Firewall: Why use it and how to use it?

In an increasingly interconnected world, network security is a primary concern for internet provider companies and their customers. An essential tool for protecting your IT infrastructure against cyber threats is the firewall. In this article, we’ll explore why using firewalls is critical and how to implement them effectively on your network.

Success Story: Modernization of the Wi-Fi Infrastructure at the Apucarana City Council

Client: Apucarana City CouncilCompany: Made4it Overview: The Apucarana City Council, a government institution responsible for legislating and making decisions on behalf of the local community, faced a significant challenge with its communications infrastructure. With the growing reliance on technology and connectivity, the need to provide a reliable Wi-Fi signal throughout the building has become essential for the efficient conduct of legislative and administrative activities. Challenge: Before partnering with Made4it, the Apucarana City Council faced a number of problems related to Wi-Fi connectivity. Coverage was uneven, with areas where the signal was weak or nonexistent, resulting in interruptions during legislative sessions, difficulties in live-streaming meetings, and slow access to essential digital documents. The challenge was to modernize the Wi-Fi infrastructure to ensure full coverage and high-quality connectivity throughout the building. Solution: Made4it was chosen to tackle this challenge and designed a comprehensive solution to modernize the Apucarana City Council’s Wi-Fi infrastructure. The project was divided into several phases: Results: The Made4it project has yielded remarkable results for the Apucarana City Council: The Made4it project at the Apucarana City Council demonstrated how a well-designed Wi-Fi infrastructure can positively impact the operations of a government agency, increasing efficiency, improving communication, and providing a more modern and connected environment for everyone involved. If you’re looking for a solution to a Wi-Fi issue or any other problem with your network infrastructure or server, please contact us to learn more.

Why Have Your Own RADIUS Server?

Benefits for ISPs and Corporate Customers These days, connectivity is the backbone of nearly all business operations and personal communications. Internet service providers (ISPs) and companies face the need to manage network access efficiently and securely. A key tool for achieving this goal is a dedicated RADIUS (Remote Authentication Dial-In User Service) server.In this article, we’ll explore the reasons why Internet service providers and corporate customers should consider implementing a dedicated RADIUS server. What is a RADIUS server? Before we dive into the benefits of having your own RADIUS server, it’s important to understand exactly what RADIUS is.RADIUS is a widely used authentication and authorization protocol that enables centralized management of network access. It acts as an intermediary between network devices (such as routers, switches, and access points) and authentication systems (such as LDAP servers or user databases). Benefits of Having Your Own RADIUS Server: Conclusion: Having your own RADIUS server offers a number of significant benefits for internet service providers and corporate customers. It enhances security, simplifies management, enables granular access policies, and can lead to a better user experience. Furthermore, with the growing emphasis on cybersecurity and regulatory compliance, implementing a RADIUS server is a strategic choice. At Made4it, we understand the importance of effective and secure networking solutions. If you’d like to learn more about how a RADIUS server can benefit your organization or need assistance with implementation, please don’t hesitate to contact us. We’re here to help boost your network connectivity and security. How Made4it Can HelpToday, we offer two solutions for those who want their own RADIUS server: Made4Radius, our authentication and accounting platform, and FreeRadius, for those who prefer to deploy an open-source solution.

How do you request an ASN from your provider?

In this guide, we explore all the steps required to apply for an ASN from your Internet service provider. Keep in mind the importance of this unique number in improving connectivity and controlling your network. Be sure to research local requirements, prepare the necessary documentation, fill out the application form correctly, and wait for approval. Once you have obtained the ASN, implement it properly in your network to take full advantage of the benefits it offers.

