<br />Current Upgrade promotions<br />Questions and Answers</p>
<p>This is about keeping your data secure and available against malicious threats, infrastructure failures, natural disasters, and etc.</p>
<p>It&#8217;s about your ability for recovery not about backup <i>*I feel I&#8217;m&#8217; getting brainwashed</i></p>
<p><i>More press notes self promoting</i></p>
<p>Advantages:<br />Continuous Protection for exchange<br />Recover Critical Data in seconds<br />Enhanced Data Security &#8211; Encryption &#8211; 128/256 AES encryption<br />New Platform Support (x64 bit) -<br />and more&#8230;.. <i>* did they really need to add this?????</i></p>
<p>Exchange Backup old way &#8211; daily (weekly full backup) daily second backup of the mailboxes &#8211; so it&#8217;s taking twice the time. With 11d eliminates the mailbox backups &#8211; still having the ability to recover individual emails or accounts. They do this through granular recovery technology. With the continuous data protection you can continuously protect and granularly recover the data. <i>* Roll eyes</i></p>
<p>Granular recovery requires you to have a backup up to disc &#8211; full backup would go to tape or disc.</p>
<p>current method of backup &#8211; sample customer &#8211; 7 hour exchange database job &#8211; mailbox backup &#8211; 23 hours &#8211; total of 30 hours. With 11d it took a total of 3 hour for everything &#8211; moving the database to tape it took a total of 5 hours. 80% reduction of time with up to the minute restoration available.</p>
<p>Continuous protection is now available for exchange &#8211; previously it was available for file servers. You can setup the recovery points &#8211; you can set this up down to every 15 minutes &#8211; default is 8 hours. So you could recover your system up to the last time point (down to 15 minutes ago). You can do recovery to this.</p>
<p>This product seems to be missing the new standard Symantec Web Interface</p>
<p>Active Directory Agent:</p>
<p>Recovery individual users, attributes, computers without reboots. Much easier then the MS method &#8211; just run a full backup job &#8211; from there you can recover the individual objects from that.<br />Recovers Share point databases and documents with the GRT previously mentioned</p>
<p>MS SQL now has continuous protection also &#8211; the agent can backup locally instead of over the network for the best continuous backup in the fastest method. 11d secures the restore selection to make sure the recovery job runs successfully.</p>
<p><st1:place st="on">Central Admin</st1:place> Server Option (CASO)- Simple Three Tier Management:</p>
<p>You can protect your entire environment from one location &#8211; the central admin server allows you to manage your protected servers, computers, and media servers from one location. This includes defining and distributing backup jobs, monitoring and reporting on job activity. This option was first introduced in Backup Exec 10.0</p>
<p>Does not require persistent architecture for remote offices<br />Distributed catalog architecture<br />simple monitoring of remote managed media server jobs</p>
<p>Desktop and Laptop Option &#8211; Protecting Critical work stations</p>
<p>5 free license with BE 11d<br />Continuous Protection<br />DLO (desktop laptop option)is ideal for a mobile work force<br />synchronization of users work stations<br />end user file retrieval<br />easy to manage and deploy<br />Licenses are available in 10 packs</p>
<p>Backup exec system recovery options &#8211; Do you have a disaster recovery strategy?</p>
<p>Formally livestate recovery &#8211; the old system recovery method was manual and was long and tedious &#8211; repair &#8211; reinstall OS &#8211; reinstall drivers &#8211; reinstall apps &#8211; re configure settings &#8211; apply journal changes &#8211; test &#8211; go live. With new method select recovery point and it can recover the entire system &#8211; only taking minutes and is more reliable with the disk based backup. Disimilar hardware recovery in minutes &#8211; enhanced P2V/V2P virtual conversion capabilities &#8211; streamlined lower priced offering of Backup Exec System Recovery 7.0.</p>
<p><i>More press quotes</i></p>
<p>Dissimilar system recovery &#8211; allows you to recover to different hardware configuration with the same data &#8211; it can even restore to a virtual machine. Backup Exec for Windows Server System Recovery Option &#8211; lower cost then the full solution &#8211; it&#8217;s a stand alone unintegrated solution &#8211; which you could run backup exec 11d on mission critical servers that would allow you to recover in just a few minutes.</p>
<p>Extended platform support<br />X64 windows media server support<br />Vista Support<br />Centralized management<br />NDMP support<br />Oracle<br />Linux/UNIX<br />DB2<br />Mac OSX &#8211; PPC/Intel</p>
<p>Free 60 day trial from <a href="http://www.backupexec.com/">www.backupexec.com</a><br /><i>* there are even forums there WOWWEE /sarcasm off</p>
<p></i><br />For Exchange 2007 and Vista  you need the latest Backup Exec 11d patches.</p>
<p>Questions and Answers:</p>
<p>Symantec: Please type your questions for the speaker into this chat pod.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: can we ask tech questions?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Symantec: Liza, you are welcome to ask any questions.<span style="">  </span>We&#8217;ll do our best to answer them.<span style="">  </span>If we can&#8217;t answer them, we&#8217;ll make sure to follow up with you off line.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: my back up wld not restore even if I applied sp5<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: with the new version does it come with tech support?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: VMWARE consolidated backup support on 11d<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: Does the Sharepoint Agent give posting item level recovery? <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Symantec: BE11d includes support if u purchased it w/ support<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: Running BE 11d and had need for Exchange restore of databases. I had been running D2D2T and the restore could not be done with tape. We were able to restore from disk. Could you provide best practice set up D2D2T with Exchange agent?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: compare cps with cdp for exchangebackup<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">guest: We have had some serious issues with Lotus Notes 7.0.2 mail client and the Backup Exec remote agent, has anyone else had issues with this? The agent prevents Lotus from opening.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: will cps on exchange replace brcik level backup<o:p></o:p></p>
<p class="MsoNormal">Rod Sellers: cps itself is very nice<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: We always have files being skipped in the back log in ver. 9.1. How do we prevent that? Thanks<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: I&#8217;m running 11d remote agents to backup my NEtware servers. I use Pre/Post options &#8211; but the Post doesn&#8217;t run. Are there any known issues around this?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Symantec: Recommend reading Exchange Best Practices wp on www.backupexec.com/save<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: HI, we have 400/800G tapes for our backup. Weekly we have a full backup. It is about 399G. What is the best praktice to do a full backup and do not need to use a secound tape? (incremental Backup?)<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: Thanks<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: Backup Exec 11d has been release since 11/06. How come there have been no live updates for this program?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: On the topic of encryption, can Backup Exec backup laptops protected with PGP Whole Disk Encryption?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: Why do they not have updated native support for NetWare and GroupWise?<span style="">  </span>Not everyone runs Exchange<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Symantec: Apologies everyone, slight technical problems.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: On the subject of Lotus Domino, we are also having problems using the Domino option.<span style="">  </span>It skips too many files.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: We are using tapes. we want to convert to disk and do a virtual bkup<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Symantec: Backup Exec 11d launched in Nov06 and build 11d.7170 launched March07 with support for MS Exchange 2007, MS Vista, EMC Celerra devices etc<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: we need to talk to u abt the conversion<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: is this all about MS?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: AD meaning backing up individual users&#8217; files in pcs?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">guest: We have also had issues with 11d and the backup jobs not completing/failing when not being able to connect to machines assigned in the backup job. The Symantec techs also said there is a limit to the amount of machines you can have in one job, what is the limit?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: We are currently using 10D, and would like to upgrade to 11D, however we are still running Exchange 5.5, with a plan to upgrade Exchange to 2003 this year.. Its my understanding that 11D does NOT support less than Exchange 2000. Am I correct here?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: We have been getting weekly updates by liveupdate including SP1.