Posts

Lake Francis Nature Preserve & The Tampa and Gulf Coast Railroad

Image
Hey everyone. Today I’m taking a trip to the Lake Francis Nature Preserve in the Keystone area of Northwest Hillsborough County for a trail run. It’s 63 degrees and very foggy on this January morning. Lake Francis nature preserve is located off of Tarpon Springs Road. Together with the adjacent Lake Dan Nature preserve, this area is over 2,800 acres of preserve land. Hillsborough County acquired these parcels through the ELAPP program and operates them as a nature preserve. Before we continue down the rest of the driveway I want to give you some background on what we’ll be exploring today.   I’ve been to this preserve and Lake Dan Nature preserve several times but it wasn’t until I watching one of Danny Harman’s videos on his EXCELLENT Distant Signal YouTube channel that I learned of the existence of the Tampa Northern Railroad and the Tampa and Gulf Coast railroad. I’ve put links to his YouTube channel and all of the reference material for this video in the description. In 1910, ...

Cisco ISE Guest Portals with Ruckus SmartZone

Image
Ruckus SmartZone 7.1 (both APs and controller must be running 7.1) and later support a new RADIUS VSA (Vendor Specific Attribute) for dynamic URL redirection. This means that Cisco ISE can integrate with SmartZone Controllers just like Cisco WLCs and Meraki APs.  The ISE built-in RuckusWireless NAD profile must be duplicated and modified to use Ruckus-External-Url VSA for the $URL variable. ISE will dynamically insert the PSN FQDN and portal port number during authorization. Ruckus also supports pushing an ACL name via RADIUS from the standard RADIUS Filter-ID attribute. SmartZone also now supports CoA for URL redirection once the client successfully logs into the ISE portal. Ruckus-EXTERNAL-URL VSA Filter-ID ACL Once the NAD profile is modified and applied to the NAD definition for a Ruckus Controller, the ISE guest rules can be built out just like you normally would for any Cisco NAD.  On the Ruckus SZ side, the ACL must be configured to allow DHCP, DNS, and access to the I...

Mountain Biking Flatwoods Wilderness Park

Image
My wife and I completed a 6.5 mile ride at Flatwoods Wilderness Park, located in Northeastern Hillsborough County. I've biked this park since middle school, but it's been many years since I was last here. The park has over 30 miles of off-road bicycle single track. The land is owned by the Southwest Florida Water Management District (SWFWMD) and operated as a Conservation Park by Hillsborough County . The bike trails are maintained by the SWAMP Mountain Bike club , which operates and manages several off-road mountain bike trails throughout the Tampa Bay Area.  The Flatwoods area is a massive flood plain and headwaters of the Hillsborough River. Formally known as the Hillsborough Flood Detention Area (HFDA) In the rainy season, or during hurricanes, SWFWMD controls flow into the Hillsborough River using a flood control structure originally built in the 1960s to protect the cities of Tampa and Temple Terrace from floodwaters. An alternative water flow path, the Tampa Bypass Cana...

Brooker Creek Headwaters Nature Preserve

Image
Brooker Creek is a small waterway in Northwest Hillsborough and Pinellas Counties. Brooker Creek flows through two nature preserves, agricultural, and residential areas before eventually emptying into Lake Tarpon. Lake Tarpon then flows into Tampa Bay. Brooker Creek Headwaters Nature Preserve is a 1121 acre preserve located in the Keystone area of Hillsborough County. It is owned by the Southwest Florida Water Management District and operated by Hillsborough County Conservation and Environmental Lands Management Department . This preserve exists to protect the health of the headwaters of Brooker Creek and its contribution to Lake Tarpon and Lake Keystone. The preserve includes several miles on unpaved hiking paths and also contains portions of the paved Upper Tampa Bay Trail from Van Dyke Road to the Suncoast Parkway on Lutz Lake Fern Road. The headwaters consist of a chain of wetlands on the north side of Lutz Lake Fern Road (outside of the preserve boundary) and flow southwest until...

