<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
>
	<channel>
		<title>Michael Dale</title>
		<link>http://michaeldale.com.au</link>
		<description>looking back it was easy</description>
		<copyright>Copyright 2004-07-03 09:00:00</copyright>
		<generator>http://michaeldale.com.au</generator>
				<lastBuildDate>Fri, 29 Jan 2010 18:18:50 +1000</lastBuildDate>
						<item>
					<title>Juniper SRX210 Review</title>
					<link>http://michaeldale.com.au/archive/2010/01/29/juniper-srx210-review/</link>
					<comments>http://michaeldale.com.au/archive/2010/01/29/juniper-srx210-review/#comments</comments>
					<pubDate>Fri, 29 Jan 2010 18:18:50 +1000</pubDate>
					<dc:creator>Michael Dale</dc:creator>
					<description><![CDATA[<p>Well I've finally had some time to finish off my review of the SRX210! It's only taken like 4 months. There is still some things missing from this review that I will post about at some stage.</p>
<div>&nbsp;</div>
<div>The <a href="http://www.juniper.net/us/en/products-services/security/srx-series/srx210/">Juniper SRX 210</a> is a new firewall/router released earlier in 2009. It is the second smallest device in the SRX range (the SRX 100 being the smallest).</div>
<div>&nbsp;</div>
<div>The SRX range runs on JunOS with some new security features added that can be found in Juniper's previous firewall rage the SSG (and before that the netscreen) and in JunOS-ES.</div>
<div>&nbsp;</div>
<div>It is my understanding that the SRX series will slowly replace the SSG range.</div>
<div>&nbsp;</div>
<div>I recently purchased an SRX210 so that I could learn JunOS. I am coming from a Juniper SSG/Netscreen background, having looked after many Netscreen 5GTs, 25s and 50s along with the newer range the SSG 5/20/520 etc range.</div>
<div>&nbsp;</div>
<div>I have primarily used the SSGs for linking sites together with VPNs, providing VPN access to clients/employees, general firewalling/routing and some high availability. More recently I have been doing IPv6 over some of them.</div>
<div>&nbsp;</div>
<div>Since the SRX is based on JunOS it has all the underlying routing features found in Junipers other product ranges (such as the J series) plus the security features recently added, while the SSG is primarily a firewall device (although it has some pretty cool routing features in it too).&nbsp;You can read my review of the SSG 5 <a href="http://michaeldale.com.au/archive/2008/02/21/cisco-asa-5505-vs-juniper-ssg-5/">here</a>.</div>
<div>&nbsp;</div>
<div>So lets first look at the smaller SSG and SRX line up.</div>
<div>&nbsp;</div>
<div>The SRX100 is basically the SSG5 equivalent, while the SRX210 better matches up to the SSG20.</div>
<div>&nbsp;</div>
<div>In the SSG range the SSG5 and SSG20 were exactly the same except for the following differences:</div>
<ul>
<li>SSG20 has two mini-pim slots (for ADSL modules etc)</li>
<li>SSG20 loses two of the ethernet ports the SSG5 has</li>
<li>SSG20 is physically larger</li>
</ul>
<div>Other than that both have the same performance, memory options, wireless options etc.</div>
<div>&nbsp;</div>
<div>With the new SRX range the SRX210 is actually faster than the SRX100 and includes some nice extra features such as:</div>
<ul>
<li>SRX210 has 100mbit more routing throughput (750mbit)</li>
<li>2 gigabit ethernet ports</li>
<li>Express card slot for 3G modems</li>
<li>1 mini-pim slot</li>
<li>plus some other software things (increased session limit, max policies etc)</li>
</ul>
<div>Juniper have a nice product chart here:</div>
<div><a href="http://www.juniper.net/us/en/local/pdf/datasheets/1000265-en.pdf">http://www.juniper.net/us/en/local/pdf/datasheets/1000265-en.pdf</a></div>
<div>&nbsp;</div>
<div>One interesting difference between the two is the memory configuration options.</div>
<ul>
<li>The SRX100 models all have 1GB of ram installed, yet the base version has a software licensing limitation of 512mb.</li>
<li>You cannot upgrade a base SRX210 to 1GB as the base version only has 512mb of fixed memory.</li>
</ul>
