Wednesday, 22 May 2013

IT Management: Red Ocean vs Blue Ocean Strategies

Red oceans represent all the industries in existence today – the known market space. In the red oceans, industry boundaries are defined and accepted, and the competitive rules of the game are known. Here companies try to outperform their rivals to grab a greater share of product or service demand. As the market space gets crowded, prospects for profits and growth are reduced. Products become commodities or niche, and cutthroat competition turns the ocean bloody; hence, the term red oceans.
Blue oceans, in contrast, denote all the industries not in existence today – the unknown market space, untainted by competition. In blue oceans, demand is created rather than fought over. There is ample opportunity for growth that is both profitable and rapid. In blue oceans, competition is irrelevant because the rules of the game are waiting to be set. Blue ocean is an analogy to describe the wider, deeper potential of market space that is not yet explored.
The cornerstone of Blue Ocean Strategy is 'Value Innovation'. A blue ocean is created when a company achieves value innovation that creates value simultaneously for both the buyer and the company. The innovation (in product, service, or delivery) must raise and create value for the market, while simultaneously reducing or eliminating features or services that are less valued by the current or future market.
References:

1.  Blue Ocean Strategy

2.  Red Ocean vs Blue Ocean Strategies

IT Technology: Awesome Data Centers

This is a nifty infographic, courtesy of WhoIsHostingThis?, that offers a little data center trivia: the biggest data centers in the world, statistics on the energy they consume, and facts about the data centers used by some of the Internet’s most popular services like Google and Twitter.




Reference:

Infographic: Awesome data centers
http://www.techrepublic.com/blog/networking/infographic-awesome-data-centers/6602?tag=nl.e019&s_cid=e019&ttag=e019

Tuesday, 21 May 2013

Apple: iDevice (iPad) in Education

It's all about verbs, that is, the things teachers can do with an iPad. Those actions include showing your screen on a projector, managing the classroom, assessing student work, interacting with students, accessing your files, making instructional media, and expanding professional learning. The infographic below focuses mostly on free apps that you'll be able to put to use immediately. Those apps turn your iPad in a timer, interactive whiteboard, voice recorder, document camera, calendar, magazine, notebook, and much more.
So take a peek to see how iPad can help you capture learning artifacts, plan lessons, poll students, visualize concepts, share demonstrations, and much more.




Reference:

1.  iPad as the Teacher's Pet
http://learninginhand.com/blog/2013/4/7/ipad-as-the-teachers-pet-infographic

Sunday, 19 May 2013

BlueCoat: Video Caching with CacheFlow

The BlueCoat CacheFlow appliance is a high-performance web caching solution designed to help service providers save significantly on bandwidth and accelerate the delivery of rich Web 2.0 content, including video. CacheFlow easily scales to support more users and greater traffic volumes over time, plus provides built-in tools for web traffic reporting and filtering to protect users.
With CacheFlow, you don’t have to keep buying expensive bandwidth to meet performance goals. Using CacheFlow, you can dramatically cut infrastructure costs and deliver a more responsive web experience.
And with the patent-pending CachePulse technology, customers can be confident the CacheFlow solution will sustain high bandwidth savings and user experience gains over the long haul. CachePulse tracks the ever-changing web, so as new sites emerge or popular sites change how they deliver content, new caching rules and instruction updates are automatically delivered from the CachePulse cloud to the CacheFlow appliance.
The two major features of CacheFlow are:
1. Bandwidth Savings = Cost Savings 
CacheFlow helps service providers like you save significantly on expensive bandwidth and backhaul traffic. Designed to easily scale by adding more appliances or building out content-specific cache farms, you can use CacheFlow to accelerate the delivery of rich Web 2.0 content, including video, while easily accommodating more users and greater traffic volumes. Save 40-50% on general web traffic and achieve up to 90% savings with dedicated content caches for significant long-term savings and a short Return on Investment (ROI).
2.  Your Customers' Experience = Increase Web Performance
CacheFlow improves your customers' online experience by boosting web performance by 10x. Improve overall customer satisfaction, reduce support calls and related costs, and gain a competitive edge with faster downloads speeds. Many service providers are finding user experience to be a key competitive differentiator, especially when it comes to delivering rich content like video, plus it provides opportunity to deliver premium, high-speed Internet services.

Tuesday, 14 May 2013

IT Technology: Firewall (Hardware Based)

What is a firewall?

Generally, think of firewall as the security standing outside your gate. They inspect everyone that comes in and out, stop unauthorized people from entering a building, maintain a record of all entry and exits and  so on.

