[ISSForum] Re: ISS Guard product

2002-11-22 Thread Andrew Plato
of real-world pointers on how to make Guard work optimally. ___ Andrew Plato, CISSP President / Principal Consultant Anitian Corporation ISS Premier Reseller 503-644-5656 Office 503-644-8574 Fax 503-201-0821 Mobile www.anitian.com

[ISSForum] Security Event: IDS Today Tomorrow with Martin Roesch and Robert Graham

2002-12-09 Thread Andrew Plato
I hope its okay to make an announcement on this list. Since this is kind of an ISS event, I figured it would be okay. (see www.anitian.com\itec2002\ids.htm for more information) INTRUSION DETECTION SYSTEMS: TODAY TOMORROW With Martin Roesch Rober Graham Wednesday December 11, 2002 at 12:30

[ISSForum] BlackICE and SQL Slammer

2003-01-29 Thread Andrew Plato
convenience. ___ Andrew Plato, CISSP President / Principal Consultant Anitian Corporation 503-644-5656 Office 503-644-8574 Fax 503-201-0821 Mobile www.anitian.com ___ -BEGIN PGP SIGNATURE- Version: GnuPG v1.0.6 (MingW32

[ISSForum] ICEcap Custom Parameter Field Fix

2003-02-07 Thread Andrew Plato
risk. Download the PDF paper at: http://www.anitian.com/corp/papers/IC_Param_Fix.pdf Download the ZIP file with fixed HTML at: http://www.anitian.com/corp/papers/icecap-param-fix.zip If you have any questions, comments contact me at your convenience. ___ Andrew

[ISSForum] Re: IceCap Manager Web Console

2003-03-28 Thread Andrew Plato
. Assuming you were using the default port, you would enter the following URL: HTTPS://icecap_server_IP:8089 Give it a try. ___ Andrew Plato, CISSP President / Principal Consultant Anitian Corporation Enterprise Security Infrastructure Solutions 503-644-5656 Office

RE: [ISSForum] Desktop Protector

2003-10-16 Thread Andrew Plato
. It gathers desktop events and sends them to an event collector. ___ Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise Security 503-644-5656 Office 503-644-8574 Fax 503-201-0821 Mobile www.anitian.com

RE: [ISSForum] Full Duplex Real Secure Network Sensor

2003-11-05 Thread Andrew Plato
I have run Guard and Senty successfully on other boxes than the Dell or Compaq. The key issue is the PCI bus speed. You need at least 2 64-bit PCI buses in the machine and the 3com 3C905C NICs. The new Dell 1750 has 2 64bit slots. ___ Andrew Plato, CISSP President

[ISSForum] Site Protector GUI Customizations

2003-11-07 Thread Andrew Plato
? ___ Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise Security 503-644-5656 Office 503-644-8574 Fax 503-201-0821 Mobile www.anitian.com ___ ___ ISSForum mailing list [EMAIL PROTECTED

RE: [ISSForum] Add Custom rulez to Auto-Block in Blackice Server

2003-11-12 Thread Andrew Plato
to propagate such customizations to each new version that comes down from ISS - which can be a pain. NOTE: None of this is supported by ISS. ___ Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise Security 503-644-5656 Office 503-644-8574 Fax 503-201-0821

RE: [ISSForum] Add Custom rulez to Auto-Block in Blackice Server

2003-11-12 Thread Andrew Plato
to write some Dummies Guide to BlackICE that explains how to do all this cool stuff with BlackICE. For example - did you know you can feed Snort signatures into BlackICE? You can. Its easy. ___ Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise

RE: [ISSForum] Re-installing the SiteProtector Server

2003-11-17 Thread Andrew Plato
. But you have to make sure the version you build on another machine has the same IP address and XPU levels. ___ Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise Security 503-644-5656 Office 503-644-8574 Fax 503-201-0821 Mobile www.anitian.com

[ISSForum] Java Security Problems

2003-11-21 Thread Andrew Plato
, no word from ISS on whether the console will be updated to support 1.4.2 (which repairs the security vulnerability.) ___ Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise Security 503-644-5656 Office 503-644-8574 Fax 503-201-0821 Mobile

[ISSForum] Site Protector Console Updates Not Taking Hold after SP3

2003-11-21 Thread Andrew Plato
? ___ Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise Security 503-644-5656 Office 503-644-8574 Fax 503-201-0821 Mobile www.anitian.com ___ ___ ISSForum mailing list [EMAIL

RE: [ISSForum] Problem in Remote Installation of Agent.

