Happy New Year 2007!

Here in Rome the fireworks have been going since dark. It's probably like being under
fire, or Saturday night in Iraq.

Here is hoping for a better year for the Earth and all it inhabitants.



Be always at war with your vices, at peace with your neighbors, and let each new year find you a better man. ~Benjamin Franklin

Enterasys 1800 series routers

I've posted ab out Adtran Netvanta and cisco routers in the past. I'd like to add another manufacturer to small b ut prestigious list of router manufacturers that I've posted my 2cents about.

I recently had to configure two Enterasys 1805 branch routers that were to be installed by the customer in a point to poi nt configuration. This customer had just recently added another office a state away and was looking to get that new office on the main corporate LAN. They also have a VoIP application so not only was their regulate end-user data going to be connected b ut also their ip based phone systems .

The Entarasys was ordered and purchased by the customer and shipped to my office to be configured. Once configured, they were to be shipped back to the customer and they would do the physical cabling and installation.

The model was heavy in weight which I tend to like in networking equipment because it gives a feeling that the device is not just a cheap peice of plastic garbage. Although, I must add that lightness does not mean the the device will not work or is junk. I'm just a little old school and like the feel and sense of reliability from the weight of metal. An example of light not necessarily meaning not effective or reliable is the Adran NetVanta 3200 series. That device is very light but works very well.

The interface is industry standard which means that it looks and feels like Cisco. Con configuration of the WAN interfaces differed slightly and took a little adjusting to get going . The 1805 come with a fixed LAN interface and a NIM slot that can handle to Network Modules. I of course in each of the two routers used up one for the point to point connection. They have firewall and VPN features of which I used neither. They have SNMP for monitoring and their speed was very decent. While looking o nether web site , I found the data sheet for the using and one of the things that I found interesting and have not easily found from other manufacturers is the MTF (Mean Time Before Failure). for this unit it was rated at 72 ,000 hours - not bad at all.

It was a very inexpensive router and fairly easy to configure and get going. The only complain I have for this unit is the no shutdown command did not have the desired results. What I was looking to do and I'm fairly certain that I've done it on Cisco routers before , is issue a no shut command on the router's interfaces so that after they've been shipped back to the customer they could plug them into a live T1 and the interface and protocol would come right up as active. The routers did not do this so the customer had to login using the provided console cable and run the command.

Overall I give the router a thumbs up.

Resolutions

Learn LSL
Learn Building
Go Premium
Get job? ( already had 2 offers )
Get own house
Slip ***** an exploding poseball instead of one of her sex poseballs.
Become a muse.
More Piracy
Shoot down some planes.
Get a slave.

Making resolutions is a cleansing ritual of self-assessment and repentance that demands personal honesty and, ultimately, reinforces humility. Breaking them is part of the cycle. - Eric Zorn

The Shockwave Travel Writer Part 5

I don't remember how many days it's been now, I can just see the end of my time in Rome coming to a close in a few days. The Lemonchello in the evenings does sort of make my memory of the number of days disappear.

So I have actually been in the Colesseo now, and walked all around Old Rome, and the Palatine.

Surprisingly in one shop they were selling Italian made XXXX beer from home.

Walked around the Castle, and it was full of frescos.

I installed SL on the PC in the apartment here, the CPU is a 2500 but the video card is 512M. It has less lag than the 300064 and the 128m video card. Of course it might be the network it's on as well.

vincit qui se vincit (S/he conquers who conquers her/himself.) - Roman Proverb

The Shockwave Travel Writer Part 4



Xmas eve
Saw Trevi fountain, (and others ) the Presidents Palace, went to the Portaportese Flea Market and found that the trendy boots were anywhere from 10 Euro to 20 euro, that's about 5 UK Pounds!

Walked though a main shopping area, and compared prices. It's almost worth getting on Easyjet and flying here and back to the UK, when I have a few hundred pound to spend on clothes.

Xmas Day
The the stroke of midnight on Xmas eve all the church bells in town were ringing.
Opened Presents.
That day I went for a long walk to the Tiber River, and crossed at Tiber island and then back again a bit downstream.
I went past a few old temples, and you can see marble rubble just lying in courtyards of buildings, and churches that have Roman columns built in to the walls.
Travel on train/bus is really cheap, 1 Euro for 75 minutes, thats if you put your ticket in the machine. The last two days, the busses have been so full we have not been able to put the tickes inthe machines to validate them.

Boxing day
We took the Archeobus to see the Appian Way, San Callisto Catacombs , There are about 1 km of aqueducts just outside Rome.

Police forces
There are about 6 police forces in italy, andthey are mostly armed
1)Polizia di Stato (Civil Police)
2)Carabinieri (Military Police)
3)Guardia di finanza (Financial or Tax Police)
4)Corpo Forestale dello Stato ( Foresters)
5)Polizia Municipale ( Municipal Police mostly for Traffic)
6)Polizia Penitenziaria ( Jail officers )
There are armed guards on the subway, and at some stations.

Street Traders
There are a LOT of guys, selling Sun Glasses, Tripods, Wooden Trains in the shape of letters, scarves, etc.
I think they are mostly Bangladeshis.
The Natural enemyof the Street Trader is Number 3 above.


As in Rome there is, apart from the Romans, a population of statues, so apart from this real world there is a world of illusion, almost more potent, in which most men live. - Goethe

Pirates

I'm very happy to say the PiratesofSL group is back and having battles. Woot!

So please join in, get your best pirate gear, jump on a ship and start shooting some cannon.

"The average man will bristle if you say his father was dishonest, but he will brag a little if he discovers that his great-grandfather was a pirate.” - Bern Williams

The Shockwave Travel Writer Part 3

Rome. Day one
Train from Milan was four hours.
We arrived in the afternoon, it took ages to find our apartment, but it was not yet dark, so as the coliseum was so close, we decided to have a quick look. It's one of those things I have always wanted to see, it was just like seeing Stonehenge for the first time.

Day Two

We took a few buses around the city, and arrived at the Vatican. St Peters is much bigger than I had imagined and much more ornate. I had to do the tourist thing and send a postcard from the Vatican Post office. In general Italy is much cheaper than the UK, Food and drink is almost half the price as the UK.

Dealing with crossing the road against the endless traffic is easy, if a little nerve racking, just walk, and the cars will stop.

They like to get as close as they can before they stop, but they will stop. Don't run, or hurry, then they will know that your a tourist. I think I have blended in, but my features show that I'm not a local.

Day Three.

Highlights of today, back to the market, walked around Old Rome,Trajan's Column, went to the Spanish Steps, and shopping, birthday for a friend.

"Methinks I will not die quite happy without having seen something of that Rome of which I have read so much -Sir Walter Scott

The Shockwave Travel writer Part 2

Milan,
Took the train from Geneva.
Two main sights of Milan is the cathedral, and the castle. The Cathedral is huge, and is a survivor of WW2, most of the rest of the town was flattened. You can also go up and walk around the roof, there aren't any warning signs that would be plastered everywhere in the UK.