<span style="">  </span>Automatic doesn&#8217;t seem to work though.<span style="">  </span>Try from the tools menu.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: How will the desktop &#038; laptop options work with Windows Vista? Windows Vista already has a built in snapshot for machines?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: Is the automatic feature being looked at as to why is doesn&#8217;t work? Is that a feature they may take out in the next verison?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: Is System Recovery like System Restore in Windows?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: When is the next verison coming out?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: scott, I&#8217;m just another customer.<span style="">  </span>I have other priorities at my site.<span style="">  </span>I just assumed it was because we were using central admin console.<span style="">  </span>I do all the servers manually.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: is this the IDR?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: We have just upgraded to 11d. I am getting the following error message on the sever Backup Exec is running on. Backup- THC1 V-79-57344-3844 &#8211; The media server was unable to connect to the Remote Agent on machine THC1. The media server will use the local agent to try to complete the operation.Remote Agent not detected on \\THC1. The folder it is trying to backup is the Utility Partition. The rest of the server backup up fine without asking for the remote agent. <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: is this included in 11d?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Symantec: To get current 11d updates go to: http://seer.entsupport.symantec.com/docs/289968.htm<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: Does Symantec have an Archiving solution that works w/ Backup Exec?<span style="">  </span>We have about 1 TB of data that needs to be archived off in a near line device that can be accessed when necessary. <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Symantec: Yes, BE11d for Exchage w/ CPS eliminates Brick Level Backup<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Symantec: Ceballos &#8211; <st1:city st="on"><st1:place st="on">Enterprise</st1:place></st1:City> Vault http://www.symantec.com/enterprise/products/overview.jsp?pcid=2244&#038;pvid=322_1<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: Is the Advanced File Open option free with 11D?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: migration from 9.1 to 11d is free?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: I need help in migration after the 11d comes.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: Is the Advanced Open File option free with 11d?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Symantec: Frandin &#8211; Yes BE11d only supports Exchange 2K, 2K3, 2k7<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: how to get the ppt presentation<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: ok ty!<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: give an over view os sss<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Symantec: MClark &#8211; AOFO is a purchased addonn<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: Is it per server?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: I understand that I need a VIP Update for 11.0.<span style="">  </span>Where can I get this?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: please review share storage option <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Symantec: live update<span style="">  </span>http://seer.entsupport.symantec.com/docs/289968.htm<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: Could you do an overview on the Backup to Disk to Tape technologies?<o:p></o:p></p>
<p class="MsoNormal">Guest: Do you have a whitepaper that compares your product to others? Specifically we are using Syncsort and I want to convert but will have to do justification and any help would be appreciated.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Symantec: Agents /Options: http://www.symantec.com/enterprise/products/agents_options.jsp?pcid=2244&#038;pvid=57_1<br />Symantec: Nick, today&#8217;s webcast is being recorded.<span style="">  </span>A link to this recording will be available shortly on http://www.carahsoft.com/events/index.php.<span style="">  </span>It will also be sent to you in a follow-up email.<br /> <!--[if !supportLineBreakNewLine]--><br /> <!--[endif]--></p>
<p class="MsoNormal">Guest: how can we tell if we are current on maintenance?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: can you give us teh link to the upgrade <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Symantec: www.backupexec.com/save<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: 9.1 version support has expired. I just ordered 11d does this mean I have to order support separately?</p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Symantec: You can order 11d with or without support<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: if we have IDR in 10d, does it get upgraded to live state?</p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: vmware review</p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: Does BackUp Exec cover laptops encrypted with PGP Whole Disk Encryption?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: presentation ppt file</p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Symantec: <a href="http://www.carahsoft.com/events/index.php">http://www.carahsoft.com/events/index.php</a></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Guest: system recovery has to be ordered separate?</p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">As you can see some questions went unanswered</p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">This seminar used Adobe Acrobat Connect &#8211; this is the first time I&#8217;ve run across this remote seminar solution. I&#8217;m not too impressed with the look and feel being a spectator &#8211; maybe it is more powerful on the moderator side. Though it did have that new web 2.0 technology where you enter in your phone number and it calls you &#8211; so it has that going for it.</p>
]]></content:encoded>
			<wfw:commentRss>http://creeva.com/2007/09/13/agents-and-options-for-symantec-backup-exec-11d-the-gold-standard-in-data-recovery/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Symantec Endpoint Protection 11.0</title>
		<link>http://creeva.com/2007/09/11/symantec-endpoint-protection-110/</link>
		<comments>http://creeva.com/2007/09/11/symantec-endpoint-protection-110/#comments</comments>
		<pubDate>Tue, 11 Sep 2007 17:55:20 +0000</pubDate>
		<dc:creator>Creeva</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Amazon]]></category>
		<category><![CDATA[Band]]></category>
		<category><![CDATA[Centralize]]></category>
		<category><![CDATA[design]]></category>
		<category><![CDATA[Environment]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Group Policy]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[LOL]]></category>
		<category><![CDATA[Nintendo]]></category>
		<category><![CDATA[past]]></category>
		<category><![CDATA[Picture]]></category>
		<category><![CDATA[Sites]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[Test]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Video]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://creeva.com/2007/09/11/symantec-endpoint-protection-110/</guid>
		<description><![CDATA[I&#8217;m currently in a webex seminar for Symantec Endpoint Security &#8211; the moderator has not joined yet. I thought I would share thoughts and ideas as this went along &#8211; and for reference to myself at a later date. I realize this is no apple speech or Nintendo launch &#8211; but we all have to [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m currently in a webex seminar for Symantec Endpoint Security &#8211; the moderator has not joined yet. I thought I would share thoughts and ideas as this went along &#8211; and for reference to myself at a later date. I realize this is no apple speech or Nintendo launch &#8211; but we all have to get our real time blogging skills up to date somehow. I signed and view no disclosure agreement in the invitation that was given to me and I would not have violated it if I did. This is not specific to my job or company so I don&#8217;t feel I&#8217;m violating any trust.</p>
<p>The seminar is scheduled to be 1 hour and 15 minutes &#8211; unless it&#8217;s a really short seminar and its only 1 minute 15 seconds &#8211; in that case I guess this is a hug waste of time.</p>
<p>Waiting for the moderator &#8211; we just got a message that the seminar will start in 3 minutes &#8211; 2 minutes late btw.</p>
<p>The presenter according to the slide is <a href="http://amazon.com/gp/product/B000TGJ826?ie=UTF8&amp;tag=creswor20-20&amp;link_code=em1&amp;camp=212341&amp;creative=384049&amp;creativeASIN=B000TGJ826&amp;adid=aca6b746-aeeb-4076-a2fb-299b54052d65" title="B000TGJ826" name="B000TGJ826" id="amzn_cl_link_0" target="_blank">Kevin Haley</a>, Director of Technical Product Management in the Endpoint Security Group.</p>
<p>Since my understanding is that replaces Symantec Anti-virus there is a drastic change as they consolidate all the products they have purchased in the past trying to get them to work cohesively.</p>
<p>The seminar just started only 4 minutes late.</p>
<p>Kevin is responsible for Symantec End Point protection.</p>
<p>Agenda:<br />
Goals of the seminar<br />
Overview of the product<br />
Migration and Migration issues<br />
Additional tools</p>
<p>Goals:</p>
<p>They&#8217;ve muted the participants for our own anonymity *roll eyes* &#8211; I know from experience that this is solely to not get stopped by possible trigger points that listeners may have.</p>