2003-12-04 Thread Andrew Plato
service under that account. Agents generally must be installed on systems with administrative-level rights. If you do not have admin rights a system, agent installations might fail. ___ Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise

RE: [ISSForum] Upgrade path for Real Secure Desktop Protector 3.6 - 7.0

2003-12-09 Thread Andrew Plato
is stripped off the machine. Then have them run a 7.0 agent build. ___ Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise Security 503-644-5656 Office 503-644-8574 Fax 503-201-0821 Mobile www.anitian.com

RE: [ISSForum] Desktop Protector and Application Protection

2003-12-09 Thread Andrew Plato
___ Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise Security 503-644-5656 Office 503-644-8574 Fax 503-201-0821 Mobile www.anitian.com ___ -Original Message- From: Cunningham, Chris, R. [mailto:[EMAIL PROTECTED

RE: [ISSForum] BlackICE on Windows, should only be Server Sensor

2003-12-11 Thread Andrew Plato
The BlackICE engine is used for the network IDS portion of RS Server Sensor and the firewall. -Original Message- From: Mohr James [mailto:[EMAIL PROTECTED] Sent: Wednesday, December 10, 2003 3:45 AM To: [EMAIL PROTECTED] Subject: [ISSForum] BlackICE on Windows, should only be Server

RE: [ISSForum] IceCap Manager SQL Database

2003-12-12 Thread Andrew Plato
, not ICEcap. ___ Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise Security 503-644-5656 Office 503-644-8574 Fax 503-201-0821 Mobile www.anitian.com ___ -Original Message- From: Roser, Ian (UK - Manchester

[ISSForum] Problems with adaptive profiles for RS Desktop

2004-02-02 Thread Andrew Plato
rules. Nothing, remains in default. What's weird, is that when we put the virtual range into corpnet - the agent switches into corpnet just fine. Has anybody seen this behavior. Do you have ANY suggestions? Thanks. ___ Andrew Plato, CISSP President/Principal

RE: [ISSForum] Problems with adaptive profiles for RS Desktop

2004-02-03 Thread Andrew Plato
None of these options work. The agent stays in the default setting. ___ Andrew Plato, CISSP President / Principal Consultant Anitian Enterprise Security 503-644-5656 Office 503-214-8069 Fax 503-201-0821 Mobile www.anitian.com

RE: [ISSForum] Problems with adaptive profiles for RS Desktop

2004-02-03 Thread Andrew Plato
Really? How come this isn't documented anywhere? ___ Andrew Plato, CISSP President / Principal Consultant Anitian Enterprise Security 503-644-5656 Office 503-214-8069 Fax 503-201-0821 Mobile www.anitian.com

RE: [ISSForum] Problems with adaptive profiles for RS Desktop

2004-02-07 Thread Andrew Plato
Title: [ISSForum] Problems with adaptive profiles for RS Desktop I thought I would post a follow up to the forum on this issue, in case anybody has a similar problem. I was able to resolve this issue with the help of ISS support. I want to thank Bill Sieczko for taking the time to

RE: [ISSForum] What ISS IDS product will run on Server 2003?

2004-03-09 Thread Andrew Plato
it happier. ___ Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise Security -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian Kirby Sent: March 05, 2004 12:39 PM To: [EMAIL PROTECTED] Subject: [ISSForum

RE: [ISSForum] SiteProtector Database on SQL Cluster

2004-03-15 Thread Andrew Plato
. ___ Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise Security -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe jett Sent: March 12, 2004 3:51 AM To: [EMAIL PROTECTED] Subject: [ISSForum] SiteProtector Database on SQL Cluster

RE: [ISSForum] Site Protector installing Desktop Controller

2004-03-23 Thread Andrew Plato
and it brings up that page. You could then link one of the build packages to a logon script. ___ Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise Security -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf

RE: [ISSForum] SiteProtector 2.0sp3 RSDP 7.0 - adaptive profile issue

2004-08-13 Thread Andrew Plato
back to default profile. One common trip up with this is NATing. If you have remote RSDP agents coming in over a VPN, if their orignal IP address gets NAT'ed, you have to make sure the NAT address is in the corpnet range. ___ Andrew Plato, CISSP President/Principal

RE: [ISSForum] Desktop Protector and Windows XP SP2

2004-09-08 Thread Andrew Plato
. ___ Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise Security -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Poppi, Sandro Sent: September 01, 2004 5:53 AM To: ISSforum (E-Mail) Subject: [ISSForum

RE: [ISSForum] Update Process STUCK :

2004-09-08 Thread Andrew Plato
was supposed to be bug fixes, but seems to be creating problems. 7.0 enq doesn't have any new signatures, so if you're running on 7.0eno, I'd recommend staying there for now. ___ Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise Security