The castle is brick built and contains the city museums.

The woman are well dressed in skinny jeans and boots, a fashion I adore. The men have not got the skinhead look that is so popular in the UK.
Lots more men with long hair, and there are more people wearing hats.
The shopping is excellent.

People in Europe seem to be thinner. I didn't see any fat people walking the street.
Aha!! I have just realized the cause of obesity!
It's speaking English!
Looks like another boost for Esperanto.

The main train station would look perfect in Gondor due to all the statues, and fountains. I suspect it's one of Mussolini's gifts to architecture.


Everyone loves justice in the affairs of another. - Italian Proverb

Xmas Card


card sl final
Originally uploaded by shockwaveplasma.
Here is a XMAS card I gave to some SL friends.

Sorry I missed a few of you out, but it was the last thing I was doing before I left for my holiday. And I stopped dropping it in to Inventories at 2.30 am


I couldnt help but put an FSM in the graphic.


"The whole mob has let itself go in pleasures" - Seneca on the Saturnalia

Remote Support Software

I found this a site that provides an online remote support solution:

Wait...before you click away. I know everyone knows the name brands of
remote support software that provide you with computer remote access over the web, but this one although it doesn't have an IT household name does the job like the others. In fact, it let let's technical support and IT pros provide remote assistance software for their end-users on the cheap. No, it's not just another executable with an IP address compiled into it for downloading. They have a bit more dynamic on-demand remote support system that let's you make changes to your own configuration if you need to.

So let's say you get one of the other brands of
computer remote control packages for remote tech support software that works over the web that has a static configuration and then you change ISP providers. Your out of luck. Sure you could have Dynamic DNS setup and that's good to but that's another piece of software running on your system and other id to maintain and another point of failure. Yes, point of failure. If you switch from cable, let's say, to DSL or visa versa, you have to get a new program. One can argue that you do not because of DDNS, but what if you want to provide online computer remote support software from another network. Now you have to get that same service running on the other network and the next and the next. Their system, although it works just fine with DDNS, it doesn't need it.

When you sign-up for an account you get a login to their site, not unfamiliar as many site have this, and a user page. On that user page you configure your networks settings. That's right, for many of you who have looked into software like this it's the same information you provide to the other site that have a static remote support solution. But the big difference here is that you don't wait for your
pc remote support executable to be changed and of course to get charged again. It's on the fly. Change you config and instantly the same customer that you had provided on-demand pc remote support for just a while ago from another network now is connecting to the new network. You may be thinking that you need to have all your users go to their site to get remote assistance over the web from you. No, not at all. They have an executable program too that you get at no additional cost and it's dynamic too. Pretty Cool!!

I'm going to work with it some more and post back with more information.


Adtran Netvanta 3200 Routers

I configured a few more Adtran Netvanta 3200 routers this past week.

I know I already have a post about these routers but I have to do it again. It's been some time since the last post and several firmware and software updates have made their way into this excellent product by Adtran since then.

I had to replace two Cisco routers with the Adtrans for reasons I won't go into because it really not important. These Netvantas came with firmware version 13.2. I thought the last batch at version 12 were good, Adtran topped it with some nice additions and the GUI, at least at that time, seemed to work even faster than before. I sus[past there were some hardware Updates as well like CPU and supporting ASICs.

They have some really nice features and I noticed that BGP was listed as a protocol plus HDLC protocol which means they can inter-operate with Cisco routers using Cisco proprietary protocol. Their live stats are great too. Although through command line you would have to keep repeating the command, through the GUI they just refresh and the data is actually good important information. They even display the operating temperature. They are a breeze to configure and get up and running. I was able to do both of them within an hour. I was swapping out live routers in a point to point configuration.

This customer didn't;t require QoS even though there was VoIP going over the T but the last time I had an encounter with these networking units it was for QoS purposes and VoIP and they really did the job.

Good work Adtran!!

Oh, did I forget to mention they cost a fraction of what comperable Cisco networking gear costs and you get support too - in english.

Where's Shockwave?

The Shockwave Travel Writer

Geneva

Well for those that ever want to go to Geneva, dont go on a Sunday, the whole city closes down. Only the corner shops and the ppl who run the roasted nut stands were open.

But I was able to go underneath the Cathedral to see the extensive work, done by the archeologists. It's a great display, but not really one I would do a 3 hr flight to see.

The Swiss franc notes are very colourful and they start from 10F, from 5F and below are coins, all the way to .5F. Thats equal to half an australian cent. Oddly the city is full of banks, no kidding, banks, banks swiss army knifes, watches ,swiss army knifes and clothes. Not just ordinary clothes, but the stuff Princess Di would wear ( if she still alive ). And Fur! Lots of fur.
Needless to say everything was expensive, even the golden arches was expensive.

The hotel was right in the middle of the red light district, so the working girls would gather at the rear of the hotel. One was wearing a short black leather skirt, with a black leather halter neck top and black thigh boots, I thought that looked really sexy, and strangley so familiar...oh yeah....*cough cough*

So rather than go to Geneva, unless you have a thing for bankers, do something exciting, defrag your harddrive!

I would post some pictures, but the Camera came up with the error message "Insufficent Input", and shutdown.


Switzerland is simply a large, lumpy, solid rock with a thin skin of grass stretched over it.
- Mark Twain

PixelPulse is out


ppulse2
Originally uploaded by shockwaveplasma.
When I say it's Hot, I mean it, and I've just started reading the contents!
A Journalist is a machine that converts coffee into copy.-- Michael Ryan Elgan

Why SL is hard to write and fix

( Totally unrelated picture )

















One of my favorite thinkers ( and Terry Prattchet fan ) Gwyneth Llewelyn has written a post on why SL is more than just an application, and basically how silly comments from the great unwashed masses are.

I think I left a note on Erbos blog some months ago , about the same thing, and how I used to work for an ISP, and the stupid comments in the forums from the customers. The tech guys would tell me the callers who are windows networking people have the oddest ideas.

Caller: My email is down, do you have a problem with your exchange server?
Techie: We don't have any exchange servers, what error messages are you getting?
Caller:NO Exchange, no wonder the emails are not working.
Techie falls off chair laughing.....

The CEO was called a port swilling, suited fatcat, in reality, he's never more happy than when he's putting Cisco gear together, and has the largest collection of black t-shirts, excepting Death Metal fans.

EDIT:
I suspect I was still out of my mind from lack of sleep, I wrote this originally


I would rather be the lead role in a zombiegoatbukkake movie than touch that "thing" of yours
-Shockwave Plasma

work

Due to an unseen amount of work, like four, twelve hour days in a row, I've not been doing much in SL :-(

Not even any old pics to load. Sorry

EDIT:- 28 Hrs awake at the office is not fun, but I came home before the hallucinations started.