A firewall is not so different. It keeps a check of all incoming and outgoing connections of your computer network and based on the rules configured on the firewall, it will allow/deny access to certain computers, or technically speaking IP addresses. 
A few other things it does is it maintains a log of all incoming and outgoing connections along with the date and time stamp, shows what connections were blocked and why, and of course the best part, prevents unknown people from getting into your network from the internet.
But make no mistake. A firewall is the least you can do to secure your network – that’s right. A firewall is the most basic thing to have in place when it comes to securing your computer or an entire network.
There are two types of firewall:
1.  Hardware based firewall
These are physical machines with network ports. Commonly installed at the entry point of your network.  These are used to protect an entire network from internet threats and are generally used  at offices.
2.  Software based firewall
These are commonly associated  with antivirus software. You can download it on your Windows computer and install it yourself.  These are used to protect a single computer from internet threats. Generally used for personal use. Most popular are Norton, McAfee, Kaspersky and Comodo Firewall.

How does a firewall operate?
Before I go on telling you how does a firewall work let me talk about some general concepts of computer networking, one in particular – “IP Address”
Think of IP address similar to your physical mailing address. There is one similarity in particular – its unique. So if you have to send in a letter, you’d go to the nearest post-office, on the letter you’d write your address (source), the recipient’s address (destination) and that’s it.
A computer network operates in a similar way -  every computer or device is assigned a unique IP address using which, communication takes place. This is where a firewall comes in – the administrator would want to control, what computer(s)  should or should not communicate.
So we place a firewall in between two networks to control/monitor/log all IP communication. Most commonly, this is placed between an internal network -  A local area network or LAN
and an external network  – usually WAN or wide area network or most popularly known as the Internet.
So why would we place a firewall between your local network and the internet? That’s right, we would like to shield our internal network from external threats. By placing a firewall right in the middle, we can define certain “rules” that will tell the firewall what communication should be allowed or disallowed. After we have defined certain rules on the firewall – the firewall would check the headers of every packet (a packet is a unit of data in IP networks) and would either allow it to go through or block it. This is basically how the firewall operates.



Hardware based firewall

With so many firewalls available in the market, network administrator tends to get confused. In general, your decision should be made on the following:

1.  Performance requirements

2.  Feature requirements
3.  Cost – one time and recurring costs
4.  Support
5.  Availability of IT Consulting

A golden rule to remember – “Your firewall is only as good as your configuration”
A firewall by itself doesn't do much. It’s the firewall setup and its configuration that decides the fate of your network. So if you spend $2000 on a high-performance firewall, but don’t have the configuration done right, you’re in for a lot of trouble.
A firewall should be configured under the direct supervision of an information security expert. Once you bring in a firewall in your network, you have to make sure the firewall is configured in accordance to your company’s  IT security policy to get the most out of your expense.
Before you make a decision, be sure to have a good IT consultancy firm with security expertise or an independent IT security consultant to help you plan your network security.

References:
2.  Enterprise Network Firewall Magic Quadrant for 2013
http://www.checkpoint.com/products/promo/gartner-firewall/

Monday, 13 May 2013

Microsoft: Active Directory (AD) Password Expiry Email Notification and Summary Report

This Powershell script allows you to notify your users that their AD password will expire soon or has expired. Furthermore, as a system administrator, you are going to receive a list of users whose AD password is going to expire soon or has expired.


# Start of script
# Purpose:
# Powershell script to find out a list of users
# whose password is expiring within x number of days (as specified in $days_before_expiry).
# Email notification will be sent to them reminding them that they need to change their password.

#####################
# Variables to change
#####################
# Days to Password Expiry
$days_before_expiry = 14
# SMTP Server to be used
$smtp = "192.168.1.2"
# "From" address of the email
$from = "email@abc.com"
# Administrator email
$admin = "email@abc.com"
# Web address of your OWA url - tested only with Exchange 2007 SP2
$OWAURL = "mail.abc.com"
# First name of administrator
$AdminName = "System Administrator"
# Define font and font size
# ` or \ is an escape character in powershell
$font = "<font size=`"3`" face=`"Calibri`">"

##########################################
# Should require no change below this line
# (Except message body)
##########################################
function Send-Mail{
param($smtpServer,$from,$to,$subject,$body)
$smtp = new-object system.net.mail.smtpClient($SmtpServer)
$mail = new-object System.Net.Mail.MailMessage
$mail.from = $from
$mail.to.add($to)
$mail.subject = $subject
$mail.body = $body
# Send email in HTML format
$mail.IsBodyHtml = $true
$smtp.send($mail)
}
# Newline character
#$newline = [char]13+[char]10
$newline = "<br>"
# Get today's day, date and time
$today = (Get-date)
# Loads the Quest.ActiveRoles.ADManagement snapin required for the script.
# (Will unload once powershell is exited)
# chose either one below
# Add-pssnapin "Quest.ActiveRoles.ADManagement"
# Get-PSSnapin "Quest.ActiveRoles.ADManagement"
add-pssnapin "Quest.ActiveRoles.ADManagement"
Set-QADPSSnapinSettings -DefaultSizeLimit 0