Aruba AOS-CX Switch 802.1X/MAB Template for ClearPass, ISE, FortiAuthenticator, etc

Below is a template for Aruba AOS-CX Switches for 802.1X and MAB. This template can be used with any standards-based RADIUS server such as Aruba ClearPass, Cisco Identity Services Engine, Fortinet FortiAuthenticator, FortiNAC, FreeRADIUS, etc. This configuration is just basic 802.1X and MAC Address Bypass, it does not cover Downloadable User Roles (DUR) or other advanced Aruba segmentation features.  The various sections of the configuration are explained prior to each as a comment denoted by !. This configuration should be valid for any version of AOS-CX and has practically been tested with both Cisco ISE and Aruba ClearPass. !Define the RADIUS servers. This can be a ClearPass VIP, a load-balancer, or the actual RADIUS servers. Replace the x.x.x.x with your RADIUS server IPs. radius-server host x.x.x.x key plain-text SuperSecureKey! radius-server host x.x.x.x key plain-text SuperSecureKey! !Place the RADIUS servers inside a AAA group. Replace [name] with the whatever name you...

Stop Using PEAP/MS-CHAPv2

I see a lot of customers continue to use PEAP/MS-CHAPv2 for 802.1X network authentication to Cisco ISE and other network access control platforms and RADIUS servers.  STOP!   MS-CHAPv2 uses broken MD4 encryption and should no longer be used to pass sensitive credentials over any network.  Microsoft has taken steps to disable PEAP/MS-CHAPv2 for Active Directory credentials in updated versions of Windows 10 and Windows 11.  You can get around this with a registry hack but it's still a BAD idea.  If you are still using MS-CHAPv2 for 802.1X authentication, it's time to migrate to certificate based authentication methods instead such as EAP-TLS.  Even better, use TEAP with user and machine authentication using certificates.   Some use-cases (like BYOD or guest access) could also transition to SAML-based authentication to your IDP of choice.  SAML Assertion sometimes can remove the need for a RADIUS server all together.  Having a secure, robus...

Aruba Networks Airheads MVP Expert 2024

I'm happy to announce that I have received the Aruba Network Airheads MVP Expert designation for 2024 for my assistance in the Airheads forum around ClearPass design, implementation, and troubleshooting.  Be sure to check out all of the 2024  MVPs .

Cisco Designated VIP 2024

I'm pleased  to announce that I have been recognized as a Cisco Community Designated VIP for 2024 for my assistance in the Cisco Secure Network Access Control community focusing on Identity Services Engine.  Be sure to check out all of the   Cisco Community Designated VIPs .

Cisco Meraki MS130R Ruggedized Switch

Today Cisco Meraki announced the MS130R rugged switch .  This is the first rugged Meraki switch; it's IP30 certified with an operating temperature of -40 to 70 degrees Celsius.  This enables the cloud first Meraki configuration and support model in harsh/challenging environments.  The switch includes eight 30W POE+ capable 1GbE RJ45 ports and two 1GbE SFP ports.  As with any industrial/rugged switch it can be powered by DIN rail DC power or an external AC power supply.  The two SFP ports support a variety of Cisco ruggedized SFPs: GLC-SX-MM-RGD, GLC-LX-SM-RGD, GLC-ZX-SM-RGD, and GLC-T-RGD. One of the most exciting things to me is that the MS130-X (also announced today) and MS130R will  support Adaptative Policy in a future MS firmware update.  This will extend the Adaptive Policy boundary to harsh environments to enable micro-segmentation in even more locations.  Meraki Adaptive Policy also seamlessly integrates with Cisco Identity Services Engi...