<p>We have options of typing in questions and getting them answered in real time.</p>
<p>Product Overview:</p>
<p>Symantec Endpoint Protection 11.0 and Symantec Multi-tier protections 11.0</p>
<p>Multi tier is the new version of <a href="http://amazon.com/gp/product/B00006IIT3?ie=UTF8&amp;tag=creswor20-20&amp;link_code=em1&amp;camp=212341&amp;creative=384049&amp;creativeASIN=B00006IIT3&amp;adid=10646204-89dc-4779-848b-3ef5ec79fc34" title="B00006IIT3" name="B00006IIT3" id="amzn_cl_link_1" target="_blank">SAV Enterprise Edition</a> 8, 9, 10 &#8211; customer with upgrade protection and support with Symantec will get a free upgrade. This also includes SAV for Mac OSX.</p>
<p><a href="http://amazon.com/gp/product/B000WIZPAA?ie=UTF8&amp;tag=creswor20-20&amp;link_code=em1&amp;camp=212341&amp;creative=384049&amp;creativeASIN=B000WIZPAA&amp;adid=31f006b3-87d3-4def-bbee-8355afb3b6f0" title="B000WIZPAA" name="B000WIZPAA" id="amzn_cl_link_2" target="_blank">Endpoint protection</a> 11.0 &#8211; is the upgrade for SAV CE, SCS, Symantec Sygate Enterprise Protection, and Whole Confidence online for corporate PC&#8217;s get this in their upgrade contract</p>
<p>They now took a poll if we entered the beta test for Symantec Endpoint Protection &#8211; 9% did public &#8211; 20% did external and 69% did not (this was a seminar poll for the participants.</p>
<p>They are talking about the reasons for integrating everything</p>
<p>Parts</p>
<p>Antispyware &#8211; Leads in root kit detection and removal <em>*unless they are keeping quiet for Sony</em><br />
Antivirus</p>
<p>Firewall technology &#8211; taken from <a href="http://amazon.com/gp/product/B000EXS1DG?ie=UTF8&amp;tag=creswor20-20&amp;link_code=em1&amp;camp=212341&amp;creative=384049&amp;creativeASIN=B000EXS1DG&amp;adid=6f967600-fd3e-44c0-8788-b7e9d3586191" title="B000EXS1DG" name="B000EXS1DG" id="amzn_cl_link_3" target="_blank">Symantec Client Security</a> and Sygate</p>
<p>Intrusion Prevention &#8211; Behavior Based Threat protection &#8211; SONAR whole security &#8211; network traffic protection</p>
<p>Device Control/ Application Control</p>
<p>Network Access Control &#8211; add on client</p>
<p>New client is all bubbly and vista like &#8211; take that how you want. New help and support button allows some basic troubleshooting info in one spot. Access to windows accounts info, disk space, log files, and version information. You can also import or export policies from the client. Any client installed by default from the CD are initially self managed &#8211; if you want them to be managed by default you need to create an installation package on your management server.</p>
<p>You can change all policies not just the firewall based on location.</p>
<p>The file that tells if the client is managed or unmanaged is located in the file sylink.xml &#8211; contains also server list, certificate info, heartbeat, and communications. There is a tool to auto edit the file included on the cd for easy managed to unmanaged deployment. You could also edit this manually and the file is said to be documented.</p>
<p><a href="http://amazon.com/gp/product/193226647X?ie=UTF8&amp;tag=creswor20-20&amp;link_code=em1&amp;camp=212341&amp;creative=384049&amp;creativeASIN=193226647X&amp;adid=886a96e6-af70-4d0e-84c4-866e85bc407e" title="193226647X" name="193226647X" id="amzn_cl_link_4" target="_blank">Intrusion prevention</a> capability &#8211; network based intrusion prevention tied into the tcp stack &#8211; generic exploit blocking from SCS and Sygate IDS which supports custom signatures &#8211; signature format is similar to Snort. Behavior blocking &#8211; proactive threat scan from whole security &#8211; innovative behavior based analysis &#8211; uniquely accurate low .004% false positive rate (testing for 2 years) via the web site and the consumer product (your enterprise beta testers) &#8211; enables broad deployment on endpoints. 20 million installations during the test &#8211; so 40 false positives for every 1 million PC&#8217;s &#8211; can also do white listing so false positives only show up once.</p>
<p>Stupid picture of a cookie jar with a digital camera and video camera &#8211; cookies disappear in the night and you want to catch who is doing this used camera for random images or camcorder you can review the film later but the camcorder solution is more expensive &#8211; so proactive threat scanning takes a picture of all the processes every 15 minutes and analyzes it. <em>*is this seriously the best analogy?????????</em></p>
<p>Application Control &#8211; you can disable certain application</p>
<p>Device protection &#8211; block devices by type &#8211; trying to stop items like USB, infrared, Bluetooth, serial , parallel , firewire, scsi, PCMCIA &#8211; can block read/write execute on burnable media drives &#8211; can block all USB except keyboard and mouse &#8211; <em>*I would just use a browser</em></p>
<p>Features overview<br />
email report distribution on a schedule<br />
centralized event logging<br />
customizable reports<br />
real time event viewing<br />
notifications view<br />
event export to SSIM or 3rd part<br />
Embedded and MS SQL support<br />
Client install package builder<br />
patch and update<br />
remote installation<br />
import and sync with Ad<br />
authenticate with AD<br />
customized agent package installation<br />
Migration from SAV, SCS, SSEP,&amp; SNAC<br />
Centralized Web Based console<br />
Simplified interface for SMB and enterprise<br />
Role Based Access<br />
Administrative domains<br />
Assign rights by user or group<br />
User defined multi tier groups<br />
<a href="http://amazon.com/gp/product/B000MW8YJU?ie=UTF8&amp;tag=creswor20-20&amp;link_code=em1&amp;camp=212341&amp;creative=384049&amp;creativeASIN=B000MW8YJU&amp;adid=86477cb9-a04a-443e-839d-d6ab47d7ca92" title="B000MW8YJU" name="B000MW8YJU" id="amzn_cl_link_5" target="_blank">RSA SecurID</a><br />
Integrated management of all agent components<br />
single console for management of AV, FW, NAC and other policies<br />
Group based polices<br />
- I missed the last two.</p>
<p>Migration</p>
<p>Standard migration steps so far &#8211; document, design, install architecture, migrate existing groups and policies, configure reporting, configure server/site (policies, groups, Admins, notifications etc. , create and test client packages,</p>
<p>Java based Management &#8211; talk to it on HTTPS (admin and client) clients can be configured for HTTP if you want unencrypted traffic- SQL database for storage.</p>
<p>Database contains<br />
Group structure<br />
policies<br />
patches<br />
logs<br />
content</p>
<p>only replicates<br />
Group Policies/Logs/Content</p>
<p>SQL can be separate from the management sever &#8211; many management servers can use a single database. Numbers are to be determined but there is basic info in the documentation &#8211; hard numbers will not be available in FCS (First Customer Shipment)</p>
<p>Distributed environment &#8211; multiple management servers and databases &#8211; Management servers always replicate policies and group information between them &#8211; so they will all know about ALL the clients and policies &#8211; any client can check into any server &#8211; but you can restrict that by server or server group &#8211; you can also setup a order it checks in. Logging replication is optional and they call it filtering &#8211; if you have a current architecture where all information rolls up to a master server you can still do that &#8211; or you can replicate all logs to all servers.</p>
<p>Supports migration from SAV, SCS, and SSEP &#8211; clients upgrade to SAV 11.0 will automatically connect to new SESM</p>
<p>Look and feel for reporting data is the same</p>
<p>First use wizard simplifies initial setup</p>
<p>SEPM can run on the save server as a SAV management server since they are designed to coexist since they use different executables.</p>
<p>Migration 1 &#8211; on same server as your SAV server<br />
Install SEPM<br />
Move Group and Policy info from SSE<br />
Install SAV 11<br />
Decommission original Parent server</p>
<p>Migration 2 &#8211; different server<br />
Policies can migrate with first use wizard &#8211; other steps very similar</p>
<p>Reporting migration</p>
<p>Sav 10.1 &#8211; you can redirect clients to the new SEP 11 database for reporting.</p>
<p>Client installation &#8211; support to install over SAV 9-10.1, SCS 3-3.1, SEP 5.1, SPA 5.1 (don&#8217;t have to uninstall these products)</p>
<p>Already rolled out internally at Symantec with 5000 users</p>
<p>First use wizard &#8211; which will enable you to migrate your groups, policies, users to your new management server &#8211; they will not install the client automatically on a management server-so this will have to be done manually. They warn about installing the client firewall on the servers install &#8211; LOL &#8211; I can see why but I wonder how many administrators actually did that.</p>
<p>Content distribution</p>
<p>SEPM gets client updates and content from Symantec live update &#8211; clients can be patched from management server using only a small difference file that can be pushed down.</p>
<p>Still can get content from central internal live update server or rapid release definitions</p>
<p>Clients send events, operation state, and command status to the SEPM server &#8211; commands are sent to client from server, profiles, content, updates sent to client &#8211; content and updates only the different micro definitions they don&#8217;t&#8217; have are sent instead of all the definitions each time.</p>
<p>Clients with a group update provider &#8211; will go to the group update provider for content (av defs, etc.)</p>
<p>The group update providers caches information from the SEPM server &#8211; designed for low bandwidth architectures.</p>