While Matrix like bulges in the fabric of spacetime are a tolerable visual hallucination, it's when the hands start coming out of the bulges and start talking like a sock puppet, you know it's time to get some sleep.


Personally, I have nothing against work, particularly when performed, quietly and unobtrusively, by someone else. I just don't happen to think it's an appropriate subject for an "ethic."
Barbara Ehrenreich

The Princess of Purple and The Pixellated Paperdoll


I would like to say Hello to Reina Quine and Patience Xie, newly added to list of "Random Mad People".



"I think it pisses God off if you walk by the color purple in a field somewhere and don't notice it." --Alice Walker

Re: Mail server report - another desktop email trojan.

The guys who program viruses and trojans and all other sorts of malware and adware are very clever. Don't get me wrong, I don;t condone what they do and actually despise it. It's a thorn in my side as I try to about my job, every now and then I'll get someone who has just polluted their computer system with one of the adware type of programs that either creates pop-ups gallery or has slowed down their desktop so bad they could barely do anything productive.
Some of the worst one out there make the computer almost useless.

These types just don't make sense to me. If they have the talent or skill to put together software that could download to systems automatically and open browsers and go to web pages they want the unsuspecting computer users to go to, why make a computer useless with junk. Make money with this talent. Why annoy people?

The latest incanation I've seen was just today. It's not actually a new one but a variation of the same old tired method of trying to infect desktops all around the world. It's the simple email a zip attachment that contains a computer virus routine. What makes this and other like it interesting is that the subject and body of the messages are made to look like they are really legitimate. This one had a subject that read:

Re: Mail server report

Well, this matches the usual bland email subject found in most server based or monitoring type applications and could fool many users. The body could also get people ot believe that it's a legitimate email. It mentioned things about risk and your computer should be updated and the attachment had a name that was similar to a Microsoft Knowledgebase file name. All of these coupled together has probably got a lot of people running the attachment thinking it's going to help them.

I believe there should be some real penalties for people who are caught doing these things. There must be some liability for the actions they take. They hurt people by spreading these types of programs around.

Numbers and money

Last night I had people asking me, "How do I make money"?

While this is not unusual, it was odd that the new people who where asking didn't even seem to know what SL was about.

The same people were asking "What do I do now?" and "How do I play this game"?

It was only when I looked at Saturdays Times, ( on Monday morning ) that I saw this cover.
The article inside also covers Moopf and his skates.

I can only conclude that this was the reason for the very high number of people in world last night.

The Times has a daily circulation of about 650,000.

A link to the online article
http://www.timesonline.co.uk/article/0,,28053-2479694.html


( Blogger formatting is back...yay )

“Newspapers are unable, seemingly to discriminate between a bicycle accident and the collapse of civilization” - George Bernard Shaw

Number

Well I saw 17982 as the highest inworld at about 23.00 GMT

17340


17340
Originally uploaded by shockwaveplasma.
I'm sure I saw it hit 17,650, I wonder if we will hit 18,000 ?

Book Review

I have seen a few mentions of the book "The Victorian Internet" by Tom Standage, from Ordinal and Erbo.

So on my last visit to the Library, I ordered a copy. It was not as big as I thought it would be, but quite a good read. It's about 200 pages long.

It's full of lurid tales of vice and naked ambition and seedy hotels with record company executives ripping off young talented..hang on, sorry wrong book.

Victorian Internet is mostly about Samuel Morse and how the telegraph system he invented changed the times it takes to communicate news from months to minutes.

It gives a backgroud to people and ideas leading up to his invention, and the incredible amount of trouble it took to get some backing to get it recognized as something worthwhile.

But I suspect most people who read this blog will recognize the misunderstandings that people had then, as now.

An ISP where I used to work, was once asked to send a caller the Internet on CD. There was also the ever popular, "Do I have to be connected to the Internet to get my Email"?


BTW: Blogger has taken all my formatting away! ( Stupid Blogger )



If only we'd stop trying to be happy, we could have a pretty good time.
~Edith Wharton

New Bloggers

You might have noticed a few unfamiliar names on the blog-roll. It's Eureka and Lienna.

Lienna is writing for Pixel Pulse, and Eureka for the Huffington Times.

I love the cool looking space gurrl on Liennas site. I'm also jealous of her dream journal. I just have Jungian dreams, it's my unconscious telling me things, sorting things out, etc

I want some Freudian ones for a change, it just not fair! Come on unconscious, your asleep, have some fun for a change!

They are mostly doing articles on sex in second life.

Eurekas article dated Monday, November 27, 2006, talking to "Magnus" is typical in the double standards I often encounter ( SL and RL ). Seems that it's OK for him to come inworld and have some Cyber, but if it was his RL wife doing the same..oh dear, that's just not on.

BB Brodys article on getting caught flashing his polygons, by his wife is just brilliant.


I must do more flying, but the lag has been so bad, it's not always worth it.


Your vision will become clear only when you look into your heart. Who looks outside, dreams. Who looks inside, awakens. Carl Jung

16000


16000
Originally uploaded by shockwaveplasma.
16,000 For sure this time.

loopy


loopy
Originally uploaded by shockwaveplasma.
So here I am on the Nissan car dispenser. Watching the cars go around the loop, and giggling myself silly when they come off.

Bottom left you can see some explosives going off. I have IMed Toast, "the giver of car keys", but had no reply. I guess they were getting a bit tired of waiting down there as well.

I was tempted to fly over and stand on bottom of the second loop and see what happens.


“Auto racing is boring except when a car is going at least 172 miles per hour upside down.” - Dave Barry

Grid Down



Da grid its broked :-(

Casters up mode, Borked, Down, On the fritz.

Looks like the Grid Monkeys have been unleashed.

Bang the rocks together guys.

Fairies


Well yes. I am away with the fairies.

Google Search trends

Google is such a hotbed of data, it comes in , and people search for it. But all those searches that you type in are being noted.

Remember all you guys doing the search for "Janet Jackson"?

If you are in the UK, PIPEX will tell you that all us girls are searching for "David Hassellhoff"

( Hysterical laughter dies away )

Well Google has this database of all the searches, or is could be just the popular ones over time, it's Google Trends. The data seems to stop at the end of September 2006, so it's not really great for what we are after right now.

Lets looks at Second Life.

http://www.google.com/trends?q=Second+life&ctab=0&geo=all&date=all

It shows a steady rise through 2006, the high point here is the Duran Duran concert.

Naturally it is for all "Second Life" searches, not just our favorite platform. But the probability is that would be the main proportion of the searches containing "Second Life".

I'm not to sure about the location based results either.

Lets try another ( Couldn't help it, it the first thing I thought of. ) ( I'm not sure that sounds right! )

http://www.google.com/trends?q=cyber+sex

It's actually going down, the searches I mean, and most searches are from the Philippines, weird, and second is Brisbane Australia. Lets not go there people :-)

Something else, umm, Hurricanes

http://www.google.com/trends?q=hurricanes&ctab=0&geo=all&date=all

But this also seems to be a Grid Iron team name. Bum, something else.