How to Upgrade Juniper EX JunOS using the Mist Dashboard

Image
In this article I'm going to go through updating Junos OS on an EX2300-C switch using the Mist Dashboard.  This functionality is included in the Wired Assurance Subscription.  Once the switch is claimed in your Mist organization (maybe a topic for another post?) the switch will be added to the Switches view and various statistics will be displayed. Next, check the selection box for the switch(es) to upgrade and click the Upgrade Switches button in the top right.  A new window will appear with a selection of the version of Junos to upgrade to. This pane also includes checkboxes to force a switch reboot once the image is copied.  A reboot can also be performed at later time (for example during a maintenance window) instead of automatically at the end of the Junos image download.  A recovery snapshot can also be created for easy rollback to the currently running version of Junos in case of a code related issue.  Finally, the End User License Agreement must be ...

So I tried Google Bard…

This article was written by Google Bard with the prompt “write a blog post on the importance of zero trust”.  Pretty neat but I really do question the ethics around using AI for media/publication generation.  Anyways here is what Bard gave me: Zero trust is a security model that assumes that no device, user, or service should be trusted by default. Instead, every request for access to a system or data should be verified and authenticated. Zero trust is based on the principle of "never trust, always verify." This means that organizations should never assume that any user or device is safe, even if they are inside the network perimeter. Instead, they should always verify the identity of each user and device before granting access to any resources. Zero trust is a critical security model for organizations that operate in today's digital world. The traditional security model of "trust but verify" is no longer effective in the face of modern threats. Zero trust helps...

How To: Cisco ISE Captive Portals with Aruba Wireless

See myself and Brad Johnson's   Cisco Community post .

Cisco Designated VIP 2023

I'm happy to announce that I have been recognized as a Cisco Community Designated VIP for 2023 for my assistance in the Cisco Secure Network Access Control community focusing on Identity Services Engine.  Be sure to check out all of the Cisco Community Designated VIPs .

Aruba Networks Airheads MVP Guru 2023

I'm happy to announce that I have received the Aruba Network Airheads MVP Guru designation for 2023 for my assistance in the Airheads forum around ClearPass design, implementation, and troubleshooting.  Be sure to check out all of the MVPs . -A

Cisco Cloud-scale Switching Innovations

Image
Cisco recently announced 800G capable switches focused on hyperscalers, financials, service providers, and other large organizations requiring high speeds and low latency. The 800G capable switches currently come in two flavors: the Nexus 9232E and the Cisco 8111.  Both are 1RU and powered by Cisco's Silicone One G100 ASIC (more on that below).  They support 32 QSFP-DD800 800G ports with the ability to break out to 2x400G or 8x100G offering even more port density from a compact 1RU platform.   What I think is really special about this launch surrounds the Cisco 8111.  While the Nexus 9232E supports running NX-OS; the Cisco 8111 supports third-party operating systems such as SONiC as well as IOS-XR.  This is a huge advantage for organizations who currently run white box switching solutions.  White box switches traditionally have high failure rates and suffer from poor technical support.  The Cisco 8100 series offers the world-class Cisco hardware q...

ClearPass MPSK per Device Type with Profiling

Image
Multiple Pre-Shared Key or MPSK helps solve for IOT or other endpoint device types that are not 802.1X capable.  The Aruba ClearPass default implementation of MPSK (the configuration created by the wizard) requires manually registering, enrolling, and managing individual PSK keys per endpoint using the ClearPass Guest dashboard.  While the most secure approach, excluding any sort of API based automation, this can obviously be a nightmare to manage and support due to the sheer number of PSKs.  This approach instead delivers a unique PSK per device type (printer, thermostat, etc.) so that each flavor of endpoint would have its own PSK.  If one PSK was compromised, then only those endpoints would need to be manually re-configured.  PSK rotation would also be limited to only those specific device types allowing rotation to take place slowly over several weeks rather than all devices at the same time on the SSID with a traditional single PSK; lessoning the burde...

Popular posts from this blog

Fix Cisco ISE Messaging Service

ClearPass MPSK per Device Type with Profiling

Aruba AOS-CX Switch 802.1X/MAB Template for ClearPass, ISE, FortiAuthenticator, etc