<p>Unmanaged clients can still go to live update on their own</p>
<p>Additional tools</p>
<p>http://edm.symantec.com/endpointsecurity/</p>
<p>http://www.symantec.com/endpointsecurity/migrate &#8211; migration information<br />
Consulting Services and support</p>
<p>Goodbyes and that&#8217;s the end</p>
<p>Questions and Answer from the text box:+</p>
<p>Question: Sorry missed what said&#8230; Did you mention <a href="http://amazon.com/gp/product/0596006608?ie=UTF8&amp;tag=creswor20-20&amp;link_code=em1&amp;camp=212341&amp;creative=384049&amp;creativeASIN=0596006608&amp;adid=af3f4168-e2e6-422e-9152-ac3d420a9462" title="0596006608" name="0596006608" id="amzn_cl_link_6" target="_blank">Macintosh</a> would be included?<br />
Answer: Yes, MAC will be included<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Will the Multi-Tier console server handle Macintosh clients?<br />
Answer: MAC will not be managed by the SEPM console this release<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Will it be <st1:place st="on">Vista</st1:place> compliant?<br />
Answer: Yes<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Will the Symantec Multi-tier Protection for MAC be able to utilize the Parent Servers for Windows?<br />
Answer: No. MAC has its own console as it stands today.<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Asking about the console. Will there still be a seperate console server for Macs?<br />
Answer: Yes<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: So there won&#8217;t be a Mac solution if we&#8217;re a SEPM customer?<br />
Answer: MAC is included in the Multi-Tier Protection but it is managed by a seperate console and server structure<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: What is the upgrade from SAVCE<br />
Answer: Symantec Endpoint Protection 11.0<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: is the full endpoint suite required, or can you still purchase products separately?<br />
Answer: You get everything as long as you are current on maintenance.<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Assuming no more console?<br />
Answer: MAC will be managed by its own console. SEPM will manage all windows clients<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Can you turn off various components?<br />
Answer: Yes, you can enable and disable the features as needed.<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Will it have built in reporting capabilities or do we need to continue with SAV reporter?<br />
Answer: SEPM has reporting built in.<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Will the SEP v11 console be able to managed legacy clients (SAV10, etc)<br />
Answer: No. It will not manage legacy SAV clients<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Will this all still be in a single agent?<br />
Answer: Yes, Single Client with all the mentioned technologies<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Will these products be Vista logo&#8217;d or just <st1:place st="on">Vista</st1:place> compliant? Also will you be providing both 32bit and 64bit clients?<br />
Answer: Yes, we will be providing both 32 and 64 bit versions of the client. <st1:place st="on">Vista</st1:place> compliant.<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: What? We will need to run multiple consoles? Will they all feed into SSIM?<br />
Answer: SEPM will manage the windows clients only with this release. Yes, we will have a collector for SSIM<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Will we go over migrating an existing Reporting Server to the built-in reporting in SEPM?<br />
Answer: There is a white paper that will be available as well as a migration wizard<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: would this be red if I disabled it from management side?<br />
Answer: Yes<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: does the user need admin rights to execute a FIX<br />
Answer: The fix can be run as system by the client<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Are there different levels of users provided in the SEPM?<br />
Answer: Yes, administrators can have different functions and rights as configured. There is limited administration.<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Will the 64-bit client differ by processor type, or will the 64-bit client be universal?<br />
Answer: Universal<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Current installation from CD presents you an option to choose the management server if you want to install managed. Why has that been removed?<br />
Answer: You can create packages that are &#8220;unmanaged&#8221; still it is just a different process.<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: can it be locked so a cleint can&#8217;t remove from a server?<br />
Answer: Yes<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: In previous versions, we could specify management server. This is not possible</p>
<p class="MsoNormal">now?<br />
Answer: Yes. It still is possible to specify the server that will manage the client.<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Will the client upgrade handle all current individual components that may be installed on the desktop (SSEP, SAV10, etc.)?<br />
Answer: Yes, absolutely<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Does the new policy import/export replace the usage of GRC.dat and the need to at times manually implement it.<br />
Answer: Yes. Sylink.xml is the new file used.<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Will the SPEM have the ability to set security access for other users/groups to manage their servers or sites?<br />
Answer: Yes<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: So the sylink.xml replaces the grc.dat except it doesnt disappear once processed by the client?<br />
Answer: Yes, exactly<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: When will this release be available?<br />
Answer: End of the month<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: can you import SNORT signaturs?<br />
Answer: No, we support REGEX and have a language similiar to snort<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Is there a maximum network latency value between a policy sevrer andf end client that we should consider when determine the count and location of policy servers on our global network?<br />
Answer: We will have a scalability document for distro<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Does the current license also include the signature subscription for IDS?<br />
Answer: Yes<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Has the port range for communication between SErvers and Clients decreased? Or will it still range from 1024-4999?<br />
Answer: It will be SSL<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Will this presentation be available for download so we can share with upper management?<br />
Answer: Via email<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Does the client upgrade require a reboot from version 10.x<br />
Answer: to start the firewall but not for AV protection<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: We currently install the SAVCE client on Windows <a href="http://amazon.com/gp/product/0321357582?ie=UTF8&amp;tag=creswor20-20&amp;link_code=em1&amp;camp=212341&amp;creative=384049&amp;creativeASIN=0321357582&amp;adid=667b2ad4-7608-4b5c-b606-af22cc4bc85f" title="0321357582" name="0321357582" id="amzn_cl_link_7" target="_blank">Server OS</a> managed by a Parent server. Which product is recommended for Windows Server OS or which components are recommeded to be disabled on Server OS?<br />
Answer: SEP can be run on servers and clients. All technologies are portable<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: is the management console still MMC based?<br />
Answer: No<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Is there a reporting server for this similar to the SAV 10 reporting server?<br />
Answer: No, it is integrated now.<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: When will training be available for SEP 11?<br />
Answer: At release<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: will we be able to customize the white list<br />
Answer: Yes<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Does Behavior blocking handle rogue keyloggers?<br />
Answer: Yes<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Will the new console be able to communicate with &#8220;legacy&#8217; SSEP agents (or, can we upgrade the SSEP-PM without requiring the SSEP agents to upgrade at the same time)?<br />
Answer: It will support legacy SSEP clients but not SAV.<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: so just 443 and 80<br />
Answer: Exactly!<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Can specific applications be &#8220;black listed&#8221;?<br />
Answer: Yes<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: what are the functionality differences between Sym Endpoint Protection and Sym Multi-tier Protection?<br />
Answer: Same technologies SMP includes email protection and MAC/<a href="http://amazon.com/gp/product/0131478230?ie=UTF8&amp;tag=creswor20-20&amp;link_code=em1&amp;camp=212341&amp;creative=384049&amp;creativeASIN=0131478230&amp;adid=8314d627-c2d9-41c3-a19a-a5afe8fcb739" title="0131478230" name="0131478230" id="amzn_cl_link_8" target="_blank">linux</a><br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: will the clients listen on a port for server initiated communication, or is the communication only initiated by the client?<br />
Answer: no client listen port. Client initiates all communication to the server<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Will SEP require SQL?<br />
