Sunday, March 25, 2012

7 ways to get the most from your Recruiter


Working with recruitment agencies can be a frustrating experience for many different reasons, but it needn‟t be that way! Accredited and professional Recruitment Consultants can offer valuable advice and provide career opportunities that may never be advertised.
We asked three of our most experienced staff, who have over 50 years engineering and technology recruitment experience between them, to give us their 7 top tips to ensure Recruiters and potential Employers sit up and take notice of your application.

1. Invest time in your CV. Whether applying direct to companies or via a recruitment company, it is essential to invest time in your CV. Ensure it is well formatted, spell checked, easy to read and above all does you justice. On average, hiring managers will give your CV just 30 seconds before making a yes/no decision and if they are left searching for relevant information buried in pages of block text, they will soon lose interest. Experienced Recruitment Consultants should be well placed and willing to provide independent advice on your CV but please also bear in mind that your CV will often need tailoring to a specific role to give you the best chance of securing an interview.

2. Work with Recruiters that specialise in your field. Perhaps an obvious statement - but it‟s essential that you engage and establish trusted relationships with Recruiters that are likely to be in a position to help, rather than taking the “spray and pray” approach. Recruiters that truly specialise in your sector (and it‟s easy to tell those that just talk the talk!) are much more likely to fully understand what you do and be knowledgeable about your specialist area. Furthermore, they are more likely to be well connected in your sector and therefore have more opportunities that are relevant to you. A list of accredited recruitment organisations can be found at the Recruitment and Employment Confederation website.

3. Limit the number of recruitment agencies that you work with. Do some investigation and focus on building relationships with no more than about 4-5 agencies that you believe to be credible and trustworthy within your sector, ideally from referrals.

4. Read job adverts and only respond to the ones for which you are suitable. The cause of much frustration for Recruiters is being deluged with CV‟s that are clearly unsuitable for the role advertised, despite including essential skills and experience. Job boards make it so easy to apply for roles these days that many candidates hit the send button without reading any more than the job title, thinking it will do no harm and not taking account of the considerable time it takes recruiters to assess, shortlist and respond to every application. In only responding to adverts appropriate to your skills / discipline, you are much more likely to receive a faster and more positive response.

5. Follow up with a phone call. Once you have applied for an advertised role for which you‟re confident of your suitability, it does no harm to give a call to the recruiter 24 hours later. When you‟re trying to differentiate yourself from many other applicants, speaking with the Recruitment Consultant gives you the opportunity to sell your attributes again and answer any initial queries or doubts.

6. Retain control of your CV. One of the biggest dangers of registering your details with a myriad of agencies is that you can easily start to lose control. Every week we hear of Clients receiving CV‟s that the candidate had no idea was being presented, let alone which agency might have sent it, without their knowledge or consent. We have even heard of CV‟s landing on the desk of their own Manager – unbelievable eh? Not only is this entirely illegal (although frighteningly common), but let‟s not forget that it is „your’ CV and should be treated with due respect by the recruitment community.
Be aware that the law demands Recruiters to tell you where they are proposing to send your CV and get your express permission before doing so. Most reputable Recruitment Consultants will also adhere to the voluntary REC Code of Professional Practice and the IRP Code of Ethics & Professional Conduct.

7. Utilise the expertise of the Recruitment Consultant. Once you have established a trusting relationship with a Recruiter, whose opinion you truly value, make the most of the competitive advantage they can give you. Their knowledge should include an insight into the company, organisational structure, major projects being worked / tendered etc and the preferences / personality of the managers that you might be meeting during the course of the selection process. They can also offer valuable assistance with interview preparation and what questions you might expect along with assistance with resignation letters, counter offers and salary negotiation.



Sunday, March 18, 2012

How to create the perfect CV

                                                     How to create the perfect CV

Ok, it’s time to rewrite your CV. You may perceive this as an extremely tedious and mundane task that only needs a very short amount of your time, but this attitude could seriously jeopardize your career prospects!

A CV is an opportunity to show a prospective employer your skills, achievements and also your personality. It is your shop window and should be viewed accordingly. A poorly constructed CV will do you no favours when applying for a new position.