My old ISP PIPEX

http://www.google.com/trends?q=pipex&ctab=0&geo=all&date=all

Most searches are from Welwyn Garden City, that just happens to be the PIPEX headquarters.

Now Hasselhoff ( OK, I'm just being silly now, I know ) It would also be nicer to put in the graphs, but this is all public access stuff.

http://www.google.com/trends?q=Hasselhoff++&ctab=0&geo=all&date=all

Looks like the Irish, and the Scandinavian countries love him.

Oh well, go have a play with the Google Trends people.

"Acting is not a big deal, it's basically Halloween." - The Hoff

More Syncronicity

I got a letter from home yesterday, I won't bore you with my rather odd family or my odder genetic background, or the religous insanity that runs though it all.

I've not been in contact for many years with any of my brothers and sisters, and the letter said my sister was rather ill. So with the help of goolge, dogpile and flickr I was able to find her email address, where she lived, and a recent photo.

Within 5 minutes of sending an email I had a reply. :-) So we are back in contact again.

The syncronicity is that her new flatmate had pretty much the same experience two nights before, her older sibling called, after not being heard of for over ten years.

I think I will have to send her parts to upgrade her PC so she can come in to Second Life as well.

And in other news I've been the subject of a Resident Shapshot on SLI I'm not sure why my skin looks grey, but I noticed it a few days ago.

Families are like fudge... mostly sweet with a few nuts. ~Author Unknown
( Tell me about it! - S Plasma )

Google plasma



Just a bit of fun, I'm not going to mention the local stir about the copythingy.

Although I have noticed the formatting of Blogger Beta leave much to be desired. I'm sure I have been consistant in my line spacings, but it comes out a but mangled.

I have got a new video card for the work PC, a Pentuim 4 3 gig. Sl runs fantastic, and it makes my Athlon 64 3000 at home look slow :-( At least I can log in for a bit at lunch time.

Some say Google is God. Others say Google is Satan. But if they think Google is too powerful, remember that with search engines unlike other companies, all it takes is a single click to go to another search engine - Sergey Brin

Synchronicity, Life, The Universe, and Everything

Recently Dani had a bit of a disaster when her RL house burnt down. I've always been paranoid about house fires, I turn my PC off while I'm out, and any long W/E away all the power points, except for the Fridge get turned off .

So far I've not had anything come close to going whoosh.

But, in the last two weeks I've had two things in the kitchen catch fire, no damage but just a bit of a fright.

Synchronicity is meaningful coincidences, and I do get quite a lot of this.

e.g I was in a Motorscooter accident about 5 years ago where I broke my Left wrist, 6 months before on the same scooter, on the same street, but at the other end of the street, my partner broke their wrist in the same sort of accident.

BTW Thats also the reason for my bad spelling, after the accident I no longer can see a visual image of words that I'm trying to spell.


All the works of man have their origin in creative fantasy. What right have we then to depreciate imagination?
C.G. Jung

15,000


It's over 15,000, is this a first ??












The world is populated in the main by people who should not exist.
George Bernard Shaw

What is the sound of one economist clapping?

I find it amazing that after all this time, Linden Labs didn't have anyone that could use Excel.

Zee Linden comes in, runs the numbers and tell Phillip that LL is loosing money, it looks like lots of money. So the traditional thing to do, is to raise the cost of services eg hosting, and cut wages. That is what they did.

Not very inventive, but just what a pencil pusher would think of.

It's always difficult to guess what is happening inside a service provider. I used to work in the ISP field, and the UK has some quite good forums to discuss the happening in the ADSL world.

On the forums relating to our ISP ( all the staff would read them ) were some of the greatest imagining I've read in a long time.
Our CEO was once called a "suited champagne filled fatcat", yeh..right. Torn jeans and t-shirt, only happy when he's programming his Ciscos.

How about " I can't get my Emails, do you think their Exchange servers are down?" Oh please...250,000 email accounts and you think we use Exchange!!

So unless you are on the inside, and know how it all works, customers making wild speculations can often be quite amusing.

So I promise not to make any more wild guesses on how it all works, and how much it all costs and where the accountants have to make all the cost cutting.

I just think they have to be more inventive, think lateral guys.


“Economics is extremely useful as a form of employment for economists.”

A token of affection


Well imagine my surprise when I teleported to my Sky Condo, it looked really strange and I thought I had picked the wrong one again.

So I teleported back to the ground. Tried again, hmmm waited for everything to rezz properly, and I realised that I was in the correct place. But things were looking a bit odd. I thought another sky box must have crashed into mine. So moving the camera out gave me a big surprise.

You can see, there was a great big boat embedded in my house.

As you might guess, it wasn't there when I left.

I called the landlord ( Cinda ) and asked her to have a look. She was rather impressed, as this was the biggest item she has ever removed. Qualifying that this is probably some token of affection from a secret admirer. We then debated the appeal of boats re flowers.

The privilege of feeling at home everywhere belongs only to kings, wolves and robbers. - Honore de Balzac

The Fastest heap of prims in the galaxy

Now this is for the real Sci Fi fanatic. I would love to have this on my lawn.

You came in that thing? You're braver than I thought. - Princess Leia

Sandbox Art




How does this look?

I saw part of this on New World Notes, but I sometimes check out the Sandboxes and was very impressed with this.

This is not just a build, this is Art.

In the words of Maxwell Smart Agent 86,
"Thats the second biggest vibrater I have ever seen."



Science and art belong to the whole world, and before them vanish the barriers of nationality. - Goethe

VLANs without trunking on the router.

I have a customer, a law office, that is moving to a new location. As part of their move their considering purchasing new desktops and servers. I've picked everything out and they're going to have a uote this coming week.

One of the things they are doing in addition to the move is to subnet space in their new office space. They're moving to a location that has more room than they need so they thought it a good idea to rent out the offices they're not using to non-competing attorneys. They want to offer them a desk with a fully function computer with internet access.

I need to allow the three offices that will be rented to have internet access through the same connection as my customer but they are not to be able to access the servers or other equipment on the LAN.

This is what I'm going to try and it's worked before. I'm going to get a manageable switch that has the capability to do VLANs. I'll setup each of the renters in their own vlan, and my customer who owns the network with their vlan. I'm going to try to to this without changing out the router to try and keep the project within budget. Than means that I'm going to gamble a little that I could repeat what I've done before. Put the router's connection to the lan in all three vlan groups and each of the routers and my customer in their own vlan and without access to the other.

If all goes well then all of them will share internet access but not be able to see each others computers or files and I didn't have to get a router with trunking capabilities.

Sim barriers and planes don't mix

I was out in the CLAWW again, just for a bit of a flight to Caledon. I was able to skirt a few of the crowed Sims, and protected land. Firstly I found Help Island, adn then got stuck at the barrier.
Cant move forward, back, or to the side. STUCK! :-( And in veiw of the people on the ground and that was much worse.