Answer: You can use SQL but the embedded (included) DB is Sybase<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Will mobile devices be supported? If so, what devices?<br />
Answer: Seperate product<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Will the Q&amp;A be made available after the call?<br />
Answer: Yes<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: any chance of getting a copy all the slides to review after the meeting?<br />
Answer: Yes<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Is there an estimate available of the resource impact on a host machines due to the proactive threat scanning?<br />
Answer: We will have this documented and available in a whitepaper<br />
Question: Will SMS5 &#8211; Symantec Mobile Security Suite 5 integrate into SEP?<br />
Answer: No.<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Do the antivirus capabilities within SEP 11 use less resources on a typical client and server? We have many problems with SAV 10 chewing up too much memory and CPU utilization, especially on virtual servers.<br />
Answer: Yes, lower memory footprint<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Is there an override for the USB blocking?<br />
Answer: Yes<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Can devices be blocked based on Manufacturer / Model?<br />
Answer: No- windows class ID, not vendor class ID&#8230;..coming in the future though<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: can usb thumb drives be blocked but other usb devices, ie scanner, printer be allowed?<br />
Answer: Absolutely!<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: is patch/maintenance release management going to be simplified over previous versions? (i.e. all inclusive rollups not requiring previous upgrades to a base version)?<br />
Answer: Definitely<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: so SMP includes the sygate firewall technology?<br />
Answer: Yes!<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: A new version of packager come with this &#8211; I am aware its unsupported but if new version does come with it will it be supported? If not any idea when?<br />
Answer: Packager is gone. The packaging mechanism is the Sygate technology<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Will the schema be available for the database, so we can query it?<br />
Answer: Definitely!!!<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Will SMSDOM (Mail Security for Domino) Still be supported as well as Premium Anti-Spam? How about for Exchange?<br />
Answer: Yes<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Are the INTEL portions from previous NAV/SAV versions been eliminated altogether?<br />
Answer: Yep<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Are the policies for the client available to be pushed via Group Policy in AD?<br />
Answer: Yes<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: can you restrict file types allowed to write to USB drives? i.e. allow MP3, but not DOC or XLS?<br />
Answer: Yes.<br />
Question: Can the Class ID blocking be managed by OUs, say the Director level can use usb drives, regular sales cannot?<br />
Answer: Yes, using grouping<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Can individual components &#8211; say, the firewall portion &#8211; be disabled selectively? For example, we may want AV on a server but not necessarily firewall (even more specifically, for performance savings?).<br />
Answer: YES!<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: What version of java?<br />
Answer: Local version<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: how much space is required for the sql ie per machine?<br />
Answer: DB size will vary by client count<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Does this version get away from storing client information in the registry?<br />
Answer: Yep<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Can the management server be installed on VM?<br />
Answer: Yep!<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Did he say the client port is 80?<br />
Answer: Or 443 depending on selection by administrator<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: is a certificate server required?<br />
Answer: no<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: In the current version of SAV10 Reporting, there is a vulnerability of the PHP component. Will SEPv11 provide better response to layered components that have known vulnerabilities?<br />
Answer: Absolutely!<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: the client/server traffic is based on port 80/443 correct? How is that going to affect clients running websites using port 80/443?<br />
Answer: There should not be a conflict but the ports are configurable<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: from the remediation aspect, will SAFE mode be required for a 100% detection and cleaning?<br />
Answer: Depends on the threat. SEP 11 will clean better than SAV 10 though<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: For replication what type of nbandwidth does it use over a WAN?<br />
Answer: All documented in the scalability doc<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Since the client information is no longer in the registry how can we check AV status through scripts? Is there a WMI interface?<br />
Answer: Some status can still be checked via the registry<br />
Question: Since this is running on 80 or 443 is it using some type of web server underneath for communication (e.g. Tomcat/Apache/etc.)?<br />
Answer: on the manager yes. There is a tomcat server and IIS<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: We have encountered issues with the volume of network traffic generated by corrupted defs. How does the 11.x version address this issue?<br />
Answer: corrupt defs should be a thing of the past.<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: are there any JRE versions that are not supported or are recommended for the management console? Will the client itself require JRE to be installed for SEP to work?<br />
Answer: CLient does not require JRE. The version installed is a local version specific to SEPM.<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: will registry still use intel\landesk\virusprotect6 structure?<br />
Answer: Nope. All intel technologies for management are gone and the registry has been changed as far as structure<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: How can we obtain the scalability document?<br />
Answer: It will be posted at release<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: has sepm been certified for vm<br />
Answer: We support VM environments. Not sure if it is certified by VM<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Why is this not backwards capable with SAV 10 or 9? Upgrading an entire enterprise can take a while.<br />
Answer: Completely different management architecture.<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: is there a method for users to alter administrative scan schedule (but not any other option)?<br />
Answer: Yes<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: what about Sygate 4.1?<br />
Answer: no<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Will you be able to save all the old data from the SAV 10.1?<br />
Answer: yes, migration wizard will cover this<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: no over intall for 7.x is that correct<br />
Answer: right<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: OVerinstall of 10.2 for <st1:place st="on">Vista</st1:place> supported?<br />
Answer: yes<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: he said that scalability doc will be available about a month after SEP 11.0 release<br />
Answer: probably sooner<br />
Question: when you overinstall does this require a reboot on the endpoint<br />
Answer: Yes, but not for AV, just for the FW<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Will the overinstall work even if the previous client is password protected? Or will it still require a registry hack to remove?<br />
Answer: It will work<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: can SAV10 client groups be migrated, or is there granularity to support that type of group?<br />
Answer: Migration wizard will allow this<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Does SEP support NT4.0 clients?<br />
Answer: no<br />
Question: does it work on vm . Currently version 10 I have on vm<br />
Answer: Yes<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Is the upgrade to SAV 11 more reliable than the upgrade to SAV 10? We were forced to use NONAV to pre-clean the SAV 8 and SAV 9 systems before going to SAV 10<br />
Answer: Yes.<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: What is the SEPM blog URL?<br />
Answer: https://forums.symantec.com/syment?category.id=endpoint<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Is the installer follow standard MSI best practices?<br />
Answer: Yes<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: will management server install require reboot (windows server 2003)?<br />
Answer: no<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: This includes central management and reporting for the FW?<br />
Answer: Yes<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Any problems creating an SMS package for installing to clients?<br />
Answer: no<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: to install over 4.1 do you need to uninstall 4.1, reboot and install SEP or can you uninstall 4.1, install SEP and reboot?<br />
Answer: Yes<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Can our TAM answer questions regarding SEP 11 yet? Or do we have to wait until the release?<br />