During my time in recruitment I have seen thousands of CVs, some well written and some extremely poor.Hopefully by the time you have read this, you will appreciate how important your CV is and also how to create the perfect CV.

Construction
The first thing I would advise is to write your CV yourself. Do not be tempted to pay a company to do this for you. Every CV I have seen that has been created by a ‘professional’ CV writing service has been extremely poor and a waste of money. A CV contains personal information and therefore should be treated accordingly, do not entrust someone who is merely doing it to pay bills.

When I receive a CV the first thing I look at is the grammar. Then the construction and finally the content. The reason is simple, I want to see that care and attention has been afforded. Anyone can put information onto a piece of paper, but it takes time to ensure it looks professional, captures the attention of the reader and most importantly, creates the right impression. You are a sales person after all!!

A poor CV tells the reader that you are not committed, lack attention to detail and quite simply, are not taking the process seriously. These CVs will head straight into the shredder. It still amazes me that people cannot see the importance of spending time constructing a CV, after all, this document could be your only way of securing an interview.

Don’t forget, first impressions count. You would not attend an interview in scruffy clothes, so why send a CV which is poorly constructed? Your aim is to communicate your strengths, your achievements, your initiative and your personality. In short, your credibility and suitability. Be positive, not too modest, but do not exaggerate. Always use a spell checker and get someone else to proof read. One mistake could make all the difference.

Content
So, what information should a CV contain and how should it be constructed?

1. Personal details.
Ensure that you provide all relevant information, the names of your children and year you were married are not. The introduction of the Age Discrimination Act in October 2006 means that if you do not give your date of birth, companies are not entitled to ask. I would however suggest that you provide this information as it helps the reader build a clear picture.

2. Profile.
This is a concise paragraph or bullet points highlighting your skills, strengths and achievements. Keep it brief but just enough to gain the readers interest. There is no harm in tailoring this to the role and matching your skills to those required.

3. Education
Work in chronological order starting with the most recent. Include the name of the establishment and the qualification gained. The further back you go, the less relevant they become but always provide some information, eg. 7 O’Levels incl Maths & English. If you are applying for a role that requires specific qualifications, make sure you highlight these.


4. Full employment history
This is the most important. Again, work in chronological order starting with the most recent role. You must include the dates, name of employer, role, duties and achievements.
Sell yourself! Give clear examples of your successes; include actual figures, but only ones that you can back up at interview.
Bullet point the information as this makes it easer to read. You must include a reason for leaving as this will put the readers mind at rest if you have had a few quick moves. On this note, do not leave out positions as you may be found out when references are taken.

The further back you go, the less relevant the roles become, so again, summarise. If you left school and temped for 5 years, do not list each role but bundle them all together giving an overview of the work and the skills gained.
Ensure that you do not leave any gaps between dates, this always worries the reader and makes them think you are hiding something.

5. Interests
One tip – never put ‘Socialising’ or ‘Reading’. They are far too general. Be specific without getting too quirky. Remember you want to appear interesting with an active life outside of work.

6. Referees
My advice is to write, ‘Available upon request.’ A prospective employer does not need names and addresses at this stage.

If you have undertaken relevant training courses list these also, including the date.
Including your picture is not necessary unless specifically requested by the employer.
Feel proud when writing your CV, you want to show yourself off!
Regarding length, do not try to cram all your information into 2 pages, your CV will look too cluttered. Use your common sense. Too short and your CV will lose it’s impact, too long and you will lose the interest of the reader. 3 pages will suffice and should leave the reader wanting to know more. The most recent / relevant information should be expanded upon, this will then allow you to summarise those positions you took upon leaving school etc.

Appearance
Your CV should be aesthetically pleasing also. No fancy fonts, no multimedia, keep it simple and professional. You should be spending more time on the content and less on trying to make your name flash in 5 different colours.
When printing, use quality paper with a decent gsm, do not attempt to alter your CV using a biro and when posting, do not cram the CV into a tiny envelope. Again, remember first impressions.

After all of this, take a well earned rest safe in the knowledge that when your CV arrives on the prospective employers desk, it with not languish will all the other scraps of paper and half baked resumes but will be top of the pile and making an impact.