<div>&nbsp;At this stage there is no built in wireless options for the SRX range. Juniper have released an external wireless access point that you can configure from the SRX, but I'm not going to talk about that in this review.</div>
<div>&nbsp;</div>
<div>So the SRX210 is actually quite a bit more useful than SRX100 depending on what you want to do, although both devices should be more than powerful enough for most routing requirements (750mbit on the SRX210!), although If you want to take full BGP tables you will need to be using at least an SRX650. I think this is a bit of a shame seeing as we're no longer limited by the operating system routing&nbsp;capabilities.</div>
<div>&nbsp;</div>
<div>One thing that I think is a bit odd is that the SRX can only do 3G via the Express Card slot (so SRX210 only); they don't support using usb modems (both SRX100 and SRX210 have USB ports). This feature could come in a software update, but I don't know if it will. At least it is an improvement over the SSG range that couldn't do it at all.</div>
<div>&nbsp;</div>
<div>So for the Netscreen/SSG users what does the SRX range offer:</div>
<ul>
<li>3G WWLAN (SRX210 only)</li>
<li>Significant routing performance increase</li>
<li>JunOS</li>
<li>Gigabit ethernet on smaller devices (from SRX210 upwards)</li>
<li>PoE options (SRX210)</li>
<li>Jflow/Netflow support</li>
</ul>
<div>So sounds great but unfortunately the SRX range is actually missing some features from the SSGs:</div>
<ul>
<li>Usable web interface (more on this later)</li>
<li>Integrated ADSL and wireless options</li>
<li>Auto Connect VPN (probably will be fixed in a software update)</li>
<li>Other minor feature differences&nbsp;</li>
</ul>
<div>So lets now look at the software in a bit more depth.</div>
<div>&nbsp;</div>
<div><b>ScreenOS vs JunOS.</b></div>
<div>&nbsp;</div>
<div>One of the reason's I liked the SSG range was the web interface. You can do just about anything from the web interface, it is really easy to see what policies are setup and you can easily disable and rearrange them.</div>
<div>&nbsp;</div>
<div>ScreenOS can have some interesting WebUI bugs but if you're running a fairly recent version and using Firefox or IE it works pretty well. It can be a bit slow to load over a WAN link, but once it has finished loading the excessive amount of javascript it is pretty quick.</div>
<div>&nbsp;</div>
<div>The SRX version of JunOS (tested with 9.6R2.11) has a web interface that is completely different to ScreenOS. It is broken down into two main sections configure and monitor. Unlike ScreenOS you need to switch between these two sections to either configure a setting or see what is actually going on. It might actually be a useful feature if is wasn't for the fact that the web interface is bad, really bad.</div>
<div>&nbsp;</div>
<div>My biggest issues include:</div>
<ul>
<li>It's slow, much much slower to load that ScreenOS</li>
<li>It seems to expire my session and log me out while in the process of doing stuff</li>
<li>It doesn't feel like it was designed for people to actually use. It is basically a graphical representation of the configuration file. I've noticed that I expect different things from a web interface verses a command line interface.</li>
</ul>
<div>Because of these reasons I don't even bother using the web interface, which really feels like I'm going backwards compared to the SSG. Don't get me wrong the command line in JunOS is great, more complex than ScreenOS but in the long term you will appreciate the power of it.</div>
<div>&nbsp;</div>
<div>For the larger range of SRX devices this probably doesn't matter as much because the people configuring them should really know how to use the command line; but I believe a good web interface is really important for the smaller devices especially if Juniper want this device to be popular in not just the enterprise market.</div>
<div>&nbsp;</div>
<div><em>UPDATE:</em></div>
<div><em>&nbsp;</em></div>
<div><em>Juniper have since released JunOS 10.0R2.10 which seems to have improved the speed of the web interface. They have also started working on fixing up many of the configuration pages. From what I have heard Juniper plan to keep improving it over the next few versions. I might do an updated post once the WebUI has been improved further.</em></div>