Answer: Yes<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: We run <a href="http://amazon.com/gp/product/B000A7Q0CU?ie=UTF8&amp;tag=creswor20-20&amp;link_code=em1&amp;camp=212341&amp;creative=384049&amp;creativeASIN=B000A7Q0CU&amp;adid=85557c3a-f406-4c21-b182-de2ef773f545" title="B000A7Q0CU" name="B000A7Q0CU" id="amzn_cl_link_9" target="_blank">Symantec Mail Security</a> for Exchange. If we run SEPv11 on the same box, are the defs compatible? Can they co-exist?<br />
Answer: They can co-exist<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: you mentioned earlier that the client initiates all contact with the server. What about Virus sweeps, updates that you want to push, do you have to wait til the next time the client checks in<br />
Answer: No</p>
<p>Question: does the patch require a reboot? We have lots a 24&#215;7 servers.<br />
Answer: no</p>
<p>Question: Will the dif patch require reboots on the clients?<br />
Answer: no</p>
<p>Question: No problem to run in a mixed environment, e.g. legacy clients reporting to previous management console, newer clients reporting to newer management console?<br />
Answer: no problem with a parallel environment</p>
<p>Question: We are going to have a lot of language requirements (Thai, German, French, Russian, Swedish, Japannesse, Chinesse). Is there a link on your web page to the supported language versions?<br />
Answer: It will be posted but is not right now. Should be at release time. We are localizing alot of languages</p>
<p>Question: For definition distribution, what is the approx size of the diff-defs? If a client has been off the network for a week or longer, what is the approx size of the diff-def?<br />
Answer: will vary</p>
<p>Question: Thanks for the GUP!!<br />
Answer: :)</p>
<p>Question: If a client goes to a GUP and then that client goes to another group will it still look for the GUP group A<br />
Answer: no<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: With ver9 and &gt; Symantec expanded the feature set to combat spyware and malware, many customers complained of CE being bloated, memory-intensive, and causing issues with many line-of-business applications. With all these added features in this new product release can you point to any documentation related to this version benchmarks and/or performance specs compared to previous releases?<br />
Answer: Its all documented. Check the portal<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: will rapid release definitions be available for the Liveupdate server?<br />
Answer: yes with LUA 2.5<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Not sure if this was asked. But when a client connects to a 11.0 server does it use a certificate like in the past for communications?<br />
Answer: no<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: Can the gups be configured as Primary, secondary, and can the clients recognize that<br />
Answer: no<br />
<!--[if !supportLineBreakNewLine]--><br />
<!--[endif]--></p>
<p class="MsoNormal">Question: when will this be available for download from the platinum site?<br />
Answer: end of the month</p>
<p>Question: Thank You<br />
Answer: You are welcome</p>
<p><script src="http://feeds.feedburner.com/%7Es/CreevasWorld20?i=http://www.creeva.com/2007/09/symantec-endpoint-protection-110.html" charset="utf-8" type="text/javascript"></script><script src="http://feeds.feedburner.com/%7Es/CreevasWorld20?i=http%3A//www.creeva.com/2007/09/symantec-endpoint-protection-110.html&amp;showad=true" type="text/javascript"></script> <script type="text/javascript"><!--  google_ad_client="pub-2850455207197635";  google_ad_host="pub-0720175472434865";  google_ad_width=468;  google_ad_height=60;  google_ad_format="468x60_as";  google_ad_type="text_image";  google_color_border="CCCCCC";  google_color_bg="CCCCCC";  google_color_link="000000";  google_color_url="666666";  google_color_text="333333";  //--></script></p>
]]></content:encoded>
			<wfw:commentRss>http://creeva.com/2007/09/11/symantec-endpoint-protection-110/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Symantec Enterprise Firewall &#8211; Solutions Guide for Load Balanced NAT Issues</title>
		<link>http://creeva.com/2005/06/27/symantec-enterprise-firewall-solutions-guide-for-load-balanced-nat-issues/</link>
		<comments>http://creeva.com/2005/06/27/symantec-enterprise-firewall-solutions-guide-for-load-balanced-nat-issues/#comments</comments>
		<pubDate>Mon, 27 Jun 2005 17:46:19 +0000</pubDate>
		<dc:creator>Creeva</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Band]]></category>
		<category><![CDATA[Consultant]]></category>
		<category><![CDATA[Family]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Load Balancing]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[SEF]]></category>
		<category><![CDATA[SGS]]></category>
		<category><![CDATA[Symantec]]></category>

		<guid isPermaLink="false">http://creeva.com/?p=2686</guid>
		<description><![CDATA[&#60;!&#8211; /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {mso-style-parent:&#8221;"; margin:0in; margin-bottom:.0001pt; mso-pagination:widow-orphan; font-size:12.0pt; font-family:&#8221;Times New Roman&#8221;; mso-fareast-font-family:&#8221;Times New Roman&#8221;;} @page Section1 {size:8.5in 11.0in; margin:1.0in 1.25in 1.0in 1.25in; mso-header-margin:.5in; mso-footer-margin:.5in; mso-paper-source:0;} div.Section1 {page:Section1;} /* List Definitions */ @list l0 {mso-list-id:572855412; mso-list-type:hybrid; mso-list-template-ids:-1186181492 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 {mso-level-tab-stop:.5in; mso-level-number-position:left; text-indent:-.25in;} [...]]]></description>
			<content:encoded><![CDATA[<p><!--[if gte mso 9]><xml> <w :WordDocument> </w><w :View>Normal</w> <w :Zoom>0</w> <w :PunctuationKerning /> <w :ValidateAgainstSchemas /> <w :SaveIfXMLInvalid>false</w> <w :IgnoreMixedContent>false</w> <w :AlwaysShowPlaceholderText>false</w> <w :Compatibility> <w :BreakWrappedTables /> <w :SnapToGridInCell /> <w :WrapTextWithPunct /> <w :UseAsianBreakRules /> <w :DontGrowAutofit /> </w> <w :BrowserLevel>MicrosoftInternetExplorer4</w>  </xml>< ![endif]--><!--[if gte mso 9]><xml> <w :LatentStyles DefLockedState="false" LatentStyleCount="156"> </w> </xml>< ![endif]--> &lt;!&#8211;  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:&#8221;"; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:&#8221;Times New Roman&#8221;; 	mso-fareast-font-family:&#8221;Times New Roman&#8221;;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:572855412; 	mso-list-type:hybrid; 	mso-list-template-ids:-1186181492 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l1 	{mso-list-id:1128162760; 	mso-list-type:hybrid; 	mso-list-template-ids:-592835512 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l1:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l2 	{mso-list-id:1157769049; 	mso-list-type:hybrid; 	mso-list-template-ids:1523214700 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l2:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l3 	{mso-list-id:1258293677; 	mso-list-type:hybrid; 	mso-list-template-ids:-1536103412 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l3:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l4 	{mso-list-id:1437094087; 	mso-list-type:hybrid; 	mso-list-template-ids:1230905382 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l4:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l5 	{mso-list-id:1599633008; 	mso-list-type:hybrid; 	mso-list-template-ids:-493076830 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l5:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l6 	{mso-list-id:1631399832; 	mso-list-type:hybrid; 	mso-list-template-ids:417990644 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l6:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l7 	{mso-list-id:1964076882; 	mso-list-type:hybrid; 	mso-list-template-ids:-135861800 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l7:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} &#8211;&gt; <!--[if gte mso 10]><br />
<style>
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman";
	mso-ansi-language:#0400;
	mso-fareast-language:#0400;
	mso-bidi-language:#0400;}
</style>
<p> < ![endif]--></p>
<p class="MsoNormal" style="text-align: left;">I wrote this document for a customer back in 2005 when I was a <a href="http://www.symantec.com">Symantec</a> Consultant &#8211; posting it from 2008 in the right time period.</p>
<p class="MsoNormal" style="text-align: center;" align="center">
<p class="MsoNormal" style="text-align: center;" align="center"><strong><span style="text-decoration: underline;">Solutions Guide for Load Balanced NAT Issues</span></strong></p>
<p class="MsoNormal">
<p class="MsoNormal">
<p class="MsoNormal">These are solutions to possible load balancing issue you may encounter with the Symantec Firewall load balancing methods.<span> </span>The assumption is problems you would encounter going from an internal network to an Internet host or network.<span> </span>These problems also rarely occur and are usually an issue depending on the security of the remote host.</p>
<p class="MsoNormal">
<p class="MsoNormal">
<p class="MsoNormal"><strong>Scenario:</strong> Multiple TCP connections on the same port leaving with different outside NAT addresses causes the remote server to reject the connection.</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Example:</strong> HTTPS connections that do not use a client side cookie.</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Solutions:</strong></p>
<ol style="margin-top: 0in;" type="1">
<li class="MsoNormal">We can      use stateful failover for the TCP traffic and all traffic would leave as      the VIP address. The downside is some increased load on all the firewalls      in the cluster.</li>
<li class="MsoNormal">Have a      one to one NAT configured, this would correct that issue as the client      would always be seen as the NAT address you configured.<span> </span>The downside is that you need a public      IP address for every machine you would do this for.</li>
