Archive for the ‘Cisco Consultancy’ Category

PCI Compliance & the Cisco Security Network

Wednesday, September 30th, 2009

I am sure you heard the term PCI compliance before. Also surely you will know that Security is quite hard to sell in Europe as it is not being seen as a business enablement tool. It is rather seen as a necessity or a “I must be compliant”. I understand that it is slightly different in the US.

However here in the UK we are seeing a lot of interest in PCI compliance. Not because the customers have additional funds to spare but because banks and other credit card processing organizations are increasing pressure to become compliant by the end of 2010.

Currently we are working with one of our Partners on 2 large retail accounts to become PCI compliant. We are tailoring an all inclusive package to meet the deadline. Hardware, Design, Consultancy & of course tailored high end Cisco Training.  It involves AAA (Cisco ACS), SSH on all boxes, IPS/IDS, NAC, Router & Switch Security as well as Cisco Security Manager and CS MARS.

Apparently the processing bank (a leading UK financial) organization has told the customer that if PCI compliance isn’t met by the end of 2010 there will be a fine of up to £50k per month for every non-compliant month. Ouch!

So it is better worth checking with the financial institutions now before it’s getting to close to the deadline. The beauty for me as the CTO and for our technical Cisco Consultants and Cisco Trainers is the fact that we get to spec, design, implement all the latest and greatest Cisco Security technologies and deliver Training on it.

The timelines are tight, but we have a great team and look forward to those 2 large projects.

Martin Voelk
CTO
ProNetExpert
http://www.pronetexpert.com/cisco-ccie-consulting-consultancy-support-services-security-ironport.html

IT Network Security Consulting Services & Cisco CCSP Training Courses

Wednesday, August 26th, 2009

We often get asked, what Security Services are essential in today’s Cyberspace. We have created a list of the most important Services we offer. We kept it not too technical.

 

Penetration Tests & IT Network Security Audits

Threat: Hackers attack both private and corporate systems on a daily basis. The attacker can be stationed anywhere in the world and needs just internet access and the appropriate tools. The threat is real and it happens thousands of times a day. Many attacks take place undetected and result in the theft and destruction of valuable data.

Solution: Penetration Tests and Network Security Audits. ProNetExpert will, with the legal permission of the network owner, attack customer systems in the same way as a Hacker. In doing so, ProNetExpert is able to expose security holes in the system.

Benefit: The customer is made aware of the Security holes that exist and could be exploited by a hacker with malicious intent to gain unauthorized access to the customer network. In addition, ProNetExpert will prepare a plan of action and, if the customer wishes, implement the closure of these holes.

 

Compliance & Government Best Practices

More and more governments define rules and frameworks around IT Network and Host Security. Customers dealing with sensitive data, such as government information, financial information (i.e. credit cards) and medical health records, must ensure their network and systems are compliant with government standards.

Solution: ProNetExpert will analyse the customer network and host systems, and formulate an action plan and Security Policy to assist the customer in becoming compliant with the rules and regulations of the country in question. ProNetExpert can then help the customer in implementing the necessary security appliances and protocols to ensure all compliance requirements are satisfied.

Benefit: Companies will meet government and/or financial security compliance standards, are protected from threats and, in the unlikely event of a security breach, the customer is protected from legal consequences as the compliance framework and Security Policies are in place.

 

 

IT & Network Security Training Courses & Workshops

Necessity: Security awareness amongst personnel operating and maintaining security equipment is a hugely important factor. Ongoing Security Training has become of increased concern to customers as they battle to defend themselves against digital threats.

Solution: ProNetExpert offers a variety of IT and Network Security Training Courses. Those courses include general IT Security training courses such as the Certified Ethical Hacker class, Penetration Testing class and IT Security awareness class. Additionally, ProNetExpert Offers Cisco authorized Security Classes on products such as Firewalls, Intrusion Prevention Systems, VPNs, Router & Switch Security, Host Intrusion Prevention Systems, Identity Management, Security Management and Wireless Security. All Cisco CCSP courses delivered by ProNetExpert are fully compliant to the US NSA Security standards 4011 and 4013, as well as to the US Committee on National Security Systems (CNSS).

Benefit: Both end users and engineers are trained on the latest security standards and best practices to be able to operate and maintain secure IT Network Infrastructures.

 

Cyber Attacks and Cyber Warfare

Threat: Individuals, corporate companies and governments become are now a constant target of Distributed Denial of Service (DDoS) attacks, whereby a victim network or system is flooded with vast amounts of traffic in an attempt to bring it to a standstill and discontinue its legitimate use. Blackmailing is also a common practice - if funds are not paid to the criminal organizations in question, the services of the victim are taken offline. Likewise, unfriendly governments may launch Cyber attacks as described above, as a form of electronic Warfare. 

 Solution: ProNetExpert can work with customers and governments to design and implement appropriate systems that are capable of dealing with such attacks without compromising the services available. Furthermore, comprehensive Training can be provided to ensure users of these systems can harness their full defensive potential.

Benefit: Customers and governments are protected from DDoS attacks by having the appropriate defence systems in place.


Millions of users are targeted by fraudulent emails and websites daily. Criminals attempt to deceive users into disclosing personal and financial information.

 

 

Email & Website Content

Solution: ProNetExpert can provide expert consultancy on the latest Email and Web Filtering solutions in order to render malicious sites inaccessible for unsuspecting end-users, and to scan and delete Emails with malicious intent (Spam, Phishing, Virus Attachments etc.) Once again, Training can be provided by highly skilled instructors with extensive experience in these areas.

Benefit: Customers are protected from the danger presented by fraudulent Emails and websites.

