Friday, March 14, 2014

Cisco ASA – Permitting traffic between two interfaces with the same security level

Cisco ASA – Permitting traffic between two interfaces with the same security level

I had to make some network modifications to an ASA to activate another interface to accommodate some storage devices on a separate subnet for management purposes.  The below diagram shows the subnet’s in question.  I needed to configure the two interfaces to allow all interesting traffic to pass bi-directionally between each other.  Here are the commands I used to this rolling.
image
Even though the SERVER and STORAGE interfaces are configured with the same security level of 100 the default behavior of an ASA is to block communication between them.  We can enable communication between these two interfaces with the same security level with the following command:
ASA-CLI (config) # same –security-traffic permit inter-interface
Here is where many people get stuck.  After this command is added many people become baffled that they still cannot ping and pass traffic through.  This is because a “static or dynamic” translation rule is still required.  I added the following two commands to allow all IP traffic to pass bi-directionally.
ASA-CLI (config) # static (server,storage) 192.168.0.0 192.168.0.0 netmask 255.255.255.0
ASA-CLI (config) # static (storage,server) 192.168.2.0 192.168.2.0 netmask 255.255.255.0
At this point you should be good to go.
-Justin Vashisht (3cVguy)

Thursday, March 13, 2014

Outlook 2007: Remove or Disable RSS Feed Support

The integration between Outlook 2007 and Internet Explorer’s RSS system will slow down Outlook 2007. If you do not want to use Outlook 2007 for your feed reader or aggregator, here is how to remove this feature from Outlook.

Sadly, there is no command, option, or registry hack to hide the RSS icon or section in Outlook. We can, however, pretty much disable it.
If you do not want to use Outlook 2007′s RSS Feed Reader feature, you should remove it. It slows down Outlook. This also shows you how to remove the RSS feeds from the Outlook sidebar.
The main reason Outlook is made slower by RSS feeds is that Outlook will need time to sync with IE7′s feeds. By disabling this sync, you will improve Outlook’s performance.
Disable Outlook’s RSS Sync:
    1. Open Outlook 2007
    2. Click the Tools menu
    3. Click Options
    4. Select the Other tab
    5. Click the Advanced Options button
    6. Uncheck Sync RSS feeds to the Common Feed List
    7. Click OK X 2
Woo-hoo. That will speed up Outlook. If you want to remove the RSS subscriptions from Outlook, you may wish to do this following.
Mass Remove Feed Subscriptions from Outlook:
    1. Click Tools menu and then Options again.
    2. Select the poorly named Mail Setup tab
    3. Click the Data Files button
    4. Click the RSS Feeds tab
    5. Click the first feed and scroll down to the bottom of the feed list
    6. Hold the SHIFT key and click the last feed. All feeds should now be selected.
    7. Click the Remove button
    8. Confirm you want them all deleted.
Now we’ll need to delete the old feed content as well…
    9. Expand the RSS Feed folder under Personal Folders
    10. Select each feed and press Delete. You’ll have to confirm the delete.
    11. Repeat ad nauseum until all are gone.
     
    ---------------------------------------------------------------------------------------

Unsubscribe from an RSS Feed

At any time you can stop receiving, or unsubscribe from, a Really Simple Syndication (RSS) Feed. You can either cancel the feed and remove all items from that feed in Microsoft Office Outlook 2007, or cancel the feed and keep items downloaded from the feed.
 Note   If you want to keep the RSS Feed, but delete the downloaded items, open the folder for the RSS Feed, select the items to be deleted and then press DELETE.

Cancel an RSS Feed and remove all content from the feed

Delete the folder associated with the RSS Feed. Doing so will delete all of your downloaded items in the folder and cancel the RSS Feed.
  1. In Mail, in the Navigation Pane, expand the RSS Feeds folder.
Expanding the RSS Feeds folder
  1. Select the RSS Feed that you want to delete.
  2. Press DELETE.
  3. When prompted to confirm the deletion, click Yes.

Cancel an RSS Feed and keep all content from the feed

  1. On the Tools menu, click Account Settings.
  2. Click the RSS Feeds tab.
  3. Under Feed Name, click the feed you want cancel, and then click Remove.
 Note   To cancel multiple RSS Feeds, press and hold CTRL as you click RSS Feed names. This allows you to select multiple RSS Feeds.
Previously downloaded items from the feed are not deleted.