# Retrieves list of users whose account is enabled, has a passwordexpiry date and whose password expiry date within (is less than) today+$days_before_expiry
$users_to_be_notified = Get-QADUser  -SearchRoot "OU=USA,DC=abc,DC=local" -Enabled -passwordNeverExpires:$False | Where {($_.PasswordExpires -lt
$today.AddDays($days_before_expiry))}
# Send email to notify users
foreach ($user in $users_to_be_notified) {
# Calculate the remaining days
# If result is negative, then it means password has already expired.
# If result is positive, then it means password is expiring soon.
$days_remaining = ($user.PasswordExpires - $today).days
        # Set font for HTML message
        $body = $font
        # For users whose password already expired
        if ($days_remaining -le 0) {
                # Make the days remaining positive (because we are reporting it as expired)
                $days_remaining = [math]::abs($days_remaining)
                # Add it in a list (to be sent to admin)
                $expired_users += $user.name + " - <font color=blue>" + $user.LogonName + "</font>'s password has expired <font color=blue>" + $days_remaining + "</font> day(s) ago." + $newline
                # If there is an email attached to profile
                if ($user.Email -ne $null) {
                        # Email notification to user
                        $to = $user.Email
                        $subject = "Reminder - Password has expired " + $days_remaining + " day(s) ago."
                        # Message body is in HTML font
                        $body += "Dear " + $user.givenname + "," + $newline + $newline
                        $body += "This is a friendly reminder that your password for account'<font color=blue>" + $user.LogonName + "</font>' has already expired "+ $days_remaining + " day(s) ago." + $newline + $newline
                        $body += "Please contact email@abc.com ( EXT. 9999 ) to arrange for your password to be reset."
                        }
                else {
                        # Email notification to administrator
                        $to = $admin
                        $subject = "Reminder - " + $user.LogonName+ "'s Password has expired " + $days_remaining + " day(s) ago."
                        # Message body is in HTML font
                        $body += "Dear administrator," + $newline + $newline
                        $body += "<font color=blue>" + $user.LogonName+ "</font>'s password has expired <font color=blue>" + $days_remaining + " day(s) ago</font>."
                        $body += " However, the system has detected that there is no emailaddress attached to the profile."
                        $body += " Therefore, no email notifications has been sent to " + $user.Name + "."
                        $body += " Kindly reset the password and notify user of the password change."
                        $body += " In addition, please add a corresponding email address to the profile so emails can be sent directly for future notifications."
                        }
                # Put a timestamp on the email
                $body += $newline + $newline + $newline + $newline
                $body += "<h5>Message generated on: " + $today + ".</h5>"
                $body += "</font>"
                # Invokes the Send-Mail function to send notification email
# Comment out this line if you do not want to send email to users with already expired passwords.
                Send-Mail -smtpServer $smtp -from $from -to $to -subject $subject -body $body
        }
        # For users whose password is expiring
        # if ($days_remaining -gt 0) {
        else {
                # Add it in a list (to be sent to admin)
                $expiring_users += $user.name + " - <font color=blue>" +$user.LogonName + "</font> has <font color=blue>" + $days_remaining +"</font> day(s) remaing left to change his/her password." + $newline
                # If there is an email attached to profile
                if ($user.Email -ne $null) {
                        # Email notification to user
                        $to = $user.Email
                        $subject = "Reminder - Password is expiring in " + $days_remaining +" day(s)."
                        # Message body is in HTML font
                        $body += "Dear " + $user.givenname + "," + $newline + $newline + $newline
                        $body += "This is a friendly reminder that your AD account password '<font color=blue>" + $user.LogonName + "</font>' is due to expire in "+ $days_remaining + " day(s)." + $newline + $newline + $newline
                        $body += "Please refer to the links below for quick guides" + $newline + $newline
                        $body += "For Windows user:" + $newline
                        $body += "\\fileserver\Public\Change_Windows_Password.pdf" + $newline + $newline
                        $body += "For Mac user:" + $newline
                        $body += "smb://fileserver/Share/Change_Mac_Password.pdf" + $newline + $newline
                        $body += "Please remember to change your password before <fontcolor=blue>" + $user.PasswordExpires.date.tostring('dd/MMM/yyyy') +"</font>."
                        }
                else {
                        # Email notification to administrator
                        $to = $admin
                        $subject = "Reminder - " + $user.LogonName+ "'s Password is expiring in " + $days_remaining + " day(s)."
                        # Message body is in HTML font
                        $body += "Dear administrator," + $newline + $newline
                        $body += "<font color=blue>" + $user.LogonName+ "</font>'s passwordis expiring in <font color=blue>" + $days_remaining + " day(s)</font>."
                        $body += " However, the system has detected that there is no emailaddress attached to the profile."
                        $body += " Therefore, no email notifications has been sent to " +$user.Name + "."
                        $body += " Kindly remind him/her to change the password before <fontcolor=blue>" + $user.PasswordExpires.date.tostring('dd/MMM/yyyy') +"</font>."
                        $body += " In addition, please add a corresponding email address to the profile so emails can be sent directly for future notifications."
                        }
                # Put a timestamp on the email
                $body += $newline + $newline + $newline + $newline
                $body += "<h5>Message generated on: " + $today + ".</h5>"
                $body += "</font>"
                # Invokes the Send-Mail function to send notification email
                Send-Mail -smtpServer $smtp -from $from -to $to -subject $subject -body $body
        }
}
# If there are users with expired password or users whose password is
# expiring soon
if ($expired_users -ne $null -or $expiring_users -ne $null) {
                # Email notification to administrator
                $to = $admin
                $subject = "< Info > Password Expiry Report"
                # Message body is in HTML font        
                $body = $font
                $body += "Dear " + $AdminName + ","+ $newline + $newline
                $body += "The following users' passwords are expiring soon or have already expired." + $newline + $newline + $newline
                $body += "<b>Users with expired passwords:</b>" + $newline
                $body += $expired_users + $newline + $newline
                $body += "<b>Users with passwords expiring soon:</b>" + $newline
                $body += $expiring_users
                # Put a timestamp on the email
                $body += $newline + $newline + $newline + $newline
                $body += "<h5>Message generated on: " + $today + ".</h5>"
                $body += "</font>"
                # Invokes the Send-Mail function to send notification email
                Send-Mail -smtpServer $smtp -from $from -to $to -subject $subject -body $body
}
# End of script 