<li class="MsoNormal">We can      use original client address. The downside of this would require you to      have publicly routable addresses going to the outside of the firewall.<span> </span>It would also allow the outside world to      see your internal networking schema.</li>
<li class="MsoNormal">Pass      the traffic through a filter.<span> </span>The      downside is that this passes below the proxy level and tight controls      would need to be in place to maintain security.<span> </span>Also you would need publicly routable IP      addresses or NAT the traffic on the upstream router.<span> </span>If you use public addresses internal and      do not on the router it would allow the outside world to see your internal      networking schema.</li>
<li class="MsoNormal">Use      traffic grouping, this ensures all traffic to the configured host goes      through only one firewall at a time.<span> </span>The downside is administration level is higher due to the need of      configuring remote hosts manually.</li>
<li class="MsoNormal">Hardware      Load balancer.<span> </span>The downside is that      this is out of Symantec’s control and immediate scope.<span> </span>It would require reliance on a third      party product.</li>
<li class="MsoNormal">Manually      route traffic through only one firewall.<span> </span>This would have the traffic corrected by having traverse one      firewall only.<span> </span>The downside is      administration level required to perform this.<span> </span>Another issue is if the firewall that is      passing the traffic goes down the connection would not work or network      administrators would have to configure a route change on the router      directing this traffic.</li>
</ol>
<p class="MsoNormal">
<p class="MsoNormal">
<p><span style="font-size: 12pt; font-family: &quot;Times New Roman&quot;;"><br style="page-break-before: always;" /> </span></p>
<p class="MsoNormal"><strong>Scenario:</strong> A connection that requires multiple TCP destination ports.</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Example:</strong> Passive mode FTP (which the FTP daemon can handle this without modification; lack of a more common protocol as an example is not immediately available.)</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Solutions:</strong></p>
<ol style="margin-top: 0in;" type="1">
<li class="MsoNormal">We can      use stateful failover for the TCP traffic and all traffic would leave as      the VIP address. The downside is some increased load on all the firewalls      in the cluster.</li>
<li class="MsoNormal">Have a      one to one NAT configured, this would correct that issue as the client      would always be seen as the NAT address you configured.<span> </span>The downside is that you need a public      IP address for every machine you would do this for.</li>
<li class="MsoNormal">We can      use original client address. The downside of this would require you to      have publicly routable addresses going to the outside of the      firewall.<span> </span>It would also allow the      outside world to see your internal networking schema.</li>
<li class="MsoNormal">Pass      the traffic through a filter.<span> </span>The      downside is that this passes below the proxy level and tight controls      would need to be in place to maintain security.<span> </span>Also you would need publicly routable IP      addresses or NAT the traffic on the upstream router.<span> </span>If you use public addresses internal and      do not on the router it would allow the outside world to see your internal      networking schema.</li>
<li class="MsoNormal">Use      traffic grouping, this ensures all traffic to the configured host goes      through only one firewall at a time.<span> </span>The downside is administration level is higher due to the need of      configuring remote hosts manually.</li>
<li class="MsoNormal">Hardware      Load balancer.<span> </span>The downside is that      this is out of Symantec’s control and immediate scope.<span> </span>It would require reliance on a third      party product.</li>
<li class="MsoNormal">Manually      route traffic through only one firewall.<span> </span>This would have the traffic corrected by having traverse one      firewall only.<span> </span>The downside is      administration level required to perform this.<span> </span>Another issue is if the firewall that is      passing the traffic goes down the connection would not work or network      administrators would have to configure a route change on the router      directing this traffic.</li>
</ol>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Scenario:</strong> A mixture of UDP and TCP traffic.</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Example:</strong><span> </span>This is usually seen in custom applications such as streaming media where the connection starts on TCP and migrates over to UDP for media delivery.</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Solutions:</strong></p>
<ol style="margin-top: 0in;" type="1">
<li class="MsoNormal">Have a      one to one NAT configured, this would correct that issue as the client      would always be seen as the NAT address you configured.<span> </span>The downside is that you need a public      IP address for every machine you would do this for.</li>
<li class="MsoNormal">We can      use original client address. The downside of this would require you to      have publicly routable addresses going to the outside of the      firewall.<span> </span>It would also allow the      outside world to see your internal networking schema.</li>
<li class="MsoNormal">Pass      the traffic through a filter.<span> </span>The      downside is that this passes below the proxy level and tight controls      would need to be in place to maintain security.<span> </span>Also you would need publicly routable IP      addresses or NAT the traffic on the upstream router.<span> </span>If you use public addresses internal and      do not on the router it would allow the outside world to see your internal      networking schema.</li>
<li class="MsoNormal">Use      traffic grouping, this ensures all traffic to the configured host goes      through only one firewall at a time.<span> </span>The downside is administration level is higher due to the need of      configuring remote hosts manually.</li>
<li class="MsoNormal">Hardware      Load balancer.<span> </span>The downside is that      this is out of Symantec’s control and immediate scope.<span> </span>It would require reliance on a third      party product.</li>
<li class="MsoNormal">Manually      route traffic through only one firewall.<span> </span>This would have the traffic corrected by having traverse one      firewall only.<span> </span>The downside is      administration level required to perform this.<span> </span>Another issue is if the firewall that is      passing the traffic goes down the connection would not work or network      administrators would have to configure a route change on the router      directing this traffic.</li>
</ol>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Scenario:</strong> TCP and IP traffic mixture.</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Example:</strong> <span> </span>Microsoft’s PPTP VPN.<span> </span>This product uses port 1723 TCP and IP type 47 to pass traffic.</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Solutions:</strong></p>
<ol style="margin-top: 0in;" type="1">
<li class="MsoNormal">Have a      one to one NAT configured, this would correct that issue as the client      would always be seen as the NAT address you configured.<span> </span>The downside is that you need a public      IP address for every machine you would do this for.</li>
<li class="MsoNormal">We can      use original client address. The downside of this would require you to      have publicly routable addresses going to the outside of the      firewall.<span> </span>It would also allow the      outside world to see your internal networking schema.</li>
<li class="MsoNormal">Pass      the traffic through a filter.<span> </span>The      downside is that this passes below the proxy level and tight controls      would need to be in place to maintain security.<span> </span>Also you would need publicly routable IP      addresses or NAT the traffic on the upstream router.<span> </span>If you use public addresses internal and      do not on the router it would allow the outside world to see your internal      networking schema.</li>
<li class="MsoNormal">Use      traffic grouping, this ensures all traffic to the configured host goes      through only one firewall at a time.<span> </span>The downside is administration level is higher due to the need of      configuring remote hosts manually.</li>
<li class="MsoNormal">Hardware      Load balancer.<span> </span>The downside is that      this is out of Symantec’s control and immediate scope.<span> </span>It would require reliance on a third      party product.</li>
<li class="MsoNormal">Manually      route traffic through only one firewall.<span> </span>This would have the traffic corrected by having traverse one      firewall only.<span> </span>The downside is      administration level required to perform this.<span> </span>Another issue is if the firewall that is      passing the traffic goes down the connection would not work or network      administrators would have to configure a route change on the router      directing this traffic.</li>
</ol>
<p class="MsoNormal">
<p><span style="font-size: 12pt; font-family: &quot;Times New Roman&quot;;"><br style="page-break-before: always;" /> </span></p>