<div>&nbsp;</div>
<div>During the writing of this review Juniper have released at least three software updates and at least for me each upgrade as been an improvement. Before JunOS 10.0R2.10 the SRX210 was really too buggy for production use, I had lots of issues with keeping a stable PPPoE link up. Luckily this seems to have finally been fixed in the latest OS. This was one of the main reasons for the delay in this review. I really wanted to get the problem fixed first.</div>
<div>&nbsp;</div>
<div>Also during the review, one of the companies I work for purchased two SRX240s, this has allowed me to really get used to the operating system as I've had to setup Clustering/NAT/DHCP/VLANs/SNMP/VPNs and some firewall rules. I ended up configuring everything via the command line and I'm glad I did because the command line in JunOS is really much better than ScreenOS.</div>
<div>&nbsp;</div>
<div>The configuration in JunOS is converted to XML when loading, so the configuration process has a much more structured feel to it. Everything is nicely broken down into different sections such as: system, interfaces, security, vlans etc. I've found this makes it easier to find what you're looking when changing things.</div>
<div>&nbsp;</div>
<div>Upgrading the operating system is also easy as you can simply point JunOS to an HTTP url and not need to setup a TFTP server.</div>
<div>&nbsp;</div>
<div>I still prefer the ScreenOS WebUI for configuring firewall policies though, the whole process just seems quicker and better thought out.</div>
<div>&nbsp;</div>
<div>For laptop style VPNs Juniper have moved away from Netscreen Remote the 3rd party IPsec VPN software and replaced it with basically nothing. They now have something call dynamic VPN, which I haven't used yet. This type of VPN setup has a new VPN client but it also requires extra licenses to be purchased (at great expense I'm sure), so I probably won't use it. Luckily JunOS still supports IPsec VPNs so you should simply be able to use one of the better free VPN clients (Netscreen Remote really sucked anyway so no big loss). I haven't tested this yet, although if it does work correctly that is great because the SRX actually supports 128 IPsec tunnels on the SRX100 and double that on the 210! Heaps more than the old SSGs.</div>
<div>&nbsp;</div>
<div>One last thing I will mention in the software section, JunOS doesn't seem to support IPv6 in flow-based mode which is a shame. Hopefully this will come soon.</div>
<div>&nbsp;</div>
<div><strong>Hardware</strong></div>
<div>&nbsp;</div>
<div>The base Juniper SRX210 is about the same size as the SSG20; it includes 8 ethernet ports and a single mini-pim slot (the SSG20 had two, which was useful if say you wanted to have two adsl connections).</div>
<div>&nbsp;</div>
<div>The main difference between the two is the different integrated options.</div>
<div>The SSG20 allowed for wireless, where as the SRX210 gives you PoE and VoIP options.</div>
<div>&nbsp;</div>
<div><strong>Final Thoughts</strong></div>
<div>&nbsp;</div>
<div>The SRX210 is a promising device that has been plagued by some early software bugs (most of which have been fixed). It doesn't include all the features from the old SSG range (yet) and it does feel a bit more enterprise than the SSG. I think the smaller SSG range was great for small businesses, where as the smaller SRX range can get quite expensive with some of the optional extras.</div>
<div>&nbsp;</div>
<div>I will miss the integrated wireless options from the SSGs (the SRX external wireless is very expensive) and for the time being some of the stability.</div>
<div>&nbsp;</div>
<div>Saying all this JunOS is the future for Juniper and I believe the SRX range will keep getting better (and quickly JunOS 10.1 is due out soon).</div>
<div>&nbsp;</div>
<div>Juniper have also produced some nice help documents recently for users of ScreenOS, they also have many examples of say VPNs between an SSG and SRX which makes the upgrade process easier.</div>