Friday, 10 May 2013

BlueCoat: Web 2.0 and Mobile Applications Control

Web traffic today is diverse. To effectively manage the content that users in your network can access, you can allow or block access to the content using web categories, web applications and web operations.

You can also control access to web content using a URL or domain name. In today’s web milieu, this is not an effective solution because the elements of a web site are served from multiple URLs or domains. Blocking specific URLs is effective only when you know that the content is always served from a specific domain or URL.

To allow reasonable access to Web content, you need to create policy that combines categories, applications and operation controls. This means that you can allow access to certain applications within a category while blocking the category itself, or restrict selected operations across all applications.

The pre-requisites for enabling web and mobile application control at BlueCoat device is as follows:
  •  Proxy Edition license (not a MACH5 license)
  • The Blue Coat WebFilter feature must be enabled. (Configuration > Content Filtering > General)
  • A current BCWF database must be downloaded to the ProxySG. (Configuration > Content Filtering > Blue Coat WebFilter)
  • The ProxySG must have one or more Web services, such as External HTTP and HTTPS, set to intercept. Bypassed Web traffic is not classified into applications.

For the applications you have blocked, you do not have to update your policy to continue blocking the new content sources; To block newly recognized applications, you will need to select the new applications and refresh your network policy.

When you block by operation, unlike blocking by application, you prevent users in your network from performing the specified operation for all applications that support that operation. They can however, access the application itself.


Note, however, that the Request URL operation object only pertains to operations for sites that BCWF recognizes as Web applications. So, blocking picture uploads would not prevent users in your network from using FTP to upload a JPEG file to an FTP server, or from using an HTTP POST to upload a picture on a Web site running bulletin board software.


The following application and operation control objects allow you to match against the URL in an HTTP or HTTPS request that the ProxySG appliance receives from clients in the network and create policy to allow or restrict access to the requested action or content:
1.  Request URL Application
The Request URL Application object gives you the ability to block popular Web applications such as Facebook, Linkedin, or Pandora. As new applications emerge or existing applications evolve, BCWF tracks the domains that these Web applications use to serve content, and provides periodic updates to include the new domains that are added. You can use the Request URL Application object to block an application and all the associated domains automatically.
2.  Request URL Operation
The Request URL Operation object restricts the actions a user can perform on a Web application. For instance, when you select the Upload Picture action for the Request URL Operation, you create a single rule that blocks the action of uploading pictures to any of the applications or services where the action can be performed such as Flickr, Picasa, or Smugmug.


Reference:
1.  How do I control Web 2.0 and Mobile applications in my network?
https://kb.bluecoat.com/index?page=content&id=KB4784&actp=RSS