Saturday, March 17, 2012

CV Writing Tips

CV Writing Tips
Your CV is your personal sales brochure and the key that unlocks the door to high quality interviews. Decisions to interview or reject candidates will be made on this document and in most instances your CV will be pitched against a potentially vast number of other candidates.

How to write your CV
• Include contact/personal details at the front
• Unless requested, do not include supporting documents such as certificates or letters of recommendation
• Ensure all qualifications and jobs are dated
• If there is a gap in dates, include a brief explanation
• Illustrate your capabilities – try not to make sweeping statements
• Be clear about what your main selling points are
• Revisit your completed CV to check if these come across
• Examples of selling points: well-known employer, rare skill set, size of projects, particularly relevant qualifications etc.
• State the size and scope of your responsibilities. Examples of people you were responsible for,budgets, number of people affected etc
• Give examples of achievements, using adverbs where possible eg. “Successfully implemented…”
• Use a universally recognised job title if the internal one is likely to confuse
• State the scope and size of business when a company is not widely known
• Dedicate just a couple of lines to you your hobbies / interests Format
• Aim to keep your CV to 2-3 pages long. (Interim CV's may be longer).
• Try to use a good word processing package like Microsoft Word
• Include page numbering and repeat your name on each page
• Space the text out – with clear breaks in between sections
• Use lists – it is quicker and easier to pull out key information than in paragraph form
• Make it 3rd person: avoid using 'I was involved with..' - instead find examples where you can use 'Responsible for…’ or ‘ Achieved …’

Finally:

1. Check your CV for spelling and grammar
2. Ask a friend to have a look as they may spot some oversights
3. Read your CV again and ask yourself
Is it realistic? – don’t exaggerate or indeed, undersell Is it relevant to the job?
Would you want to meet that person?

Thursday, March 8, 2012

Are you a Determined or Desperate Job Seeker ?

When you’re anxiously awaiting your next job opportunity, sometimes it’s easy to walk the fine line between being a determined job seeker and desperate one. Of course, it’s not uncommon to feel desperate when you’re ready to get a job, but being desperate is something that should be practiced in the privacy of your home – not where others, namely prospective employers, can catch wind of it. If you’re not sure whether you’re giving off an air of determination or desperation, here are some ways to make sure you’re coming off as a determined job seeker.

Keep the Usual Formatting In Your Resumes
Desperate job seekers have been known to do some crazy things when trying to find work. One has been creating the crazy resume that is meant to garner attention but actually steers people in the other direction.

You may feel that you’re in the middle of a last ditch effort to get someone to pay attention to you so you want to submit your resume in a quirky font or add hearts as bullet points – what do you have to lose, right? Well, there is actually as much to lose today as there was when you started your search right after leaving your last job.

Don’t allow the search to drive you to do crazy things. Instead, keep your composure, submit your great traditional resume and feel confident that it will help you get hired.


Follow Up but Don’t Harass
While you may feel anxious to get out there and tackle every hiring manager you see, pin them down and stuff your resume in their face, of course, this is something you wouldn’t do. However, in the midst of your job search, there are ways to actually come off as though you’re just that desperate.

For instance, you could hound a hiring manager with whom you’ve shared your resume or pester a person who may be a networking contact for you. In both cases, it’s good to hand over your information and let the people do their job. There’s nothing wrong with following up, but harassing someone is not acceptable.

Don’t Overstress Your Search
It’s good to dedicate quality time each day to your job search. In fact, many say that it’s good to give an entire work day’s effort to the search. However, you don’t need to spend every waking hour looking for a job, contacting individuals, blogging and sending out blasts on Facebook. You have to allow some of the search to manage itself.


A good way to remedy this is to spend time outside or enjoying some other favorite activities. Being anxious and desperate doesn’t really help you and won’t have a hugely positive impact on your search.

Whether you’re turning in crazy resumes or telling an interviewer how anxious you’ve been to find work, there is a such thing as being too desperate. So take time to pace your job search and make sure to relax so that the process doesn’t overwhelm you. Most important, feel confident that the hard work you’ve given will inevitably offer the results you desire.

Tuesday, March 6, 2012

CV Tips

                                              CV Tips


How many ads do you remember every day?

When you're job-hunting you are the ad. Your CV and interview are the only chances you've got to advertise yourself. Make sure you stand out. Don't forget, first impressions last: you're on sale from the first call.