RE: [ISSForum] Advanced firewall parameters of Desktop Protector viaSiteProtector console

2004-09-08 Thread Andrew Plato
). Once you get a feel for the parameters and files, is actually pretty easy to do. Oh, and remember to stop and restart your desktop controller after you have added your new custom version. ___ Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise

RE: [ISSForum] Realsecure Server Sensor - Network Filtering

2004-10-11 Thread Andrew Plato
use the advanced parameters for the sensor, enter a name of pam.trust.pair. Its a string value. And then the value is ipaddress,signature_id . This should work. Andrew Plato, CISSP President / Principal Consultant Anitian Enterprise Security www.anitian.com

RE: [ISSForum] Realsecure Server Sensor - Network Filtering

2004-10-11 Thread Andrew Plato
Try using the regular trust.pair Drop it into the blackice.ini. ___ Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise Security -Original Message- From: Michael Nurre [mailto:[EMAIL PROTECTED] Sent: October 08, 2004 12:33 PM

RE: [ISSForum] SSL (TLS) between Dektop controller and Agent

2004-10-06 Thread Andrew Plato
data and some config information. It wouldn't be terribly useful to a would be attacker. There is no way to use SSL between the RSDP and the desktop controller. Andrew Plato, CISSP President / Principal Consultant Anitian Enterprise Security www.anitian.com

[ISSForum] Problems with XPU updates after SP5 - SOLUTION

2005-01-31 Thread Andrew Plato
exclusively over port 443. Site Protector downloads information off the ISS site first using regular old HTTP. Then it switches over the HTTPS for the actual downloads. ___ Andrew Plato, CISSP President/Principal Consultant ANITIAN ENTERPRISE SECURITY 3800 SW

[ISSForum] Server Sensor Blue Screen of Death - Solution

2005-02-03 Thread Andrew Plato
. ___ Andrew Plato, CISSP President/Principal Consultant ANITIAN ENTERPRISE SECURITY 3800 SW Cedar Hills Blvd, Suite 298 Beaverton, OR 97005 503-644-5656 Office 503-214-8069 Fax 503-201-0821 Mobile www.anitian.com ___ GPG fingerprint: 16E6 C5B0 B6CB F287 776E

RE: [ISSForum] DB backups and offline access

2005-02-10 Thread Andrew Plato
have to know the in's and out's out SP to do it, but it can be done. Heck, maybe I should offer a special SiteProtector Disaster Recovery service. ;-) ___ Andrew Plato, CISSP President/Principal Consultant ANITIAN ENTERPRISE SECURITY 3800 SW Cedar Hills Blvd

Re: [ISSForum] Proventia G in Passive Mode

2005-08-19 Thread Andrew Plato
. I'd go talk to your ISS rep and see about trading in your 200 for a 604. You'll be a lot happier. _ Andrew Plato, CISSP President/Principal Consultant ANITIAN ENTERPRISE SECURITY 3800 SW Cedar Hills Blvd, Suite 280 Beaverton, OR 97005 503-644-5656 Office 503-214

Re: [ISSForum] Proventia G in Passive Mode

2005-08-22 Thread Andrew Plato
just buying an A604 than trying to put weird interface cards into a G200. _ Andrew Plato, CISSP President/Principal Consultant ANITIAN ENTERPRISE SECURITY 3800 SW Cedar Hills Blvd, Suite 280 Beaverton, OR 97005 503-644-5656 Office 503-214-8069 Fax 503-201-0821

Re: [ISSForum] Black Ice client install

2005-08-26 Thread Andrew Plato
the existing one. ___ Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise Security -Original Message- From: Nicholas Claus [mailto:[EMAIL PROTECTED] Sent: Thursday, August 25, 2005 4:47 AM To: issforum@iss.net Subject: Re: [ISSForum] Black Ice

Re: [ISSForum] Server Sensors that just die

2005-10-07 Thread Andrew Plato
. --- Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise Security --- -Original Message- From: Cunningham, Chris, R. [mailto:[EMAIL PROTECTED] Sent: Friday, October 07, 2005 6:57 AM To: Andrew Plato Subject: RE: [ISSForum

Re: [ISSForum] Network taps for monitoring full-duplex network withProventia G2000

2005-12-19 Thread Andrew Plato
Why not just deploy in-line, but configure for passive monitoring. In this arrangement, the unit can't block anything and will give you the functionality you want. --- Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise Security

Re: [ISSForum] G1200 firmware 1.2 upgrade

2006-01-03 Thread Andrew Plato
it. --- Andrew Plato, CISSP President/Principal Consultant Anitian Enterprise Security --- -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Gregory Jansen Sent