Time to parachute out so I attached the chute, jumped, twisted, took the plane back into inventory. So I thought I might make a disgret entrance back to HI. This model of the chute , emits particles, so it's hard not to be noticed, I wasn't expecting that, and it was harder to steer. So I just missed the boardwalk and went in to the water.

That looked very uncool, so I teleported home ASAP.

So at home, rerezzed the plane, and off we went again. Only this time I crossed on the exact corner of four sims, two totally full.

So there I am, the plane is just flying in a tight circle, when I say plane, I mean just the lower part of the fusalarge and the engine pods, the rest had disapeared, along with all my clothes and hair. Hmmm tricky ( that's why no pictures for this entry ).

So yes, what do I do now? Teleporting home usually drops me in among 4/5 people. I can't parachute out, as the plane is not really there, and I cant Stand, for the same reason.

So logging out and in was the only thing left, usually I end up on the nearest teleport point when this happens. So it was, no one around and a quick dip into inventory for some clothes.

Being naked approaches being revolutionary; going barefoot is mere populism. - John Updike

shelterinexile


shelterinexile
Originally uploaded by shockwaveplasma.

Well it's been good and bad news, so lets start with the good.

I've made it to the front page of New World Notes!!
A bit of syncronicity, as you can see from my last post is dropped by Wagners place the day before.

The bad, well I know Mera was upset, really upset, she said as much in her blog. But I didn't know why, there has been few issues at The Shelter, and Coal and Dolomere cover it in detail in their blogs.

I had felt a change in The Shelter, and the only clue I had was that my friends just didn't seem to be around very much, or as much as they used to. I thought it was all the new residents coming in, and everyone being so busy.

So now we have an alternate Shelter in Exile, so thanks to those who put in all the hard work, and a big thanks to Coal for the land.
If I ever get a shoulder rub animation, you can all have a 20min one each from me.

Synchronicity reveals the meaningful connections between the subjective and objective world.
Carl G. Jung (1875 – 1961)


snowcrash


snowcrash
Originally uploaded by shockwaveplasma.

I guess most people in SL would have heard of the novel Snow Crash by Neal Stephenson. From what I have read from people who have met him, hes fairly indifferent to SL, as he has moved on to other things.

Remember this book was published in 1992.

Well this is on top of Wagner James Aus ( Hamlet Linden ) office at Waterhead., and it's a sort of memorial to the book. I think I came here as I really did want to see the view from his window.

BTW, if you do land on his roof, dont use the teleporter. It's a one way trip.


"Ninety-nine percent of everything that goes on in most Christian churches has nothing whatsoever to do with the actual religion. Intelligent people all notice this sooner or later, and they conclude that the entire one hundred percent is bullshit, which is why atheism is connected with being intelligent in people's minds."
[Juanita talking to Hiro] Snow Crash

Being noticed

WOW, Danielle and Erbo have put me on their Blog Role! Yay! and a comment! Thanks guys and girls.

Naturally just now is when my ISP decides to have a hiccup with the pictures down the bottom of the page.

I'll forgo the comments of what happens were a really good ISP gets taken over by a bad ISP, and then can't figure how it works.

You affect the world by what you browse.
Tim Berners-Lee ( TBL to his friends )


( Note to self:- Chek their is no speelling or gramer mistakkes befor posting yu sily gurl )

AT AT


walker1
Originally uploaded by shockwaveplasma.

Pip Perth and I out in the CLAWW, spying the Empires AT AT Walker,we go in for an attack run, being the good rebel sympathisers we are. :-)

The AT AT is actually on the Shelter Balloon ride route, thats where I saw it first.

The rest of the photos are on Flickr, so yes I have been putting screen captures on there for the last two weeks.

Do you know what the worst part about flying at 50m a sec is ? Protected land. All of a sudden you stop, and your pasenger dissappears, and the both of you wonder were you are. Two nights ago I was flying, and then suddenly I wasn't! I was on the ground still in that "sitting at controls" pose.

OK log out, log back in again, back to normal. Good. So where is that wretched plane? Hmmm can't find it. So I'll have a bit of a fly around instead.

Bizarrely enough, again I crashed in a place I had been to before, some shop I had been to see about a lightsabre. Now they had a TIE fighter in stock (yay!). I could not sit at the controls for a picture unfortuantly (boo), and that's were I met Pip.



Waterhead Welcoming area. You will never find a more wretched hive of scum and villainy.

Obi-Wan Kenobi - Star Wars - A New Hope

Fun with Daleks


darlek1
Originally uploaded by shockwaveplasma.
I was able to get some free roaming combat daleks, you get a set of two and they hunt each other. It would be more fun to have them chase you or someone else as well I think.

"Oy, Dalek! It's me, the Doctor! What's the matter?Don't you recognize your mortal enemy?" Dr Who in REMEMBRANCE OF THE DALEKS

Death In Tibet


tibetflag
Originally uploaded by shockwaveplasma.

Real life Intrudes today:

I'm a very angry person today, after watching the film of the murder a Tibetan nun. I won't put the URL , all you need to do is type "tibet nun shot" in Google, and it's everywhere.

I was a member of Free Tibet about 10 years ago, and I wrote letters to Governments, asking for help for the Tibetans, and the recognition of the Dalai Lama. But I realized it was a dream more than reality. China will never leave Tibet, it sees no reason to, it's like asking when the US will leave Hawaii.

I've read the books and articles from the refugees, the stories of the torture and killing of the Tibetans by the Chinese, the shooting in the film happens every week, it's nothing new, so why am I so angry?

But then as the Chinese have said, they were attacked, and the Army was just defending itself, and this film shows that they are just blatant liars, and they always have been when it comes to Tibet.

Now they have been caught out, and the Chinese Govt are very keen to decide when black is white, and they will screem and shout that black is white and anyone who disagrees is an enemy of China.

You may have seen a few films about China, rememer that Richard Gere film where he has sex with his Chinese lawyer? I have been told that woman who have sex with a non-chinese will be a social outcast All films with Chinese woman havign sex with non-chinese, are either heavily cut or banned. Why? because it's institutionaly racist.

Naturally films with Chinese men and non-chinese woman are fine.

Time to start some activisim.

This is my simple religion. There is no need for temples; no need for complicated philosophy. Our own brain, our own heart is our temple; the philosophy is kindness. Dalai Lama


Meras Shop


Snapshotmerashop[
Originally uploaded by shockwaveplasma.

Last night I took off in the CLAWW, just flying at random, and turning left, right and then hitting full throttle.

I dropped by Meras shop to look at the art gallery, but it's gone. I wondered if she had noticed.

So I took off again, flying at random, then I hit a Sim boundary, and the CLAWW went to prim heaven, and I had some blurrey moments, and it all went grey.