How to Configure Archer-C20 Routers Using TR069

Today I’m going to show you how to set up your Archer-C20 on Made4Graph’s TR-069.I recommend doing this in a lab environment with a public IP address, since you’ll need to validate the configuration. To do this, we’ll change some settings on your CPE via TR-069, and we don’t want a customer to be left without internet access.Before starting the configuration, it is essential that there be no “NAT” of any kind on the network between the CPE and the TR-069 server; if there is, it will compromise the functionality of TR-069, according to the protocol documentation.Now that I’ve covered the prerequisites, let’s configure the CPE. When you open CPE, go to the Advanced tab, then System Tools, and finally Settings.When you reach the screen shown below, make the following settings: CWMP Settings:→ The CWMP button must be enabled→ The information button should be active→ Data interval = 300→ ACS URL = http://ip_do_server_de_tr:7547→ ACS username = admin→ ACS password = admin→ Interface used by TR-069 = Any WAN→ CPE ID = SN→ “View SOAP Message” button = disabled→ The “Connection Request Authentication” checkbox must be checkedIn the fields below the connection request box, you will be asked for a username and password; you should enter:→ User = admin→ Password = admin→ Path = /tr069→ Port = 7547 The “Simple UDP Traversal over NATs” option can be enabled, but it does not need to be configured; the settings can be left at their defaults.After that, click Save. Shortly thereafter, the CPE should appear in Made4Graph, where it will be approved by our team Some information has been redacted to keep CPE data confidential.If you still have questions, send us a message, and we’ll help you with your CPE.

Internet service providers face a new wave of DDoS attacks

A lack of care in maintaining equipment, services, and IP address block configurations has put ISPs at imminent risk of distributed denial-of-service attacks Internet service providers (ISPs) are at imminent risk of large-scale distributed denial-of-service (DDoS) attacks, largely due to a lack of care in managing equipment, services, and the configuration of IP address blocks. Last year, several Brazilian ISPs faced difficult times as they dealt with DDoS attacks on their infrastructure, a situation that led to numerous posts on social media, as well as coverage in newspapers and on TV shows. Recently, in late February, a new wave of attacks once again hit several ISPs, with numerous reports involving providers in Rio de Janeiro, some of whom have even spoken out publicly, informing customers that they are facing serious problems in providing services due to these attacks. The victim is not necessarily the target Despite the disruptions they cause to internet service operations, DDoS attacks targeting ISPs—contrary to popular belief—do not necessarily target the ISPs themselves. In most cases, the goal of hacker groups is to use these companies’ infrastructure to attack their actual targets, which are usually large multinational corporations. Equipment with inadequate or incorrect configurations, along with human error, are typically factors that facilitate the exploitation and “recruitment” of this infrastructure into the criminal underworld. During large-scale DDoS attacks, victims are typically hit with a high volume of requests originating from thousands—and sometimes tens of thousands—of different sources, usually spread across the globe. Mitigation measures and strategies that rely on human effort to identify the sources of attacks become ineffective in the face of hackers’ enormous firepower, since these attacks originate from thousands of different malicious sources that suddenly flood the victim’s infrastructure. That is why it is best to rely on an Anti-DDoS system. DDoS attacks spread across 181 countries On the 12th of last month, about two weeks before the new wave of DDoS attacks was made public, Hacknet, an artificial neural network designed to identify hacking activity worldwide, identified and mapped a large network of more than 40,000 servers, spread across 181 countries, that were being used to launch DDoS attacks. The news was posted on the website and social media accounts of NetSensor, the company that maintains this neural network, along with a link to download the list of IP addresses being used in the attacks, so that security professionals could take preventive measures to protect themselves. NetSensor reviewed the list of devices that were being exploited, enriched it with additional data, and sent private notifications to the email addresses registered as the contact information for each IP address block. In Brazil, more than 1,000 companies were involved, resulting in more than 1,600 contact emails, in which NetSensor issued the alert, provided information about the device, and made itself available to answer any further questions. The results of the notifications were a negative surprise, with things like: The saddest response came from the person in charge of a provider’s server, who simply wrote: “Please remove my email from the list.” Few companies take this seriously There were also some companies that responded positively to the alert. Some forwarded the case to the person in charge of the device using that IP address; others requested more information about the case; and still others thanked us for the alert and said they would review the case and take the necessary measures. Unfortunately, the percentage of companies that took this more serious and professional approach was around 0.5%. Given this scenario, companies in general need to keep in mind that cybercrime has become much more sophisticated in recent years; it has become highly organized, structured, intelligent, and profitable. Therefore, to be able to confront and defend against these cybercriminals, we must develop techniques and knowledge and make intelligent use of resources that match the level of our attackers. In other words, we must seek out new approaches and technologies capable of helping us defend against emerging threats—threats that we are currently unable to address effectively. Furthermore, the neglect, incompetence, and negligence we see in relation to networks, equipment, and services can no longer be tolerated. Only then will we have a chance of success in confronting the threats that surround us, coming from the dark side of the internet. Source: https://www.cisoadvisor.com.br/provedores-de-internet-enfrentam-nova-onda-de-ataques-ddos/ How to Protect Your Internet Service Provider from DDoS Attacks Just as there are tools used by attackers, we also have tools and methods to protect the service provider. What we need to do is mitigate the attack, which involves protecting the target from DDoS attacks. Made4it has the right tool for you: Made4Flow!With Made4Flow, you can detect attacks and take action to protect your provider. Learn about the benefits of anti-DDoS for internet service providers:

What’s new in Zabbix 6.4?

The new release focuses on simplifying Zabbix configuration, allowing Zabbix to instantly propagate configuration changes across large, distributed environments, as well as streamlining software update workflows. Organizations using LDAP or SAML will benefit from the new Just-in-time (JIT) user provisioning capabilities, allowing IT administrators to propagate Zabbix users using centralized user authentication mechanisms. This update also contains several templates and integrations for the most popular vendors and cloud providers such as Veeam, AWS, Azure, Cisco and many others. Just-in-time (JIT) user provisioning Automatically create and update your Zabbix users with the new Just-in-time user provisioning feature for LDAP and SAML: Cause and symptoms events To allow for an overview of issues and better filtering options, as well as identifying root cause of issues, issue events can now be marked as cause or symptom events: Instant propagation of configuration changes Instantly sync your configuration changes to Zabbix Agent and Proxy, running in active or passive modes. Zabbix active and passive proxies can now capture any configuration changes made to your Zabbix instance almost instantly: The active Zabbix agent now receives a complete copy of configuration only when configuration changes are made between configuration synchronization intervals: Zabbix update without downtime To improve Zabbix component update flows (especially for large environments), proxies are now backward compatible within the same LTS release cycle: Speed and performance improvements to bulk SNMP discovery and data collection A new way to collect a large amount of SNMP metrics in bulk with minimal performance impact on the monitored endpoint using GetBulk requests: New menu layout The Zabbix menu layout has been redesigned. The purpose of the new menu layout is to provide logical and consistent access to key Zabbix features: Real-time streaming of HTTP metrics and events Transmit real-time metrics and events from Zabbix to external systems via HTTP: Template Versioning Template versioning was introduced to improve template management and make it easier: Development framework for creating Zabbix widgets Several design changes have been made with the aim of simplifying the workflow for creating custom widgets in Zabbix: Optional interfaces for server-originated checks. A host interface is no longer needed for item types related to collections initiated directly from Zabbix Server or Zabbix Proxy: Simplified setup of media types for multiple email service providers Zabbix 6.4 simplifies the workflow of configuring a new email media type by allowing you to select from several pre-configured email service providers: Additional templates and integrations Zabbix 6.4 comes with many new templates for the most popular cloud providers and vendors: Zabbix 6.4 introduces a webhook integration for the Line messaging app, allowing events from Zabbix to be forwarded to the app Additional changes and improvements Made4it is a technology company that is proud to be a certified partner of Zabbix, one of the world’s most renowned network monitoring platforms. As certified partners, our professionals are highly skilled at providing customized solutions tailored to each client’s specific needs. Our network monitoring solutions are comprehensive and range from basic configuration to the implementation of advanced solutions for large-scale networks. With Made4it, you can rest assured that your system is being monitored 24 hours a day, 7 days a week, ensuring the security and optimal performance of your network. In addition, we have a highly qualified support team that is always ready to help if you have any problems or questions. With Made4it, you can rest assured that you’re in good hands. Don’t waste any more time and get to know our network monitoring services. Contact us today and find out how we can help your business perform even better!