     
     

Thursday, March 6, 2014

Different UPS Definition Offline, Line-Interactive , Online

Different UPS Definition

 
Offline UPS
The UPS which has transformer time, BUT NO automatic voltage regulation (AVR) function. Its output will be square wave
Line-interactive UPS
The UPS which has transformer time, AND automatic voltage regulation (AVR) function is built-in. Its output can be either square wave or sine wave.
Online UPS
The UPS which has NO transformer time, AND automatic voltage regulation (AVR) function is built-in. It only produces sine wave output.
Different Type of UPS Comparison

Series Name Type Output Wave Transfer Time AVR PCB Communication Rated Power
Soho Econ offline Square >6 ms - Single Side - 500VA
Braver Line-interactive Square 2-6 ms Yes Single Side RS232 400VA, 600VA, 800VA
Braver Pro Line-interactive Square 2-6 ms Yes Single Side RS232 1KVA, 1.4KVA, 2KVA
Centrio Online Sine 0 ms Yes Single Side RS232, SNMP, RJ45, DB9 1KVA, 2KVA, 3KVA
Centrio DSP Online Sine 0 ms Yes Double Side RS232, SNMP, RJ45, DB9 6KVA, 10KVA, 15KVA, 20KVA
Sigma Online Sine 0 ms Yes Double Side RS232, SNMP, RJ45, DB9 4KVA, 6KVA
Vector 15KSL Online Sine 0 ms Yes Double Side RS232, SNMP, RJ45, DB9 15KVA
Vector 30KSL Online Sine 0 ms Yes Double Side RS232, SNMP, RJ45, DB9 30KVA
Vector Online Sine 0 ms Yes Double Side RS232, SNMP, RJ45, DB9 15KVA, 30KVA, 45KVA, 60KVA 75KVA, 90KVA, 105KVA, 120KVA
centrio 3c3 Online Sine 0 ms Yes Double Side RS232, SNMP, RJ45, DB9 20-80KVA

Wednesday, February 19, 2014

The installation of PGP Desktop has not been initialized or the initialization settings have been deleted or damaged

This installation of PGP has not been initialized...

Article:TECH149607  |  Created: 2009-10-28  |  Updated: 2011-02-06  |  Article URL http://www.symantec.com/docs/TECH149607
Article Type
Technical Solution

Product(s)

Languages

Issue




When attempting to open PGP Desktop in a PGP Universal Server managed environment, you receive the following error message and PGP Desktop fails to open:

This installation of PGP has not been initialized or the initialization settings have been deleted or damaged.

Solution




This error can occur when the PGP preference files on the computer have become corrupted on PGP Desktop clients. To resolve this issue, stop the PGP Services and delete the PGP preference files. When PGP Desktop is restarted, the preference files will be automatically re-created.

Use the following steps to delete the PGP preference files:

  1. Stop the PGP services by clicking the PGP Tray icon in the Windows system tray and then click Exit PGP Services.
  2. Browse to the following folder for your operating system:

    Windows XP - C:\Documents and Settings\%user name%\Application Data\PGP Corporation\PGP

    Windows Vista - C:\Users\%user name%\AppData\Roaming\PGP Corporation\PGP

    Windows 7 - C:\Users\%user name%\AppData\Roaming\PGP Corporation\PGP

    Note: If the Application Data/AppData folders are hidden, you must change the folder options for Windows Explorer to show hidden files and folders. In Windows Explorer, click Tools > Folder Options then click the View tab. In the Advanced Settings window, click Show hidden files, folders, and drives then click OK.
  3. Delete the PGPprefs and PGPpolicy files.
  4. Click Start > All Programs > Startup and then select PGPtray.exe
  5. If prompted, enter your license information and authorize the PGP Desktop software.

Friday, January 24, 2014

How to use Outlook policy to control credential prompts when connecting to an Exchange Server mailbox




  1. Click Start, click Run, type regedit, and then click OK.
  2. In the Registry Editor, locate the following key for Outlook 2013:

    HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\xx.0\Outlook\Security

    Where xx.0 is 15.0 for Outlook 2013, 14.0 for Outlook 2010, 12.0 for Outlook 2007, and 11.0 for Outlook 2003
  3. Point to New, and then click DWORD Value.
  4. Type PromptForCredentials as the name of the new registry entry, and then press ENTER.
  5. In the right pane, right-click PromptForCredentials, and then click Modify.
  6. In the Edit DWORD Value dialog box, and then type one of the following values in the Value data dialog box:

    ValueDescription
    0Cached credentials are used.
    1Cached credentials cannot be used. You are always prompted for logon credentials.
  7. Click OK.
 