When I refocused, I was on the waters edge, not on the bottom of the sea, as per normal, and I thought "Great, a new sim to explore" I'll pretend that it's Lost.

Then I noticed a big ballon just like at The Shelter, and a hut on the waters edge, ummm just like The Shelter. I don't know what the odds of this happening , but amazingly I crashed right in to The Shelters waterfront!

I've been trying to go to other places at random. So I went in and stayed for the evening.

BTW I'm wearing my Flight Suit in the photo :-)

"When once you have tasted flight, you will forever walk the earth with your eyes turned skyward, for there you have been, and there you will always long to return." -- Leonardo da Vinci


Legal Stuff

It looks like LL is finally getting serious about greifing, and has brought the FBI in. YAY!!
Even better they might restrict scripts to people they "trust"....hmmmm.

Well I turned up to my exam, and they decided it should be £184 rather than £82.
WHAT! NO WAY!
They were a bit surprised as well, and couldn't figure out why the price rise, so they will see if they can get a discount, and let me know.

I told Akela about Cheri's http://www.slpixelpulse.com/ and he put it on SlInsider, and gave me a credit :-)
I was tempted to post the it's not me on the cover, and I am not on any of the pages, or the centre fold.

Money often costs too much.
Ralph Waldo Emerson

Goo

As Dolomere would say:- YAGA :-Yet Another Grid Attack.
I'll be happy when the FBI finally catch someone, take them to Court, and they
are either fined or jailed.
But then LL can always take civil action as well.

I was so planning on getting out the CLAWW for a flight, and having a bit of combat flying.



If it weren't for my lawyer, I'd still be in prison. It went a lot faster with two people digging.
Joe Martin, Mister Boffo

Green Card Time

Well it's time for the DV-2008 http://www.dvlottery.state.gov/ , where those who want a USA Green Card, can go and try their luck.
I've been entering for the last 6 years, but I have calculated the odds are over 1000 to 1 of winning a Green Card.

They get about 10 Million entries, over half are invalid for some reason or another. But they also put aside a certain number for various regions. I'm in the Pacific region, so I think my chances are just a bit higher than Europeans.

The new USA passport looks really nice, although that RFID chip is just asking for trouble IMHO.
http://travel.state.gov/passport/eppt/epptnew_2807.html

I've not spent much time inworld the last few days, I have an exam next thursday.



“Any American who is prepared to run for president should automatically, by definition, be disqualified from ever doing so.”
Gore Vidal

First Post

So here I am, joining the online blogging brigade. Why now, because it's Aimee Webers fault!! Here i was just fooling around with the DIY Southpark at http://www.sp-studio.de/ and then put it up on Flickr, and then AW has to do it!

But so what if hers look better, oh well.

Well this will mostly be about 2nd Life, I have sort of been inspired by Torleys pics on Flickr to do more while I'm in world.

I've seen a nice plane by Cubey Terra I think I'll get, it's the CLAWW, why this one? Because it's the only one I didn't crash within seconds of take off, and look, he has a web site http://www.cubeyterra.com/ cool.

I'm not a great flyer, I must have left 7-8 UFOs in the water around Help Island while I was there. But I took this out for a fly, and it was great.

When I took out the Ornithopter, well, lets say the people in the Sandbox next to the airport dont even lookup (down?) when you go straight in to the ground. It's not the plane, it's my flying.

So I will be playing around with the design of the site for some time, the random pics down the bottom, don't really work like I had thought. But then when I started on the Web HTML was done in Notepad or vi.


Do not spin this aircraft. If the aircraft does enter a spin it will return to earth without further attention on the part of the aeronaut.
— first handbook issued with the Curtis-Wright flyer.

Cable Run?

Did a survey for a long underground cable run today. This is usually not my space but I can do this. A customer has just purchased a building next door to their main business office. They already have underground conduit installed and they are ready to sun some cables. The run appears to be under 300 feet so CAT 5 for computer data will work out ok for them although fiber isn't much more expensive.
Another run that will be installed for this customer is for the voice system. Probably a 25 pair run for all thier extension (all 4 - wow) using the same under ground data pipe.

What an easy survey. If they could all be that easy it would be great. I'm going back though since I forgot to inquire about their wireless access point needs. From what I saw of their new office space, the whole building will be covered with a single unit. They have a large outdoor area that may need to be covered as well. I'll be going back to find out. I enjoy fuguring out wiresll computer access points for outdoor pplications but alway get boggled down with anntenas. I'm going to try and streamline the process this time.Going right for overcoverage with too much emphasis on the cost. The goal is to cover without customer complaints about signal strengh so they have to pay more - period.

Changing a PC Power Supply

This is a boring post as it concerns a part of the computer that hasn't received media attention or reached the glamorous recognition some of the other PC components have - it's the power supply.

After all of these years in the field I still do what would be considered boring or beneath stature jobs. I don't care, the pay is the same. Another reason that a task such as this is that it's simple. Changing a desktop computers power supply takes a low amount of mental energy that it's almost relaxing. It's mostly a physical labor thing with just a few minor technical points to remember. If they all go as smooth as the this one then bring them on I say.

This was an old PC and it was using an AT style power supply, not even an ATX. One of the basic differences between the AT and ATX is the motherboard connectors. The old on came out without a hitch and the new one when in with even less trouble. The power button lined up right away and the whole thing was wrapped up in 20 minutes. All jobs should go this way.

XP Media Center Edition Can't Join Domain

Surprise, Surprise! (at least for me it was)

Media Center Edition of XP can't join a domain. This was a big surprise for me today. I though there were two flavors of XP and they were home and pro. Well there;s another version that floating around. I still don't know what makes this one special except for the name and the reason it would be opurchased instead of pro or home. I never had to install this version or even run the last setup steps on a new desktop. Today I had a customer that had just bought a new Dell system and needed the cnew desktop joined to the domain and the user's "stuff" moved over from their old system to the new. The old system is a story too. It turns out that they thought the computer just wasn't working anymore and that's how the computer problem had been expressed to my service department.

I go to the customer's office to check o nthe computer to see if there was enough life in it to get the data I needed off. The computer booted up just fine but when the user tried to log in, the hourglass just stayed on the screen literally forever. The system was looking for a Novell server to authenticate the user against. The Novell server had been removed and the user had not rebooted since then so they didn't come across this problem earlier. I dumped the novell client and the computer was logging in just fine. They were surprised to hear this but the user wasn't giving up the new desktop so easy and still wanted the new one.

So there I went. I un-boxed and hooked it up to the network a bright new keyboard and mouse and powered it up. I started clicking through the setup screens and rebooted. I started to then clean up programs using add/remove through the control panel removing things I now were just useless on this desktop computer for this customer. The time came to join the domain. Surprise. The join domain option in computer properties was greyed out. The system was coming up as XP pro. I checked the numbers and sure enough it was coming up as XP. But it wasn't. No where on the system itself did it say XP pro.