Get our specialist advice on how to create the best possible CV as well as our tips on clinching that first vital interview. Take a look at the online CV template: simply fill in your own details and a consultant will contact you regarding suitable vacancies.


CV Do's


Communicate your strengths, your achievements, your initiative and your personality. In short, your credibility and suitability. Your CV should be no more than two pages long. Think quality, not quantity. On average, readers absorb 60% of the first page, 40% of the second, and the third is generally a waste - this has been proven time and time again.

Aim to make an impact on the reader.

Put the greatest emphasis on your most recent positions. Summarise older roles. Include dates and months of employment for each. Include your competence in foreign languages (basic, good, fluent), but be honest. So, if you only have 'O-Level French', then you have 'basic French'. Be positive - don't be too modest and don't lie about your experience. Positive thinking is vital to secure that next position.

Tailor your CV to each job application. Tailor the CV to the company/department and position whenever possible. Although this may be time-consuming, it could just help you clinch that job! You could include a 'position sought' section in your CV for this purpose.
top

CV Don'ts


A badly prepared CV undermines the credibility of its contents.

If you cannot produce a professional document about yourself, an employer may conclude that you are unlikely to have the competence to fill an important job.

Don't make false/exaggerated claims: honesty is always the best policy. If the interviewer spots inconsistencies in your CV you won't be successful.

Don't provide personal information such as weight, height, and place of birth. You can include information about your interests, but keep it short.

Don't enclose a picture.

There is no need to include your 'hobbies'. If you have some outstanding achievements, such as 'Olympic Rower', there is clearly no harm in mentioning this: it may enhance the interview.

Don't include your required rate/salary. You cannot win - the figure will often be too high, or sometimes even too low. Negotiate this after you've got the job!
top

CV Content


Make sure your CV has a clear structure - include career overview, skills overview, qualifications (education/professional) and employment history.

Employers often make up their mind from reading the initial summary and key skills. Create a compelling summary on the first page and include a list of your key skills and key applications in bold. Note the quantity of experience you have for each key skill, e.g. Sales Manager (5 Years), Field sales exec (4 Years), etc.

Bullet points break up a CV well. Employers want to get straight to the salient points so direct them there. Important information should stand out but avoid using just one or two words.

  • Your typical duties
  • Your achievements
  • Your reason for leaving

The above should mean that the reader does not have any unanswered questions and would feel confident in inviting you for an interview.

For further information please download the following article, ‘How to Create the Perfect CV’ or clicking on this link.
top

CV Template


Download the Online CV Template which you can complete and send to us.

Monday, March 5, 2012

Working overseas can be a real possibility if you know where to look

                                               SIX easy steps to finding work overseas.
1. INTERNAL INQUIRY
If you're lucky enough to be working for a multinational corporation, there are normally opportunities to work for the business overseas. An inquiry to the human resources department will determine what's available but it's also worth asking your boss. Hotel chains and mining companies are prime for such opportunities, as are large finance and banking corporations.
                                                                                                                         
work anywhere in the world 2. RECRUITERS
At any one time there are hundreds of international recruitment firms offering opportunities for overseas labour, including many Australian-based groups. As well as facilitating the move, they can offer practical advice for would-be workers and save you time on research.

3. WORKING HOLIDAYS
If you are under 30 and not undertaking an internal company transfer, there are many countries that offer working holiday arrangements. Generally you need to be childless and have sufficient money for the length of your stay to qualify. The Australian Government has reciprocal agreements with many countries, including Britain, France, Hong Kong, Malta and Cyprus. Visit: www.immi.gov.au/visitors/working-holiday/australians-overseas/#c

4. LINKEDIN
LinkedIn is Facebook for work. It allows members to have a profile that can be viewed by colleagues, prospective employers and recruiters. Recruitment firm Robert Walters HR manager Marisa Iuculano says LinkedIn is a must if you want to be noticed.
"Getting LinkedIn is simply a non-negotiable if you want to find yourself a job overseas. It's an international database for labour, and employers won't be able to find you if you are not there. It is the easiest way for employers to see your skills."