<p class="MsoNormal"><strong>Scenario:</strong> UDP connections using multiple ports</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Example:</strong> No known examples available for reference.</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Solutions:</strong></p>
<ol style="margin-top: 0in;" type="1">
<li class="MsoNormal">Have a      one to one NAT configured, this would correct that issue as the client      would always be seen as the NAT address you configured.<span> </span>The downside is that you need a public      IP address for every machine you would do this for.</li>
<li class="MsoNormal">We can      use original client address. The downside of this would require you to      have publicly routable addresses going to the outside of the      firewall.<span> </span>It would also allow the      outside world to see your internal networking schema.</li>
<li class="MsoNormal">Pass      the traffic through a filter.<span> </span>The      downside is that this passes below the proxy level and tight controls      would need to be in place to maintain security.<span> </span>Also you would need publicly routable IP      addresses or NAT the traffic on the upstream router.<span> </span>If you use public addresses internal and      do not on the router it would allow the outside world to see your internal      networking schema.</li>
<li class="MsoNormal">Use      traffic grouping, this ensures all traffic to the configured host goes      through only one firewall at a time.<span> </span>The downside is administration level is higher due to the need of      configuring remote hosts manually.</li>
<li class="MsoNormal">Hardware      Load balancer.<span> </span>The downside is that      this is out of Symantec’s control and immediate scope.<span> </span>It would require reliance on a third      party product.</li>
<li class="MsoNormal">Manually      route traffic through only one firewall.<span> </span>This would have the traffic corrected by having traverse one      firewall only.<span> </span>The downside is      administration level required to perform this.<span> </span>Another issue is if the firewall that is      passing the traffic goes down the connection would not work or network      administrators would have to configure a route change on the router      directing this traffic.</li>
</ol>
<p class="MsoNormal" style="margin-left: 0.25in;">
<p class="MsoNormal">
<p class="MsoNormal">
<p class="MsoNormal"><strong>Scenario:</strong> UDP and IP traffic mixture.</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Example:</strong> This traffic would mostly be associated with IPSEC VPN traffic.</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Solutions:</strong></p>
<ol style="margin-top: 0in;" type="1">
<li class="MsoNormal">Have a      one to one NAT configured, this would correct that issue as the client      would always be seen as the NAT address you configured.<span> </span>The downside is that you need a public      IP address for every machine you would do this for.</li>
<li class="MsoNormal">We can      use original client address. The downside of this would require you to      have publicly routable addresses going to the outside of the      firewall.<span> </span>It would also allow the      outside world to see your internal networking schema.</li>
<li class="MsoNormal">Pass      the traffic through a filter.<span> </span>The      downside is that this passes below the proxy level and tight controls      would need to be in place to maintain security.<span> </span>Also you would need publicly routable IP      addresses or NAT the traffic on the upstream router.<span> </span>If you use public addresses internal and      do not on the router it would allow the outside world to see your internal      networking schema.</li>
<li class="MsoNormal">Use      traffic grouping, this ensures all traffic to the configured host goes      through only one firewall at a time.<span> </span>The downside is administration level is higher due to the need of      configuring remote hosts manually.</li>
<li class="MsoNormal">Hardware      Load balancer.<span> </span>The downside is that      this is out of Symantec’s control and immediate scope.<span> </span>It would require reliance on a third      party product.</li>
<li class="MsoNormal">Manually      route traffic through only one firewall.<span> </span>This would have the traffic corrected by having traverse one      firewall only.<span> </span>The downside is      administration level required to perform this.<span> </span>Another issue is if the firewall that is      passing the traffic goes down the connection would not work or network      administrators would have to configure a route change on the router      directing this traffic.</li>
</ol>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Scenario:</strong> Multiple IP types only connections.</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Example:</strong> No known examples available for reference.</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Solutions:</strong></p>
<ol style="margin-top: 0in;" type="1">
<li class="MsoNormal">Have a      one to one NAT configured, this would correct that issue as the client      would always be seen as the NAT address you configured.<span> </span>The downside is that you need a public      IP address for every machine you would do this for.</li>
<li class="MsoNormal">We can      use original client address. The downside of this would require you to      have publicly routable addresses going to the outside of the      firewall.<span> </span>It would also allow the      outside world to see your internal networking schema.</li>
<li class="MsoNormal">Pass      the traffic through a filter.<span> </span>The      downside is that this passes below the proxy level and tight controls      would need to be in place to maintain security.<span> </span>Also you would need publicly routable IP      addresses or NAT the traffic on the upstream router.<span> </span>If you use public addresses internal and      do not on the router it would allow the outside world to see your internal      networking schema.</li>
<li class="MsoNormal">Use      traffic grouping, this ensures all traffic to the configured host goes      through only one firewall at a time.<span> </span>The downside is administration level is higher due to the need of      configuring remote hosts manually.</li>
<li class="MsoNormal">Hardware      Load balancer.<span> </span>The downside is that      this is out of Symantec’s control and immediate scope.<span> </span>It would require reliance on a third      party product.</li>
<li class="MsoNormal">Manually      route traffic through only one firewall.<span> </span>This would have the traffic corrected by having traverse one      firewall only.<span> </span>The downside is      administration level required to perform this.<span> </span>Another issue is if the firewall that is      passing the traffic goes down the connection would not work or network      administrators would have to configure a route change on the router      directing this traffic.</li>
</ol>
<p class="MsoNormal">
<p class="MsoNormal">
<p><span style="font-size: 12pt; font-family: &quot;Times New Roman&quot;;"><br style="page-break-before: always;" /> </span></p>
<p class="MsoNormal"><strong>Scenario:</strong> A connection using TCP, UDP, and IP types all in conjunction.</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Example:</strong><span> </span>Older VPN connections that did not adhere to the IPSEC standard.</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Solutions:</strong></p>
<ol style="margin-top: 0in;" type="1">
<li class="MsoNormal">Have a      one to one NAT configured, this would correct that issue as the client      would always be seen as the NAT address you configured.<span> </span>The downside is that you need a public      IP address for every machine you would do this for.</li>
<li class="MsoNormal">We can      use original client address. The downside of this would require you to      have publicly routable addresses going to the outside of the      firewall.<span> </span>It would also allow the      outside world to see your internal networking schema.</li>
<li class="MsoNormal">Pass      the traffic through a filter.<span> </span>The      downside is that this passes below the proxy level and tight controls      would need to be in place to maintain security.<span> </span>Also you would need publicly routable IP      addresses or NAT the traffic on the upstream router.<span> </span>If you use public addresses internal and      do not on the router it would allow the outside world to see your internal      networking schema.</li>
<li class="MsoNormal">Use      traffic grouping, this ensures all traffic to the configured host goes      through only one firewall at a time.<span> </span>The downside is administration level is higher due to the need of      configuring remote hosts manually.</li>
<li class="MsoNormal">Hardware      Load balancer.<span> </span>The downside is that      this is out of Symantec’s control and immediate scope.<span> </span>It would require reliance on a third      party product.</li>
<li class="MsoNormal">Manually      route traffic through only one firewall. <span> </span>This would have the traffic corrected by      having traverse one firewall only.<span> </span>The downside is administration level required to perform this.<span> </span>Another issue is if the firewall that is      passing the traffic goes down the connection would not work or network administrators      would have to configure a route change on the router directing this      traffic.</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://creeva.com/2005/06/27/symantec-enterprise-firewall-solutions-guide-for-load-balanced-nat-issues/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