If it doesn't say XP PRO then it ain't pro . . .


It said media Center Edition. This was a big clue of course staring me right in the face. A little more research revealed that this version of XP, like the home edition, can't be joined into a domain. I hit some forums and there seemed to be some rumor that the only way it can be done is during installation. The customer didn't get the CD either with this new PC so they are going to order a new CD and use the old computer until then.

Adtran Netvanta 3200

The Netvanta router from Adtran are accessable remotely using either a telnet session and through a web browser. They can be accessed quite easily on a local area network but for access from the internet, they need to have enabled acces from the wide area network optioned enabled.

In an earlier post I had a customer who had a point-to-point T1 connection between two offices. One of the offices in in NYC and the other is in the Bronx (unfortunately I had to go to the Bronx twice for this customer). They were doing VoIP between their two ofices with a couple of NEC Aspire phone systems. The problem was getting the quality of voice up to a nice level even though we had QoS enabled and configured correctly on both routers.

We checked their local area network for problems and the circuit itself - driving verizon people crazy (don't feel bad for them). I even tried different flavors of quality of service configurations and also enabled diffserv and packet tagging on the phone systems. Also monitored bandwidth usage. Nothing helped. No metter what we did, the voice was horrible whenever they started a download. Adtran couldn't helped with this problem. I like and admire Adtran's tech support as they are ver very good and often helped me get out of trouble. But this time they overlooked this solution.

Here is the solution. If you know of anyone, or it's you yourself reading this, with a couple of Netvanta 3200 routers trying to do quality of service and it just is not working our right then check that wieghted fair queuing (WFQ) is enabled on the router and not FIFO.

Once I enabled this option the quality was great.

Data wall jacks not working?

I went to a customer's office today on a call about a wireless problem. Once I got there of course other issues they were having came were remembered. One such problem was regarding two wall network wall jack that were "not working". I figured this would be an easy problem to fix, I started it before the more mysterious and dangerous wireless access point problem.
I checked both of the wall jacks with my laptop and they weren't working like they said. Not even a link light - forget about not getting an IP address. I toned them out to see if they even ran to their data room and they both did. But, of course, there was not patch cord going from the patch panel were the wires terminated to the data switch. I plugged two cables in and tested again. Both ports now linked u pthe the LAN fine. The customer paid for this. I guess to me and other in the support world this was a no brainer. I really think that if the customer had applied some simple troubleshooting skills and basic knowledge they could have avoided the bill. Oh and by the way, they wanted to start arguing that my company did the cabling and therefore they should not get billed. Go figure.
Now about the wireless problem. This has a few more twists in the plot than the wall jack problem did.

Adtran Netvanta 3200

My company has a customer who has a point-to-point leased line ( a T1) between their two offices. In each office we have installed an NEC Aspire phone system. These systems aer capable of doing VoIP for station to station transfer betwee nthe two locations. This solution has been done many times before successfuly. The router that terminate the T1 at each end are the Adtran Netvata 3200 series routers.


NetVanta 3200


Modular Access Router - Single Slot/Single Ethernet
The NetVanta 3200 is an access router designed for cost-effective Internet access, corporate Frame Relay, point-to-point connectivity, and Virtual Private Networking (VPN) for applications requiring bandwidth from 56k to dual-T1s. Residing in a standalone desktop chassis with a plastics enclosure, the NetVanta 3200 is a single platform that offers one interface slot and one 10/100Base-T Ethernet LAN port. The modular NetVanta 3200 will house a variety of Network Interface Modules (NIMs) and includes a Stateful Inspection Firewall, QoS for delay sensitive traffic like VoIP, NAT and DHCP, and all managed with a familiar Command Line Interface (CLI).


The command line of the router is familiar. It has the look and feel of cisco routers. This makes using the CLI easy and comfortable for anyone familiar with configuring cisco router.


Adtran in my opinion makes some of the best most reliable equipment. Their support is top notch and never let you down. I've only had a problem with their tech support when they have been backed up. Besides this ocurring once or twice their technical support staff is top notch.

The NEC communicate with each other over the point-to-point T1 just fine. but when a download is initiated from iether side to the other, the voice is terrible. After upgrading the operating systems on both adtrans, which I have to say was a breeze, I had more quality of service tools at my disposal. After trying various methods to smooth the voice quality there was no fixing it. The reason I found that the quality of the VoIP is so bad is providers line is bad. In particular, it seems it's the tranmitt pairs at one of the locations. This will be a long drawn out fight with the service provider for sure. They have tried to blame the custoemr premiss equipment but I'm steadfastly standing behind the Netvanta router.

U.S. Mac users receive best support

Source: MACNN
May 8, 2006

A new report suggests that U.S. Mac users receive the best tech support compared to other free technical support systems. The Consumer Reports National Research Center found that only 55 percent of consumers who contacted technical support had their problem solved, drawing from surveys of 20,000 users with computer problems in the US, according to Macworld UK. Users said that most manufacturers provided "dismal" free tech support, with the exception of Apple's support for desktops/laptops and IBM's support for laptops. "Apple's support for desktops and laptops and IBM (Lenovo) for laptops. Apple solved 76 percent of survey respondents' problems, and IBM (Lenovo) solved 64 percent." Compaq was rated the worst free tech support, solving only 38 percent of desktop problems for respondents, while 15 percent of users with problems didn't even bother to contact the manufacturer's support due to negative previous experiences.

Invensys Introduces World’s First 'Enterprise Control System'

Source:Yahoo News

Mon Apr 17, 8:00 AM ET

(PRWEB) - Foxboro, MA (PRWEB) April 17, 2006 -- Invensys today introduced the world’s first industrial system that goes beyond the plant or other industrial operations to provide a true enterprise view. The new InFusionTM enterprise control system combines industry-leading capabilities from across Invensys with advanced enterprise information and integration technologies from both Microsoft and SAP to dramatically reduce integration costs. With InFusion technology, most existing plant floor and enterprise systems can now be cost-effectively integrated into a common system. In conjunction with a suite of new performance services, Invensys’ InFusion system will help industrial enterprises more effectively align plant operations and maintenance departments with the business to optimize overall asset performance management.

VERCLSID.EXE

A recent Microsoft security update is causing problems on desktops. The desktops seem to freeze or hang when users click on My Recent Documents or My Computer or just using Explorer. The olny way to stop the process is to end the task using task mananger. There may even be multiple instances of the program running.

The verclsid.exe is a binary that was added to the system32 folder. It's supposed to check the DCOM class id of the executed or initiated program. This has a known problem. A work around that I used this morning was to rename the file:

  • Start a command prompt
  • go to the system32 directory
  • type in ren verclsid.exe verclsid.old
The new binary doesn't prevent remote access to the system so using online remote desktop control software over the web to connect to the affected system should in most cases still be a viable method to get access to the system to fix.

The microsoft security update is MS06-015 (908531). More information on the verclsid.exe can be found at Microsoft's site.