GRE + IPSec tunnel between Cisco IOS and Huawei NE40

In this post we will discuss a very common (and little documented) scenario, which is to use a GRE tunnel secured with IPSec between a Cisco IOS ASR1002 router and a Huawei NE40 router. The topology for this example is described below. It has been kept simple so that we can discuss the details of GRE+IPSEC without getting into the rest of the network. In this setup, we have a Cisco router with the public IP address 198.51.100.2 and a Huawei NE40 router with the public IP address 203.0.113.66. Both are connected to the Internet and are connected to each other. We need to establish a GRE tunnel between the routers and secure it using IPSec in tunnel mode. The tunnel’s address space is 172.31.31.0/30. In the next lines below we will talk about GRE and IPSec. The objective is not to completely detail these protocols, but to give an overview and, mainly, a basis for the rest of the article. Don’t be hasty, there is very relevant information in there. GRE Generic Routing Encapsulation (GRE) is a tunneling protocol that can encapsulate a variety of network protocols (eg ATM, IPX, IPv6 and even IPv4) within IPv4 packets. These packets can then be transmitted over common IPv4 networks (eg Internet). Some use cases for GRE:connecting internal networks that are not directly connected to each otherconnecting isolated IPv6 networks via IPv4 networksestablishing communication between headquarters and branches over the Internetmitigation links using VPNs when routing protocols are required IPSEC IPSec is a security framework developed by the IETF that seeks to solve security problems that the IPv4 protocol failed to address, such as encryption, data integrity, source validation, and anti-replay. IPSec is actually not a single protocol, but a combination of protocols and algorithms. The main ones are IKEv1, IKEv2, ESP and AH. IPSec is widely used in VPNs, both remote-access and site-to-site. In the life cycle of a tunnel, we have 5 well-defined stages: Definition of interesting trafficInteresting traffic is the trigger that causes the tunnel to be established. When the router or firewall detects interesting traffic, it initiates the next steps in the IPSec negotiation. Interesting traffic is usually configured in the form of ACLs, or traffic policies. IKE Phase 1In Phase 1, the protocol establishes a secure communication channel with the remote peer. Once this secure channel is established, Phase 2 message exchanges are permitted. It is in phase 1 that peers are protected, authenticated, and ISAKMP policies are compared (and need to match). There are two modes, main and aggressive. Terms you will see about phase 1: ike, isakmp, DH group, pre-shared-key, integrity, isakmp policy IKE Phase 2In this phase, with the secure tunnel already established in Phase 1, we can negotiate what are called IPSec SAs, which are essentially dynamically negotiated “contracts” specifying the type of traffic that will be protected by the IPSec tunnel. An example might be “I will protect traffic from the 192.168.1.0/24 network when the destination is 192.168.2.0/24 using encryption algorithm X and authentication algorithm Y,” and the remote peer establishes the rule in the opposite direction. Another function of phase 2 is to maintain SAs, as well as expire keys and sessions if some parameter is reached (e.g. expire SAs and trade new ones every x hours, or every N kilobytes). Terms we will see about phase 2: ipsec, ipsec sa, crypto acl, transform set, mode tunnel, authentication, encryption, ipsec policy Data Transfer This phase involves the data transfer itself. Once the relevant traffic arrives at the router and phases 1 and 2 are complete, the packets are sent in accordance with the agreements established in the IPSec SAs and transmitted to the remote peer. Tunnel Termination The tunnel is terminated manually, or when an IPSec parameter expires or reaches its limit. In this case, all keys are discarded, the agreements are terminated, and if traffic needs to be routed, a new IPSec tunnel must be established. For more details on GRE and IPSEC, please refer to the references cited at the end of the article. The GRE and IPSEC configurations agreed upon by the parties The example below is how VPN information is agreed upon. These are usually forms that are filled out with information about the tunnel. VPN Device Site A VPN Device Site B VPN Device VPN Peer IP Address * 198.51.100.2 203.0.113.66 Device * Cisco ASR 1004 Huawei NE40-M2K Version * V3.0.6 Tunnel Properties Site A VPN Device Site B VPN Device Phase 1 Authentication Method APasswordWellS3gur@ APasswordWellS3gur@ IKE version IKEv2 IKEv2 Diffie-Hellman Group group 14 group 14 Encryption Algorithm * AES 256 AES 256 Hashing Algorithm * SHA-1 SHA-1 Main or Aggressive Mode * Main mode Main mode SA Lifetime * (for renegotiation) with no kbytes rekeying 86400 seconds 86400 seconds Phase 2 Encapsulation * (ESP or AH) ESP ESP Encryption Algorithm * AES 256 AES 256 Authentication Algorithm * SHA-1 SHA-1 Perfect Forward Secrecy for rekeying * Disabled Disabled Diffie-Hellman Group * group 14 group 14 SA Lifetime * (for renegotiation) ) with no kbytes rekeying 3600 seconds 3600 seconds GRE Addressing 172.31.31.1/30 172.31.31.2/30 Keepalives Disabled Disabled MTU 1400 1400 Adjust MSS 1360 1360 Important License/Module Information Check with the manufacturer of your equipment to see if some kind of service card, or license is not required. In the case of the equipment in this lab, the NE40-M2K router did not need an additional physical module, just the IPSec license. On the Cisco router no license was needed either, because its IOS was already in ADVIPSERVICES-K9 (which contains the entire basis for Ipsec). *Helpful information*: if you want to run IKEv1, on the Huawei router you need a software module for IKEv1 (which you get from the Huawei vendor). Cisco IOS XE Configurations So let’s configure the Cisco router to establish the VPN. I won’t go into detail about the physical interfaces, only about the VPN. At the end of the article there is a block with the relevant conf of them. Phase 1