5. VOLUNTEER
While you are not a slave, many overseas companies have an unwritten policy requiring prospective employees to do some unpaid work before they give them a job.
"This sort of thing appeals a lot to graduates who want to travel and who have just finished their degree. It also shows employers that you are keen," Iuculano says.

6. NETWORKINGGetting in touch with the governing body for your industry will help with creating opportunities to meet and get to know future employers and colleagues at industry events.


 

Monday, February 6, 2012

A Different Approach to Network Intrusion Detection

There are many Intrusion Detection Systems out there. What exactly should an Intrusion Detection System or Solution do? Well that one’s sort of self explanatory, it should detect intrusions. There are host based intrusion detection solutions and there are network based IDS solutions. Host based IDS try to determine malicious processes and inter-process behavior from the perspective of a host. Network IDS solutions attempt to see malicious activity from analyzing network traffic. Network Based IDS has a particularly broad view, but is prone to false positives (falsely identifying benign traffic as malicious) and false negatives (not identifying malicious traffic). Additionally, more and more network traffic is being encrypted, thus hiding malicious payloads from IDS sensors. So in addition to the initial cost of purchasing an IDS solution, they require a lot of tuning to get useable results.

This post is about a different approach to network intrusion detection. It is certainly not meant to replace traditional IDS solutions, but can be added alongside existing solutions. This solution looks for traffic that shouldn’t exist at all. If traffic is seen using this method, it should be investigated. This stray traffic is either a result of a configuration error, or a malicious process. In addition to producing few false positives, the cost of this solution is next to nothing.

To implement this solution, a network administrator would basically black hole all address ranges that are known not to be in use and direct the traffic to a host that can capture these packets. The RFC1918 range should be a safe bet. Additionally any public IP address space that is owned by the organization, but not in use could also be used. Let’s look at an example organization’s IP address usage to understand how this might work

ACME Organization

Routing Protocol (IGP): EIGRP (summarization disabled)

IP Addresses (Internal)—

192.168.1.0/24
192.168.50.0/24
192.168.60.0/24
192.168.70.0/24
192.168.80.0/24
10.1.1.0/30
10.1.1.4/30
10.1.1.8/30
10.1.1.12/30

Public Addresses Owned: 192.0.2.0/24
Public Addresses Used: 192.0.2.1-250

In the ACME organization, we should only see IP traffic destined to IPv4 addresses in the above RFC1918 address ranges, the used public address range, and any other public IP address that are not owned by this organization. If traffic appears on the network destined to other RFC1918 address it is certainly out of place and should be investigated. Additionally packets containing a destination IP addresses 192.0.2.0 or 192.0.2.251-255 are also out of place and should be looked at.

So how do we easily capture this traffic for investigation? It is actually quite simple if we think about how routers work and how packets are converted into frames as they are handed back down the OSI model. The first concept we should revisit is the longest match rule that is used by the route table. If a router has a route to 192.168.0.0/16 and another to 192.168.50.0/24, a packet to 192.168.50.12 would match the route to 192.168.50.0/24. A packet to 192.168.33.5 would match 192.168.0.0/16. We can leverage this and inject some routes into our network. So let’s take this concept and apply it to a simple network.

Network Diagram

6-3-2011 12-36-27 AM.png

In the above diagram, we have a “deflection router”. This router is located just behind the firewall, but could be located anywhere in the network (as long as summary routes aren’t overriding the routes that we are about to inject). The first thing we need to do is to deflect packets going to unused RFC1918 ranges out the Ethernet interface connected to our “Sniffer Host”. To do this, we’ll set up an IP address for that interface, and create some routes.

Router(config)#interface fa0/1
Router(config-if)#ip address 10.1.1.13 255.255.255.252
Router(config-if)#no shut
Router(config)#ip route 10.0.0.0 255.0.0.0 10.1.1.14
Router(config)#ip route 172.16.0.0 255.240.0.0 10.1.1.14
Router(config)#ip route 192.168.0.0 255.255.0.0 10.1.1.14
Next we will create routes that will divert the unused public addresses.

