Ni cite wa mau tgk.........
Release Date: 27 January 2011
Language: Cantonese
Subtitle: English / Chinese
Genre: Action
Running Time: 2 Hours 11 Minutes
Director: Benny Chan
Cast: Andy Lau, Nicholas Tse, Jackie Chan, Fan Bing Bing, Wu Jing
Synopsis: As a covert officer in the CIA's Counter-Proliferation Division, Valerie Plame (Naomi Watts) leads an investigation into the existence of weapons of mass destruction in Iraq. Valerie's husband, diplomat Joseph Wilson (Sean Penn), is drawn into the investigation to substantiate an alleged sale of enriched uranium from Niger. But when the administration ignores his findings and uses the issue to support the call to war, Joseph writes a New York Times editorial outlining his conclusions and ignites a firestorm of controversy.
(Source: Cinema Online)
High-Performance Gigabit Ethernet Access
- Non-Blocking 48 1000 Mbps (RJ-45) & four 1/10GbE uplinks (SFP+)
- Layer 2/3 switching up to 176 Gbps and 120 Mpps
- 40 gigabits of interconnect capacity from leaf to the spine
Deep Buffer Architecture
- 768 MB of packet memory
- All ports can simultaneously buffer up to 50ms of traffic
- Fair allocation of bandwidth with 8 virtual output queues per port for congestion mgmt
Arista EOS™
- Extensible operating system customizable to customer needs
- Fine-grain modular protected memory architecture
- Access to Linux tools
High Availability
- In-service-software-upgrades (ISSU)
- Self-healing stateful fault repair (SFR)
- Hot swappable, redundant power supplies and fans
Layer 4-7 Integration
- Citrix Systems NetScaler VPX Integration
- Layer 4-7 Load Balancing and Application Security
Datacenter Optimized
- 1 rack unit (RU)
- Front-to-rear and reversible airflow options for flexible mounting
- Power efficient
Details Here : Arista
" Gourlay will be responsible for product and solutions marketing, communications, and the strategic alliances of Arista Networks (which is a vendor that builds networking platforms enabling customers to build network systems optimized for high-performance computing, virtualization and cloud deployments). "
Details Click Here : Networkworld
Kejayaan anak buah " Raja " memenangi Piala AFF 2010 membawa sinar baru dalam mutu bola sepak negara.Terutamanya penyerang sensasi negara " kasut emas Asia Tenggara " memberi ruang dan peluang pada dirinya untuk mencuba nasib di ISL ( Liga Super Indonesia ) . Ini membuktikan anak tempatan mampu untuk mendapat tempat di luar negara. Biarpun hanya di Indonesia, ini satu permulaan yang baik untuk kemajuan bola sepak negara. Persib Bandung , Persib Balik Papan, Pelita Jaya adalah antara kelab indonesia yangberminat untuk mendapatkan khidmat beliau(Safee Sali).
Persib Bandung menjadi pilihan Safee Sali sekiranya semua berjalan lanjar. Menurut sumber, 70% urusan telah disempunakan. Sekiranya tiada apa-apa halangan, kita mungkin akan melihat anak tempatan menggegar ISL untuk musim baru nanti. ISL yang dijadualkan bermula MEI ini memberi ruang untuk Safee Sali mempersiapkan diri sebelum menjejakkan kaki di bumi seberang.
Mengikut pengamatan saya, liga ISL lebih mencabar dan menarik. Banyak yang boleh dipelajari oleh Safee Sali. Mungkin disana, Safee Sali tidak akan keletihan mencari bola untuk menjaringkan gol sepertimana di sini. Tetapi mungkin Safee Sali akan keletihan kerana terlalu banyak bola dihantar kepadanya untuk dijaringkan.
Sumber : Dijedok dari : Klik Sini
FACEBOOK WILL END ON MARCH 15th!