 

 

Wireless & Voice over IP

Necessity: Voice over IP Communications and Wireless / Mobile Technologies are gaining more and more popularity. However, they also bring inherent Security risks if not secured appropriately. Standard Wireless and Voice over IP communications can easily be intercepted by malicious hackers, leading to the theft of highly sensitive and valuable information.

Solution: ProNetExpert can work with customers in securing both Voice over IP Networks and Wireless Infrastructures to meet the latest Security standards. Strong Virtual Private Networks (VPNs), encryption and authentication schemes can be implemented to guarantee Integrity, Confidentiality and Availability. Training Courses can also be provided.

Benefit: Customers can enjoy new technologies and use them to their fullest potential whilst guaranteeing the very highest levels of security.

 

IT Network Security Consulting

Many companies have security systems in place. However, often they are not configured to the latest Security best practices, nor used to their fullest extent.

Solution: ProNetExpert offers Security Consulting on all IT Network Security systems and solutions, such as: Firewalls, Intrusion Prevention Systems, Host Intrusion Prevention Systems, Access Control, Virtual Private Networks, Identity Management, and Security Management. Additionally, ProNetExpert delivers complete training on all technologies and systems.

Benefit: Customer Security equipment is designed, configured and maintained to the latest Security best practices, thus ensuring a secure and reliable infrastructures.

Cisco Support & Cisco Consulting Wireless Reference Project

Friday, July 10th, 2009

ProNetExpert were engaged by a UK government client to set up a 1 week temporary wireless infrastructure. The objective was to enable wireless access for high government officials in order to connect to the Internet and corporate resources from their laptops and other mobile devices.

ProNetExpert’s Cisco Consultants designed a complete solution (Design, Staging, Implementation and Monitoring). The ProNetExpert Cisco Support Team arranged two 34 MB E3 upstreams from a local Service Provider, which ran multihomed BGP and served as the upstream. The Cisco 3800 upstream routers were firewalled off by ASA 5540s. Around 40 Cisco Access Points were deployed (incl. site surveys). The setup also contained various outdoor wireless MESH bridging setups. Users were able to seamlessly roam on Layer 2 and Layer 3 basis and form direct VPN connections into corporate networks from the end devices.

Additionally around 200 VoIP handsets were supplied to enable Voice over WLAN telephony for the attendees. The PBX solution was supplied by a Service Provider and configured and monitored by our Cisco Consultants. The ProNetExpert Cisco Support Team configured comprehensive Quality of Service to provide optimal performance for both Voice and Data Traffic.

Martin Voelk
CCIE # 13708
CTO @ ProNetExpert

Wireless Consulting Project delivered by ProNetExpert’s Cisco Wireless Consultants

Thursday, July 9th, 2009

This is a massive boost to all of us. Today our Managing Director received the P/O for a 6 month Cisco Wireless rollout project in the United States. As often in those economic times, the bigger projects come from the government and as in our case from the US military. In a nutshell, we will supply the Cisco Wireless Consultants to build a large campus wide Cisco MESH network. 1500 series Access Points, Cisco 4400 Controllers, all sorts of Yagi and parabolic dish antennas and Cisco WCS to manage everything from a central point. An exciting project where I would be keen to get involved myself again, but I am fairly busy with the Argentinian government WAN Optimization project design.

Martin Voelk
CTO
ProNetExpert

ProNetExpert Successfully deliver Redundant Cisco Content Switch Installation

Wednesday, June 10th, 2009

Today ProNetExpert successfully completed the installation of a pair Cisco Content Service Switches (CSS 11501) for a London based customer. The Content Services Switches provide the client with Layer 4 to Layer 7 traffic management allowing them to load-balance HTTP and HTTPS access on to their websites. This was the final phase of a project that provided the client with a fully redundant network utilizing dual Internet uplinks routing using BGP for failover terminated on a HSRP pair of Cisco 2800 routers, a redundant pair of Cisco ASA 5510 firewalls for security and VPN access for management of the data centre hosted equipment.

Maria Boyle

CCIE #19890

Senior Network Consultant

 

 

 

Cisco MARS project for UK government client

Thursday, June 4th, 2009

ProNetExpert’s Cisco MARS Consultants will deploy, install and configure Cisco MARS appliances to monitor a large UK government core network consisting of multi-vendor Router, Switch and Firewall products. In addition Cisco IPS 4240 Intrusion Prevention System appliances will be deployed in order to tighten up network security and to report to the Cisco Security Monitoring, Analysis and Response System (CS-MARS). ProNetExpert was awarded with the contract and is very excited in delivering this project over the weeks to come. It’s the third Cisco MARS Consultancy project ProNetExpert rolls out in the UK in 2009.
Best regards,
Martin Voelk
CCIE # 13708
CTO, ProNetExpert

ASA SSL VPN configuration successful

Wednesday, June 3rd, 2009

Today ProNetExpert successfully configured a Cisco ASA 5510 for SSL VPN in Australia. The configuration was done remotely and all tests were conclusive. (including authentication against a Microsoft IAS for AAA Authentication). The Cisco Anyconnect client (SVC) was used to have full network access (Layer3 access to the network - compared to clientless SSL VPN access via a portal). WebVPN features (clientless VPN) will be configured at a later stage. The remote access solution based on SSL VPN was preferred over an IPSec solution for simplicity.

Based on this proof of concept configuration other locations in UK and mainland Europe will be configured the same way.

CCIE Hotline’s 125th customer

Tuesday, June 2nd, 2009

Today we had our 125th. new customer at the CCIE Hotline and that’s worth celebrating. When I first started that website back in summer 2008 it was just an idea. Both myself and the team at ProNet Expert are positively surprised about how well CCIE Hotline is doing. A big Thank You to our customers and to our CCIE Consultants in all tracks for making this such a great success.
In case you haven’t seen the CCIE Hotline yet: http://www.cciehotline.com

Regards
Martin Voelk