Router(config)#ip route 192.0.2.0 255.255.255.255 10.1.1.14
Router(config)#ip route 192.0.2.251 255.255.255.255 10.1.1.14
Router(config)#ip route 192.0.2.252 255.255.255.252 10.1.1.14
Notice, I’m routing the traffic to these unknown address ranges to 10.1.1.14. Does 10.1.1.14 have to exist on “sniffer host”? Not exactly. Actually I might not even want IP bound to the sniffer hosts’ interface. This will help protect the sniffer host itself from being attacked. However, if I take this approach, I must somehow coerce the router to forward the frame anyway. Typically, the router will do an ARP lookup or request to figure out what destination MAC address to use on the frame it has to build. We can trick the router into doing this by creating a static ARP entry. In this diagram, we are directly connecting a host to the router via crossover cable so the host will receive all frames produced by that interface (we just need to remember to put the sniffer’s NIC into promiscuous mode when we start to capture traffic).

Router(config)#arp 10.1.1.14 abcd.abcd.abcd arpa

Now the router understands the egress interface for these packets based on the route statements and the interface that is connected to the 10.1.1.12/30 network. The static arp entry gives the router the information that it needs to “frame” the packets. As long as the interface is up and the router doesn’t have more specific routes to a destination, it will send these packets to the sniffer host.

Earlier I pointed out that this router is in the path to the firewall but it could be located anywhere in the network. Keep in mind that if summary routes are being used, that may need to be evaluated. If this router isn’t already in the path of all packets (aka the default gateway), the routes can be injected into the IGP. This might look something like the following.
Router(config)#router eigrp 1
Router(config-rtr)#redistribute static

Now all we need to do is connect the Sniffer Host to our router via a crossover cable and start our favorite sniffer program. We don’t even need an IP address or the IP Protocol bound on the sniffing interface. A good technique for capturing traffic might to be using dumpcap (part of the Wireshark package) to capture anything destined to MAC address abcd.abcd.abcd and storing it in a file. For example, create a directory called “c:\caps” and enter the following command.
C:\Program Files\Wireshark>dumpcap.exe -i 2 -b duration:86400 -b filesize:50000 files:1000 -f "ether host ab:cd:ab:cd:ab:cd" -w c:\caps\badtraffic.pcap

The above command uses dumpcap to capture traffic on interface 2. The interface number is entered following the “-i” parameter. To determine the interface numbers use for a system, use the following command “dumpcap –D” (case sensitive). The parameters following the “-b” parameters are the ring buffer options. These tell dumpcap when to create a new file. In this case, a new file would be created at least once every 24 hours, the files would never exceed 50MB, and 1000 files would be retained. This should keep space consumption below 50GB. The string following “-f” limits the capture to the frames that contain the MAC address abcd.abcd.abcd (from the static arp). Finally “-w” directs dumpcap to save this contents to a file in the c:\caps directory. The filenames will be based on badtraffic.pcap but will also include a timestamp in the filename.

Now that we have this in place, we can easily test it. To do so, simply ping an address from an RFC1918 address space that is not in use. For the ACME network, we could ping 192.168.254.200. It is a good idea to test this from various points in the network. These packets should make it to our capture file. Double clicking the capture files should open it in Wireshark. We can now investigate the file for any signs of configuration errors or reconnaissance against our internal network. While this is not a comprehensive IDS solution, it is a good way to see when an internal host has been infected with something that it is trying to propagate to other internal hosts.

Saturday, January 7, 2012

Ever heard of Layer 8?

In the networking world many are taught the Open Systems Interconnection model or OSI model of networking.  The OSI model is described as a layered approach of how data travels in the network.  The layers taught in any networking class are, starting from the bottom and working your way up:

Application Layer
Presentation Layer
Session Layer
Transport Layer
Network Layer
Data Link Layer
Physical Layer


However, for years I have always heard the joke about Layer 8.  Now although the OSI has no official designation of such a layer, it has been my experience that such a layer may exist!  In fact, Cisco even addresses this “layer” in their CCDA certification although they do not refer to it as a Layer of the OSI, which they are correct.

In the CCDA, it is taught that in order to make a good design you need to know what the business and technological requirements are and you have to live within the business and technological constraints.  Think about that for a minute.  You have to design a network to deliver who knows what and you have to do it with certain constraints, usually a limited time line or budget.  Have you ever found yourself in a meeting where a customer wants what is technologically impossible, against their company policy or so expense that not even all the money in the world could afford what they want?  I have… often.  To make matters worse the customer may have multiple people present the business and technological constraints and goals and they may conflict with another person’s goals and constraints within the same organization.  Then comes the process of debating, negotiating, hashing out the details to find some kind of compromise and to find a solution that will meet all of the goals and be achievable within the constraints that exist.  It is this process that I refer to as the Layer 8.