“After March 15th the whole website shuts down,” said Avrat Humarthi, Vice President of Technical Affairs at Facebook. “So if you ever want to see your pictures again, I recommend you take them off the internet. You won’t be able to get them back once Facebook goes out of business.”
Source :Click This
What Are Firewalls
Firewalls are an integral part of any secure network. As we continue the discussion of the various security features and designs, it is important to take an in-depth look at how firewalls protect a network.
3 Part : 1 - Firewalls
2 - Types of Firewalls
3 - Positioning of Firewalls
Firewalls
- Logging and notification ability
- High-volume packet inspection
- Ease of configuration
- Device security and redundancy
Logging and Notification Ability
A firewall is not much good unless it has a good logging facility. Good logging not only allows network administrators to detect if attacks are being orchestrated against their networks, but it also lets them detect if what is considered normal traffic originating from trusted users is being used for ungainly purposes. Good logging allows network administrators to filter much information based on traffic tagging and get to the stuff that really matters very quickly. Obviously, good logging is different from logging everything that happens."Good logging" also refers to notification ability. Not only do you want the firewall to log the message, but you also want it to notify the administrator when alarm conditions are detected. Notification is often done by software that sorts through the log messages generated by the firewall device. Based on the criticality of the messages, the software generates notifications in the form of pages, e-mails, or other such means to notify a network administrator. The purpose of the notification is to let the administrator make a timely modification to either the configuration or the software image of the firewall itself to decrease the threat and impact of an attack or potential attack.
High-Volume Packet Inspection
One test of a firewall is its ability to inspect a large amount of network traffic against a configured set of rules without significantly degrading network performance. How much a firewall should be able to handle varies from network to network, but with today's demanding networks, a firewall should not become a bottleneck for the network it is sitting on. It is important to keep a firewall from becoming a bottleneck in a network because of its placement in the network. Firewalls are generally placed at the periphery of a network and are the only entry point into the network. Consequently, a slowdown at this critical place in the network can slow down the entire network.Various factors can affect the speed at which a firewall processes the data passing through it. Most of the limitations are in hardware processor speed and in the optimization of software code that keeps track of the connections being established through the firewall. Another limiting factor is the availability of the various types of interface cards on the firewall. A firewall that can support Gigabit Ethernet in a Gigabit Ethernet environment is obviously more useful than one that can only do Fast Ethernet in a faster network such as Gigabit Ethernet.One thing that often helps a firewall process traffic quickly is to offload some of the work to other software. This work includes notifications, URL filter-based access control, processing of firewall logs for filtering important information, and other such functions. These often-resource-intensive functions can take up a lot of the firewall's capacity and can slow it down.Ease of Configuration
Ease of configuration includes the ability to set up the firewall quickly and to easily see configuration errors. Ease of configuration is very important in a firewall. The reason is that many network breaches that occur in spite of a firewall's being in place are not due to a bug in the firewall software or the underlying OS on which the firewall sits. They are due to an error in the firewall's configuration! Some of the "credit" for this goes to the person who configures the firewall. However, an easy-to-configure firewall mitigates many errors that might be produced in setting it up.It is important for a firewall to have a configuration utility that allows easy translation of the site security policy into the configuration. It is very useful to have a graphical representation of the network architecture as part of the configuration utility to avoid common configuration errors. Similarly, the terminology used in the configuration utility needs to be in synch with normally accepted security site topological nomenclature, such as DMZ zones, high-security zones, and low-security zones. Use of ambiguous terminology in the configuration utility can cause human error to creep in.Centralized administrative tools that allow for the simultaneous management of multiple security devices, including firewalls, are very useful for maintaining uniformly error-free configurations.Device Security and Redundancy
The security of the firewall device itself is a critical component of the overall security that a firewall can provide to a network. A firewall that is insecure itself can easily allow intruders to break in and modify the configuration to allow further access into the network. There are two main areas where a firewall needs to have strength in order to avoid issues surrounding its own security: - The security of the underlying operating system- If the firewall software runs on a separate operating system, the vulnerabilities of that operating system have the potential to become the vulnerabilities of the firewall itself. It is important to install the firewall software on an operating system known to be robust against network security threats and to keep patching the system regularly to fill any gaps that become known.