<div>&nbsp;</div>
<div><strong>Further Reading</strong></div>
<div>&nbsp;</div>
<div>Getting Started Examples: <a href="http://kb.juniper.net/index?page=content&amp;id=KB15694">http://kb.juniper.net/index?page=content&amp;id=KB15694</a></div>
<div>Mapping of common troubleshooting commands from ScreenOS to JUNOS <a href="http://kb.juniper.net/index?page=content&amp;id=KB14000">http://kb.juniper.net/index?page=content&amp;id=KB14000</a></div>
<div>JunOS nat for screenos users <a href="http://www.juniper.net/us/en/local/pdf/app-notes/3500152-en.pdf">http://www.juniper.net/us/en/local/pdf/app-notes/3500152-en.pdf</a></div>
<div>&nbsp;</div>
<p>&nbsp;</p>
]]></description>
				</item>
							<item>
					<title>Native IPv6 over PPPoE with Internode and a Juniper SSG5</title>
					<link>http://michaeldale.com.au/archive/2010/01/17/native-ipv6-over-pppoe-with-internode-and-a-juniper-ssg5/</link>
					<comments>http://michaeldale.com.au/archive/2010/01/17/native-ipv6-over-pppoe-with-internode-and-a-juniper-ssg5/#comments</comments>
					<pubDate>Sun, 17 Jan 2010 11:10:17 +1000</pubDate>
					<dc:creator>Michael Dale</dc:creator>
					<description><![CDATA[<p><a href="http://www.internode.on.net/">Internode</a>&nbsp;released a trial of native IPv6 over ADSL a few months back, so anyone with an ADSL account with them can try it.</p>
<p>So one of my clients has an SSG5 and an internode connection so I thought I'd set it up.</p>
<p>So the setup:</p>
<ul>
<li>ADSL modem in bridge mode</li>
<li>SSG5 running ScreenOS 6.3.0r2 (I had some issues with 6.2, so it is best to use the latest OS)</li>
</ul>
<p>The very first step is to enable IPv6 on the SSG5, this requires you to run the following command and then restart/reboot the device:</p>
<div class="code">set envar ipv6=yes</div>
<p>Once done you should now have access to all the IPv6 functions in the WebUI.</p>
<p>The next step is to modify your PPPoE connection settings.</p>
<div class="code">
<p>set pppoe name &quot;Internode&quot; username &quot;username@ipv6.internode.on.net&quot; password &quot;encryptedpassword&quot;</p>
<p>set pppoe name &quot;Internode&quot; ppp ipv6cp ipcp</p>
</div>
<p>Now you need to enable IPv6 on the interface that the PPPoE connection is setup on.</p>
<div class="code">
<p>set interface &quot;ethernet0/0&quot; ipv6 mode &quot;host&quot;</p>
<p>set interface &quot;ethernet0/0&quot; ipv6 enable</p>
<p>set interface ethernet0/0 ipv6 ra accept</p>
<p>unset interface ethernet0/0 ipv6 nd nud</p>
</div>
<p>So the above should be enough for you to get the /64 on the PPPoE interface.</p>
<p>Internode is currently handing out a /60 for use in your network (via DHCPv6), so lets now set that up.</p>
<div class="code">
<p>set interface ethernet0/0 dhcp6 client</p>
<p>set interface ethernet0/0 dhcp6 client options rapid-commit</p>
<p>set interface ethernet0/0 dhcp6 client options request pd</p>
<p>set interface ethernet0/0 dhcp6 client pd ra-interface bgroup0</p>
<p>set interface ethernet0/0 dhcp6 client enable</p>
</div>
<p>In the above &quot;bgroup0&quot; is my LAN interface.</p>
<p>Now let's get IPv6 running on &quot;bgroup0&quot;</p>
<div class="code">
<p>set interface &quot;bgroup0&quot; ipv6 mode &quot;router&quot;</p>
<p>set interface &quot;bgroup0&quot; ipv6 ip 2001:44b8:7763:baa0::1/64</p>
<p>set interface &quot;bgroup0&quot; ipv6 enable</p>
<p>set interface bgroup0 ipv6 ra link-address</p>
<p>set interface bgroup0 ipv6 ra transmit</p>
<p>unset interface bgroup0 ipv6 nd nud</p>
</div>
<p>In the above the IPv6 address there is my first /64 out of the /60, I've manually set it to a :1 address but you can use whatever it's default auto assigned address is.</p>
<p>Now you might want to hand out internodes IPv6 DNS server addresses to your LAN</p>
<div class="code">
<p>set interface bgroup0 dhcp6 server</p>
<p>set interface bgroup0 dhcp6 server options dns dns1 2001:44b8:1::6</p>
<p>set interface bgroup0 dhcp6 server options dns dns2 2001:44b8:2::6</p>
<p>set interface bgroup0 dhcp6 server enable</p>
</div>
<p>Now we need to setup the default IPv6 route, as the one that is added by default is incorrect.</p>