Resolving "The User Profile Service failed the logon. User profile cannot be loaded."

Appears while attempting to logon in Windows Vista, 2008, 2008 R2 and 7.
Exact cause is unknown, but this issue may occur if the user profile was manually deleted by using the command prompt or Windows Explorer by a user or by some program. A profile that is manually deleted does not remove the security identifier (SID) from the user profile list in the registry. Since the SID is still present, Windows will still try to load the profile by using the ProfileImagePath that points to a nonexistent path. Therefore, the profile cannot be loaded.
This can also be a issue with the user profile entering into a backup state, or if the C:\Users\(User Name) user profile folder is manually renamed.

1. Log on to the Computer

Log on to the computer using the Administrator (or an Administrator-level) account.
If the computer is not joined to a domain, reboot it and start your computer in safe mode, then log on using the Administrator (or an Administrator-level) account.

2. Trawl through the Registry

Open the Start menu. In the Start Search area, type regedit and press Enter (if prompted by UAC, click Continue/Yes). In regedit, go to:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
Expand the ProfileList key and look for the SID key (named "S-1-5"...) with a long number that ends in ".bak". Click it, and look at the ProfileImagePath value in the right pane to verify that this is the user account profile that has the error.
a) If you have two SID keys with the same number (with one ending in ".bak" and one showing the affected user account in the ProfileImagePath value), continue to Step 3;
b) If you have just one SID key with the ProfileImagePath value showing the affected user account, proceed to Step 4.

3. Two SID keys with the same number

a) Of the two SID keys that corresponds to the affected user account, right-click the SID key that does NOT end in ".bak" and click Rename.
b) Add .bk to the end of the numbers and press Enter.
c) Right-click the other SID key that DOES end in ".bak" and click Rename.
d) Remove only .bak from the end of the numbers (so that it has the same name as the other SID key did before you renamed it) and press Enter.
e) Now go back and Rename the first one with .bk to .bak now at the end of the numbers and press Enter.

Proceed to Step 5...

4. Only one SID key ending in ".bak"

a) Right-click the SID key that corresponds to the affected user account and click Rename.
b) Remove only .bak from the end of the numbers, and press Enter.
c) In the right pane, right-click the RefCount value (if none exists, right-click the right pane and click New and DWORD (32 bit) Value, then type RefCount and press Enter), and click Modify.
d) Type 0 into the Value Data textbox and click OK.
e) In the right pane, right-click the State value and click Modify.
f) Type 0 into the Value Data textbox and click OK.

5. Try logging on again!

Close regedit and restart the computer. You should be able to logon now...

Monday, November 25, 2013

Channel Bonding Interfaces RedHat Enterprise

9.2.4. Channel Bonding Interfaces

Red Hat Enterprise Linux allows administrators to bind multiple network interfaces together into a single channel using the bonding kernel module and a special network interface called a channel bonding interface. Channel bonding enables two or more network interfaces to act as one, simultaneously increasing the bandwidth and providing redundancy.
To create a channel bonding interface, create a file in the /etc/sysconfig/network-scripts/ directory called ifcfg-bondN, replacing N with the number for the interface, such as 0.
The contents of the file can be identical to whatever type of interface is getting bonded, such as an Ethernet interface. The only difference is that the DEVICE directive is bondN, replacing N with the number for the interface. The NM_CONTROLLED directive can be added to prevent NetworkManager from configuring this device.
The following is a sample channel bonding configuration file:
Example 9.1. Sample ifcfg-bond0 interface configuration file

DEVICE=bond0
IPADDR=192.168.1.1
NETMASK=255.255.255.0
ONBOOT=yes
BOOTPROTO=none
USERCTL=no
NM_CONTROLLED=no
BONDING_OPTS="bonding parameters separated by spaces"

After the channel bonding interface is created, the network interfaces to be bound together must be configured by adding the MASTER and SLAVE directives to their configuration files. The configuration files for each of the channel-bonded interfaces can be nearly identical.
For example, if two Ethernet interfaces are being channel bonded, both eth0 and eth1 may look like the following example: 
 
DEVICE=ethN
BOOTPROTO=none
ONBOOT=yes
MASTER=bond0
SLAVE=yes
USERCTL=no
NM_CONTROLLED=no
 
In this example, replace N with the numerical value for the interface.
Support for bonding was added to NetworkManager in Red Hat Enterprise Linux 6.3. See Section 9.2.1, “Ethernet Interfaces” for an explanation of NM_CONTROLLED and the NM_BOND_VLAN_ENABLED directive.