- Secure access to the firewall for administrative purposes- It is important for a firewall to have secure mechanisms available for allowing administrative access to it. Such methods can include encryption coupled with proper authentication mechanisms. Weakness in the implementation of such access mechanisms can allow the firewall to become an easy target for intrusions of various kinds.
An issue related to device security is the firewall's ability to have a redundant presence with another firewall in the network. Such redundancy allows the backup device to take up the operations of a faulty primary device. In the case of an attack on the primary device that leaves it nonoperational, redundancy also allows for continued operation of the network.Types of Firewalls
In order to gain a thorough understanding of firewall technology, it is important to understand the various types of firewalls. These various types of firewalls provide more or less the same functions that were outlined earlier. However, their methods of doing so provide differentiation in terms of performance and level of security offered.The firewalls discussed in this section are divided into five categories based on the mechanism that each uses to provide firewall functionality: - Circuit-level firewalls
- Proxy server firewalls
- Nonstateful packet filters
- Stateful packet filters
- Personal firewalls
Circuit-Level Firewalls
Proxy Server Firewalls
Nonstateful Packet Filters
Stateful Packet Filters
- Source and destination TCP and UDP port numbers
- TCP sequence numbering
- TCP flags
- TCP session state based on the RFCed TCP state machine
- UDP traffic tracking based on timers
Personal Firewalls
Positioning of Firewalls
- Topological location of the firewall- It is often a good idea to place a firewall on the periphery of a private network, as close to the final exit and initial entry point into the network as possible. The network includes any remote-access devices and VPN concentrators sitting on the its periphery. This allows the greatest number of devices on the private network to be protected by the firewall and also helps keep the boundary of the private and public network very clear. A network in which there is ambiguity as to what is public and what is private is a network waiting to be attacked.Certain situations might also warrant placing a firewall within a private network in addition to placing a firewall at the entry point. An example of such a situation is when a critical segment of the network, such as the segment housing the financial or HR servers, needs to be protected from the rest of the users on the private network.Also, in most cases firewalls should not be placed in parallel to other network devices such as routers. This can cause the firewall to be bypassed. You should also avoid any other additions to the network topology that can result in the firewall's getting bypassed.
- Accessibility and security zones- If there are servers that need to be accessed from the public network, such as Web servers, it is often a good idea to put them in a demilitarized zone (DMZ) built on the firewall rather than keep them inside the private network. The reason for this is that if these servers are on the internal network and the firewall has been asked to allow some level of access to these servers from the public network, this access opens a door for attackers. They can use this access to gain control of the servers or to stage attacks on the private network using the access holes created in the firewall. A DMZ allows publicly accessible servers to be placed in an area that is physically separate from the private network, forcing the attackers who have somehow gained control over these servers to go through the firewall again to gain access to the private network.
- Asymmetric routing- Most modern firewalls work on the concept of keeping state information for the connections made through them from the private network to the public network. This information is used to allow only the packets belonging to the legitimate connections back into the private network. Consequently, it is important that the exit and entry points of all traffic to and from the private network be through the same firewall. If this is not the case, a firewall may drop packets belonging to legitimate connections started from the internal network for which it has no state information. This scenario is known as asymmetric routing.
- Layering firewalls- In networks where a high degree of security is desired, often two or more firewalls can be deployed in series. If the first firewall fails, the second one can continue to function. This technique is often used as a safeguard against network attacks that exploit bugs in a firewall's software. If one firewall's software is vulnerable to an attack, hopefully the software of the second firewall sitting behind it will not be. Firewalls from different vendors are often used in these setups to ensure that one incorrect or compromised implementation can be backed up by the other vendor's implementation.