If you have not had this experience, consider yourself fortunate.  However as unpleasant as such a situation may be, there are some good learning opportunities for both the design engineer and the customer.  In fact, during this political process as I choose to call it, I have learned a great many things that have been beneficial to help me increase my understanding and help the customer increase theirs!

·      Education and understanding is key when going through the “Layer 8” or “political” process.  During such meetings I have come to realize that more often than not, the customer doesn’t even know what they want themselves!  They just want a solution to work and to be as convenient and easy as possible and they want it for next to nothing.  Listen, really listen to your customer and restate what they are telling you to make sure you understand the feedback they are giving you.  They may be surprised at what you understand from then.

·      Ask who, what, when where, why and how questions.  This will be extreamly helpful in getting the customer to really think deeper and consider the outcome. 

·      Explain in basic principles how technology works.  Some people really don’t want to know the deep details, however, give your customer enough understanding to help them make an informed decision.  It is been amazing to hear customers” gratitude for explaining technology to them. 

·      Give people options.  My kids really don’t care for being told what do to or how to do it.  Customers can be the same way.  Instead of dictating to them what they should be doing (even if you are right), give them options and explain the pros and cons of each option.  Remember it is ultimately their decision, not yours.  Help then to make decision via the process of elimination.  Objectivity is a must!

·      Control emotions!  I cannot stress this enough.  It can make or break a deal, get you promoted or fired!  It is difficult, but it can be done.  People are passionate creatures and that is ok, as long as the passion is controlled.  If it gets out of hand, you may find yourself having a Darth Vader conversion moment and that is not going to help yours or your customers situation. 

·      Document!  The old saying “the customer is always right” rings true, even when they are wrong.  We all make decision, some good and some bad.  All those decisions have some kind of consequence, some good, some bad.  When participating in the Layer 8/political process, acknowledge ownership where it is due.  This is a joint effort and there must be joint responsibility.  Documentation is the key to not only hold people responsible but serves as a reminder of what is discussed, agreed upon and finally decided.  Documentation helps serve as a reminder to everyone.  I can’t remember everything that is discussed in a meeting, but having good notes and documentation sure helps remind me of things and helps to keep me in check.

The Layer 8/political process isn’t for everyone.  Some love it, others hate it.  I love to see customers enlightened as I explain technology to them on their terms.  I really don’t care to be the mediator of a heated debate.   Oh how glad I would be if I had the Enterprise transporters to get me out of those situations!  Unfortunately, that isn’t an option so the mentioned points are the things that have helped me get through the Layer 8/political process.  For a designer, there is much more than technology skills that are needed.  Good personal and communication and negoation skills or "soft skills" are an absolute must to survive this process.

----------
Ref:Cisco.com

Saturday, December 31, 2011

Five Tips to Keep Your Career Moving Forward

Now that 2011 is coming to an end and 2012 will soon be upon us, many will be making New Year’s resolutions. The most popular resolutions probably relate to health. However, many people also include career goals in their resolve. With the continuing economic challenges, it is tough but not impossible to feel like personal career growth is continuing. This article is only peripherally related to our current series of discussions on job roles and tasks. This is article is a New Year's Article that focuses on five key things that everyone can do to help keep their careers moving forward, even in tough economic times.
Tip 1 - Find a Mentor
Finding a mentor may be a challenge. In many cases people tend to keep what they know to themselves. Some people seem to think that if they are the only person that can do a task, they are more valuable to the organization. Furthermore, some people like to place themselves high on a pedestal and have the desire to stay there. I think we have all met people like Nick Burns. I doubt Nick would make a good mentor.
For those unfamiliar with Nick Burns, here is a video excerpt from Saturday Night Live.
A good mentor is someone that you can trust and who can help you stay on track. This is not a person that does everything for you when you get in over your head. This is a person who gently steers you in a direction that is conducive to your career or your particular role in an organization. This person can not only be beneficial for career goals, but also for specific tasks that may be a stretch for your abilities. The challenge is finding someone that is willing to take the time to share their experiences. If you cannot find someone within your immediate circle, you can always have lunch with others in the industry and learn from each other’s experiences.
Tip 2 - Build your Network
There are many networks out there, so let me elaborate. There are social networks like Facebook, Twitter, Google Plus, and LinkedIn. What I’m talking about here is YOUR network. It may consist of contacts that you have met personally, as well as a subset of individuals from any or all of the social networks I mentioned. What is important is that you start to build solid relationships for a couple of reasons. You never know when you might need a “go to” person or a subject matter expert in a particular area. Additionally, making others aware of your areas of expertise or experience can be beneficial. People are in YOUR network if you feel comfortable reaching out to them and they feel comfortable reaching out to you. Don’t abuse your network. It should be a “qui pro quo” arrangement that is mutually beneficial for you and them.
Tip 3 - Help Others