<div class="code">
<p>set route ::/0 interface ethernet0/0 gateway ::</p>
</div>
<p>And finally the IPv6 policy to allow traffic out (yay no NAT).</p>
<div class="code">
<p>set policy id 12 from &quot;Trust&quot; to &quot;Untrust&quot;&nbsp; &quot;Any-IPv6&quot; &quot;Any-IPv6&quot; &quot;ANY&quot; permit log</p>
</div>
<p>That should be all you need to do to get IPv6 working on your network.</p>
<p>There is more information over at the <a href="http://ipv6.internode.on.net/configuration/adsl-faq-guide/">internode site</a> if needed.</p>
<p>And here is a traceroute from a computer on the LAN</p>
<div class="code">
<p>C:\Users\Administrator&gt;tracert -6 ipv6.google.com</p>
<p>Tracing route to ipv6.l.google.com [2001:4860:c004::68]</p>
<p>over a maximum of 30 hops:</p>
<p>&nbsp;&nbsp;1 &nbsp; &nbsp; 1 ms &nbsp; &nbsp;&lt;1 ms &nbsp; &nbsp;&lt;1 ms &nbsp;2001:44b8:7763:baa0::1</p>
<p>&nbsp;&nbsp;2 &nbsp; &nbsp;37 ms &nbsp; &nbsp;37 ms &nbsp; &nbsp;37 ms &nbsp;loop0.lns6.syd7.internode.on.net [2001:44b8:b070::4]</p>
<p>&nbsp;&nbsp;3 &nbsp; &nbsp;37 ms &nbsp; &nbsp;37 ms &nbsp; &nbsp;37 ms &nbsp;gi1-1.cor2.syd7.internode.on.net [2001:44b8:b070:5::1]</p>
<p>&nbsp;&nbsp;4 &nbsp; &nbsp;37 ms &nbsp; &nbsp; * &nbsp; &nbsp; &nbsp; 37 ms &nbsp;gi6-0-0-146.bdr1.syd6.internode.on.net [2001:44b8:b060:146::1]</p>
<p>&nbsp;&nbsp;5 &nbsp; &nbsp;37 ms &nbsp; &nbsp;37 ms &nbsp; &nbsp;37 ms &nbsp;2001:4860:1:1:0:1283:0:2</p>
<p>&nbsp;&nbsp;6 &nbsp; &nbsp;38 ms &nbsp; &nbsp;38 ms &nbsp; &nbsp;39 ms &nbsp;2001:4860::1:0:9f8</p>
<p>&nbsp;&nbsp;7 &nbsp; 184 ms &nbsp; 295 ms &nbsp; 174 ms &nbsp;2001:4860::1:0:165</p>
<p>&nbsp;&nbsp;8 &nbsp; 175 ms &nbsp; 175 ms &nbsp; 175 ms &nbsp;2001:4860::1:0:890</p>
<p>&nbsp;&nbsp;9 &nbsp; 181 ms &nbsp; 176 ms &nbsp; 182 ms &nbsp;2001:4860::29</p>
<p>&nbsp;10 &nbsp; 185 ms &nbsp; 176 ms &nbsp; 244 ms &nbsp;tx-in-x68.1e100.net [2001:4860:c004::68]</p>
<p>Trace complete.</p>
</div>
]]></description>
				</item>
							<item>
					<title>Intel Matrix Raid is Bad</title>
					<link>http://michaeldale.com.au/archive/2010/01/03/intel-matrix-raid-is-bad/</link>
					<comments>http://michaeldale.com.au/archive/2010/01/03/intel-matrix-raid-is-bad/#comments</comments>
					<pubDate>Sun, 03 Jan 2010 09:43:31 +1000</pubDate>
					<dc:creator>Michael Dale</dc:creator>
					<description><![CDATA[<p>So we've got two computers in the house using Intel Matrix raid.</p>
<p>First our server is using it for our Raid 1 boot drive, and my old desktop (just upgraded to an i7 iMac) was using it for its Raid 5 boot drive.</p>
<p>From what I've found, if WIndows crashes or isn't shutdown correctly the Raid will require rebuilding, both these systems do it. While it is rebuilding the performance is awful. It also takes up to 24hrs on our server to rebuild the array.</p>
<p>The other thing I have found is that the write performance on the Raid 5 drives is really really slow. My desktop was running it, bad idea I should have just stuck to a single drive, there was no real reason for using Raid.</p>
<p>Both systems aren't bad/slow (Q6600s with 8 and 4gb ram). We've also got a Raid 5 in the server running off a RaidCore PCI-X card and it is great. Never needs to rebuild and it is quick.&nbsp;</p>
<p>So yeah not surprising that the RaidCore actually works well but I didn't think Intel Matrix raid would be so bad...</p>
]]></description>
				</item>
							<item>
					<title>New Domain</title>
					<link>http://michaeldale.com.au/archive/2009/10/20/new-domain/</link>
					<comments>http://michaeldale.com.au/archive/2009/10/20/new-domain/#comments</comments>
					<pubDate>Tue, 20 Oct 2009 12:27:01 +1000</pubDate>
					<dc:creator>Michael Dale</dc:creator>
					<description><![CDATA[<p>It's time for a different domain for my personal blog. I'm trying to seperate my work, personal and project sites.</p>
<p>So once finished it should look like:</p>
<ul>
<li>bluetrait.com/org for Bluetrait projects</li>
<li>dalegroup.net/net.au for my business website</li>
<li>michaeldale.com.au for my personal blog</li>
</ul>