Paradyne 3160 Channelized Voice and Data

Paradyne 3160 setup in a channelized voice and data point-to-point configuration.

My company had had a telephone installation job. This was pretty much an ordinary install. The company that was having the phone system installed was a long time customer who had purchased two systems from us. The one system that was installed in their old building was done so about 10 to 15 years ago. The other, in their new warehouse and office location, was installed about 3 to 4 years. It was time to replace the old system.
The phone techs that were on site were pretty good so when I got the call at about 9:30PM and saw who it was, I was surprised and curious as to what the problem could possible be. It turns out that on one side of the point-to-point T1 connection an Adtran Total Access 750, that I installed years ago, was removed and replaced with a Paradyne for the new phone system. They were able to configure the two systems through the paradyne to the point were the voice was working but the data, IP, wasn't working. The other side of the T1 was an Adtran TSU 600 unit which was unchanged - 8 channels voice and the rest of the DS0s were for data.
The voice was working but the data was not. He was on server on the new unchanged side and could not reach any computer desktop in the main and the same held true for the main side to the remote. I tried assisting them remotely by trying to talk them through the screens. I didn't have desktop remote access over the internet to configure the unit. Access to the paradyne was through the front panel only at this time I had to take a trip in.
What techs almost had it right, and they tried.

The Paradyne, when configured for voice and data needs:
  • The port that connects to router must be set to V.35 (at least this is the most common configuration)
  • If port 1 then that port must be assigned to NET in the configuration. The same applies if port 2
  • Once the above is complete then additional options are available to configure the data channels.
  • In the channel configuration under voice, the channels that are for data must be set to RBS - this one is the gocha.

EliteSolutions

Elite Solutions

Now EliteSolutions has got the right idea. Why drive to or spend a ton of hours over the phone trying to support computers remotely. Just get some software that lets the support personal remotely access the system and get to work and get done faster. This will free him or her up to get more done. This is the basic reason why elitesolutions uses online remote support software.

This is snippet form thier support homepage. It says it all. Good work Elite Solutions.

"With rising costs for service calls many IT Companies will simply increase service rates and or find other billing techniques to offset those rising costs. At EliteSolution we believe that all other business alternatives need to be explored before raising services rates. At EliteSolution we recognize that the simple raising of rates is not always the best solution as often this does not ensure that a business will remain competitive."

VPN Client Administration - Remember the early days of VPNs

This article is from March of 2001.

In previous columns, we have discussed protocol issues and alternatives facing ISPs that offer remote access VPN services, ranging from
authentication to addressing. Here, in the final installment of this series we open Pandora's box—VPN client administration.
Lisa Phiffer VP Core Competence, Inc. [March 15, 2001]

For the most part, Virtual Private Networking is a new technology, playing the same old remote access security tunes. Distributing desktop software, configuring it properly, and keeping it up-to-date is a time-consuming, never-ending administrative chore.
ISPs that offer residential Internet access are all too familiar with support costs associated with dial-up networking, mail client, and web browser configuration. Fortunately, these applications are factory-installed on most Windows PCs and include auto-update features. But remember the old days, when subscribers had to install and configure third-party
TCP stacks?
In some respects,
IPsec clients stand today where TCP stacks stood a decade ago. In 1998, at InternetWorld IW Labs, we started testing early IPsec gateways with paired client software. These clients operated as "shims" or virtual adapters, inserting themselves into the middle of packet processing. Client install/remove problems were commonplace. Configurations exposed esoteric security parameters like crypto algorithms and secret keys to end-users. Centralized client policy and software administration tools were virtually non-existent. Multi-vendor interoperability was—well, drafty, at best. The bottom line—VPN client administration took a bigger-than-anticipated bite out of ISPs return on investment.
With maturity comes reliability Fortunately, IPsec clients have matured considerably during the past three years. Base standards stabilized. Testing against reference implementations improved interoperability. Software kinks were resolved with time and field experience. However, testing complex network software with every permutation of Windows OS, service pack, and modem/adapter is a challenge.
Today, many remote access vendors—including
Check Point, Nortel Networks, and Indus River—continue to refine their own IPsec clients. But an increasing number of equipment manufacturers—including Cisco, Lucent, 3Com, and Nokia—outsource IPsec client development by OEMing SafeNet's Soft-PK.
Today's IPsec clients are not bullet proof, but compatibility issues are declining. A study conducted by Lucent NetCare cited overall VPN product immaturity as a significant barrier to deployment, but found that technology issues—top challenges just three years ago—had been surpassed by organizational issues in 1999. This study predicted that process and procedural issues would continue to grow in importance as VPNs become more integrated into network infrastructures.
Simplified installation More robust software is one more nibble into the technical support cost cookie. Streamlined client installation and update is another. Today's IPsec clients require fewer parameters. Through smart defaults, canned policies, and automated policy updating, client installation has become easier and less error-prone. Let's consider a few examples.
eTunnels mails each user a one-time URL to download VPN-On-Demand client software. Each time this IPsec client connects to the company VPN, it must first use SSL to obtain security parameters from the eTunnels Network Server (eNS). Centralized control, simple authentication, and topology assumptions greatly simplify client configuration, but at the cost of flexibility.
IPsec gateways like the Cisco VPN 3060 and
Symantec PowerVPN Server automatically pushes administrator-defined policies to IPsec clients each time they connect. Users simply enter gateway hostname and credentials. However, stronger authentication presents the same old challenge: IKE shared secrets are easily mistyped and X.509 certificates are not intuitive to the average end-user.
Check Point's VPN-1 offers automatic version checking to assist in managing client software distribution. Should software updates be automatically pushed for consistency, or applied ad hoc? If ad hoc, how do you ensure client-gateway version synchronization? These procedural decisions still fall to the VPN administrator.
Scalable policy administration In any large deployment, efficient management and monitoring tools are essential. Policy-based management systems simplify administration of site-to-site VPNs. But sheer volume and frequency of change make remote access administration a tougher nut to crack.
ISPs that offer managed remote access services set the bar even higher. These providers require highly scalable client management systems that support multi-level security policies, delegated user administration, and version control for hundreds of customers, each having perhaps thousands of users.
Vendors like Check Point and
WatchGuard market tools specifically designed for managed VPN providers. For example, Check Point's Provider-1 multi-domain policy server can compartmentalize users, rules, and logs for each customer, with automated policy backup and restore. WatchGuard's NOC Control Center provides real-time and historical monitoring, logging, notification, and reporting for managed customer VPNs from one central console.
Over the next few years, we expect to see considerable evolution in large enterprise and carrier-class policy management systems. This past week, Check Point introduced its Next Generation management interface, equipped with a visual policy editor, automated client updates, and predefined policies. Cisco also announced its VPN Security Management (VMS) system—an integrated manager that spans 3000 series concentrators, 7000 series routers, and PIX firewalls.

Read more ...

Blog Archive