Launch Made4Flow v2

We are very proud to announce the release of version 2 of Made4Flow and Anti-DDoS. Bringing several improvements, this version brings new features and optimizations. With a much more attractive look and interactive dashboard customization option, Made4Flow v2 stands out with its much more polished and refined interface, and also much faster and dynamic compared to its predecessor.

Netflix CDN, how to order?

Now that you understand the importance and benefits of a local CDN cache (if you don’t already know, check out: “What is a CDN cache, what is it for, and why use it?”), we’ll explain what we need and how we acquired the Netflix CDN cache, also known as OCA (Open Connect Appliance): Minimum bandwidth! Since Netflix will need to invest in expensive hardware for you, it has to be profitable for them, too! Today in Brazil it is necessary to have at least 5GB/s of traffic with Netflix. Source: https://openconnect.netflix.com/deploymentguide.pdf “I get a lot of other content bundled together in transit, how can I be sure how much traffic I have with Netflix?” To accurately determine how much traffic we have from Netflix, we need a tool that allows for a detailed analysis of the source and destination of the packets traveling through the network. For this, we recommend Made4Flow! This allows us to view traffic for our top content. There are also several other means that allow the visualization of WHERE we learned the traffic: A field with more details on Netflix consumption specifically: We visualize traffic originating from Cache CDN (OCA) servers or traffic with Netflix How much Netflix traffic represents from our network total. Where do we receive traffic from Netflix, and whether it is used by us or by an ASN customer Made4flow has many other applications to give you the best visibility of your traffic. “I THINK I already have or am close to the necessary traffic with Netflix, when are they going to come here to offer the service?” Unfortunately they won’t, you need to go after them! And you need to make sure you meet the requirements before applying, otherwise they might put you on hold for a few months until your next application. Contact them through the Appliance Request, through the link: https://openconnect.netflix.com/pt_br/deployment-guide/appliance-request/ Please fill in the form with extra attention to the fields in the images below: After that, in a few days Netflix will give its answer and more details about the delivery of the Hardware, which is usually: 1u (smallest model) or 2u (largest model) server With 2 or 4 ports of 10GB/s (Optical) You can see the complete description of the hardware in the link: https://openconnect.netflix.com/pt_br/appliances/ After placing your order, be sure to meet the bandwidth, interconnection, power, and rack space requirements, which can be verified at https://openconnect.zendesk.com/hc/en-us/articles/360034538352 In the next posts we will have more details on how to perform requests from other CDN caches and much more! Also follow us on social media to learn more about Made4it and Made4Flow. If you have any questions about the request or about the made4flow software, please contact our team.

Made4it arises to meet the needs of the market, which has been demanding more and more personalized solutions.