<p>It might take some time for me to actually split bluetrait.com out and I'll need to make sure all the links keep working etc but it will happen.</p>
<p>On another note I've been meaning to release a newer version of Bluetrait Money for download but I keep adding things to it :)</p>
]]></description>
				</item>
							<item>
					<title>Jflow on SRX210</title>
					<link>http://michaeldale.com.au/archive/2009/08/13/jflow-on-srx210/</link>
					<comments>http://michaeldale.com.au/archive/2009/08/13/jflow-on-srx210/#comments</comments>
					<pubDate>Thu, 13 Aug 2009 18:52:50 +1000</pubDate>
					<dc:creator>Michael Dale</dc:creator>
					<description><![CDATA[<p>We'll I've got my Juniper SRX210 up and running and it supports some stuff the old SSG didn't (it is also missing a few features too).</p>
<p>One of the new features is the support for JFlow (which is the Juniper version of Cisco's NetFlow).</p>
<p>Basically it means that the firewall can log traffic to a server in a format that allows for graphs such as this:</p>
<p><a href="http://www.bluetrait.com/images/jflow.png"><img alt="Jflow" src="http://www.bluetrait.com/images/jflow_small.png" /></a></p>
<p>Pretty cool. Anyway the documentation for the SRX isn't that great, so here is my configuration for this (running SRX JunOS 9.6):</p>
<div class="code">
<p>fe-0/0/7 {</p>
<p>&nbsp;&nbsp; &nbsp;unit 0 {</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp;family inet {</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;filter {</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;input cflow;</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;output all;</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;}</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;address 203.206.210.249/29;</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp;}</p>
<p>&nbsp;&nbsp; &nbsp;}</p>
<p>}</p>
<p>firewall {</p>
<p>&nbsp;&nbsp; &nbsp;filter all {</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp;term all { &nbsp;</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;then {</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;sample;</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;accept;</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;}</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp;}</p>
<p>&nbsp;&nbsp; &nbsp;}</p>
<p>&nbsp;&nbsp; &nbsp;filter cflow {</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp;term 1 {</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;then {</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;sample;</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;accept;</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;}</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp;}</p>
<p>&nbsp;&nbsp; &nbsp;}</p>
<p>}</p>
<p>forwarding-options {</p>
<p>&nbsp;&nbsp; &nbsp;sampling {</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp;input {</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;rate 1;</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;run-length 0;</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;max-packets-per-second 50000;</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp;} &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp;family inet {</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;output {</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;flow-server 203.206.210.250 {</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;port 2055;</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;version 5;</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;}</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;}</p>
<p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp;}</p>
<p>&nbsp;&nbsp; &nbsp;}</p>
<p>}</p>
</div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<p>&nbsp;</p>
]]></description>
				</item>
							<item>
					<title>WordPress 2.0</title>
					<link>http://michaeldale.com.au/archive/2009/07/31/wordpress-20/</link>
					<comments>http://michaeldale.com.au/archive/2009/07/31/wordpress-20/#comments</comments>
					<pubDate>Fri, 31 Jul 2009 23:18:46 +1000</pubDate>
					<dc:creator>Michael Dale</dc:creator>
					<description><![CDATA[<p>Well it looks like WordPress 2.0 is no <a href="http://wordpress.org/development/2009/07/the-wordpress-2-0-x-legacy-branch-is-deprecated/">longer going to be supported</a>, so it is probably about time to rewrite some of my plugins to use some of the new WordPress developer features such as better database security.</p>
<p>I wonder when they're going to drop php 4...</p>
]]></description>
				</item>
							<item>
					<title>Bluetrait Connector now out</title>
					<link>http://michaeldale.com.au/archive/2009/07/24/bluetrait-connector-now-out/</link>
					<comments>http://michaeldale.com.au/archive/2009/07/24/bluetrait-connector-now-out/#comments</comments>
					<pubDate>Fri, 24 Jul 2009 20:26:39 +1000</pubDate>
					<dc:creator>Michael Dale</dc:creator>
					<description><![CDATA[<p>Well I've now released all three programs for download. More info <a href="http://www.bluetrait.com/page/bluetrait-connector-for-wordpress/">here</a>.</p>
]]></description>
				</item>
							<item>
					<title>Bluetrait Connector for WordPress</title>
					<link>http://michaeldale.com.au/archive/2009/07/24/bluetrait-connector-for-wordpress-2/</link>
					<comments>http://michaeldale.com.au/archive/2009/07/24/bluetrait-connector-for-wordpress-2/#comments</comments>
					<pubDate>Fri, 24 Jul 2009 00:03:31 +1000</pubDate>
					<dc:creator>Michael Dale</dc:creator>
					<description><![CDATA[<p>I've been hard at work on Bluetrait 2.1 and have now successfully got events to sync up to a master Bluetrait install.</p>
<p>So I've decided that the Bluetrait Event Viewer needed some love and have been working on a new WordPress plugin called Bluetrait Connector.</p>
<p>This plugin will allow a WordPress install to connect via SOAP to a Bluetrait server.</p>
<p>Basically using Bluetrait 2.1 + Bluetrait Event Viewer 1.9 and Bluetrait Connector you will be able to sync events from a WordPress install to Bluetrait.</p>
<p>I plan to have a beta release of these three programs this weekend :)</p>
]]></description>
				</item>
							<item>
					<title>New Router/Firewall Time! Juniper SRX 210</title>
					<link>http://michaeldale.com.au/archive/2009/07/22/new-routerfirewall-time-juniper-srx-210/</link>
					<comments>http://michaeldale.com.au/archive/2009/07/22/new-routerfirewall-time-juniper-srx-210/#comments</comments>
					<pubDate>Wed, 22 Jul 2009 21:40:01 +1000</pubDate>
					<dc:creator>Michael Dale</dc:creator>
					<description><![CDATA[<p>We'll I've had my <a href="http://www.bluetrait.com/archive/2007/01/13/juniper-ssg-5/">SSG 5</a>&nbsp;for about 2.5 years now and it has worked great, and will probably keep working for many years to come. But Juniper have released a new/replacement model (kind of, they're still selling the SSGs) that runs JunOS.</p>
<p>So I thought it was about time to learn the operating system as ScreenOS (OS on the SSG) will eventually be discontinued.</p>
<p>The <a href="http://www.juniper.net/us/en/products-services/security/srx-series/srx210/">SRX 210</a>&nbsp;is really more of a replacement to the SSG 20, but it looks there isn't a SSG 5 replacement (yet at least, I did see some mentions of an SRX 100).</p>
<p>Anyway hopefully I should get it next week and then I'll do a review of it.</p>
<p><img alt="Juniper SRX 210" src="http://www.bluetrait.com/images/srx210.png" /></p>
]]></description>
				</item>
							<item>
					<title>New Job</title>
					<link>http://michaeldale.com.au/archive/2009/07/17/new-job/</link>
					<comments>http://michaeldale.com.au/archive/2009/07/17/new-job/#comments</comments>
					<pubDate>Fri, 17 Jul 2009 23:49:00 +1000</pubDate>
					<dc:creator>Michael Dale</dc:creator>
					<description><![CDATA[<p>I have a new job at <a href="http://www.digitalpacific.com.au/">Digital Pacific</a> (a sydney based web hosting company) as their Network Engineer.</p>
<p>I have only been there two days and my desk is already filled with networking gear :)</p>
<p><img src="http://www.bluetrait.com/files/desk.jpg" alt="My Desk" /></p>
]]></description>
				</item>
				</channel>
</rss>