Helping others is sort of the opposite of finding a mentor. Helping others can actually help you in many ways. First, there is no better way to solidify concepts than pushing your knowledge to the point that you can explain something simply. I am not advocating that someone should share their knowledge about something that they know nothing about. However, an individual that has worked with a specific topic or technology often will initially struggle to explain it. Working through this struggle often leads to a much deeper understanding.
If you can't explain it simply, you don't understand it well enough. -Albert Einstein
Tip 4 - Continue Learning
Since you are reading an article on The Cisco Learning Network, you may naturally desire to continue learning. This is a good thing. With networking technology, I do not think there is a point that you look at yourself and think “I have arrived”. Like other career choices in technology, we must be comfortable with change. The value that you bring to an organization is your ability to work with that change. Your thirst for knowledge should not just be in deeper understanding, but also broader understanding. How technologies interact with one another is as important as knowledge about the individual technologies. Nothing lives in a vacuum anymore. All areas of technology are interoperating with other areas to achieve some business goal. Although the fact that someone can configure a router or a switch is very important, companies are looking for people that can solve the business goals and challenges.
Tip 5 - Keep your life in Balance

If you love the challenges of technology, keeping your life in balance may be difficult. I think it is important to keep your relevant areas such as family, church, health, and personal time in check. Others tend to view your priorities based on how much time you spend nourishing each of the “loves” in your life. This is valid because we tend to spend more time with those things we enjoy. So if technology is dominating ALL of your free time, you may need to schedule “technology free” times to balance out your life. I have personally witnessed family or personal issues that have had serious adverse effects on individuals’ careers.

Conclusion
I think everyone knows that many challenges exist in the current job market. The challenges seem to be even more prevalent with those who are young or inexperienced to the field in which they are seeking employment. Although technology jobs are more prevalent than some other fields, challenges still exist. If you are not employed, my recommendation is to do what you can to get employed. Even if your employment is less than what was expected, there is always room for growth. For those employed, focusing on these five tips will help keep their careers on track. As new and exciting challenges present themselves, simply gravitate to the areas that are of interest to you.

Ref:

Wednesday, November 30, 2011

Monday, October 31, 2011

Information Security for Fun and Profit

Continuing our series of discussion of job tasks, roles and careers, I wanted to talk about security. As many of you know, I consider myself to be a jack of all trades as opposed to someone that has a deep knowledge of fewer topics. As we will soon see, this actually lends itself well to information security. In this article, I will discuss different disciplines commonly found in security and the skills that are most relevant. We will touch briefly on the certifications that are most relevant to each role and see how we can build our careers as we gain knowledge and experience.
Certifications

Since this article is part of the Cisco Learning Network, I would expect most readers to be at least somewhat interested in certifications. In technology, certifications are one of the more prevalent earmarks of knowledge. In information security, this is also the case. Cisco offers many certification programs. Some are Security centric, while others are not. Even certifications that are not focused on security usually have security components. For example the CCNA program addresses device security, access control lists, and switchport security.

The fact that security is integrated into many non-security centric exams is a theme also found in non-security centric job roles. In other words, security is part of everyone’s job in the enterprise environment, not just information security professionals. For example, one may find themselves working in a network design role. Even though that is not a security position, security is still an important skill that must be integrated into the day to day tasks of that position. Even employees in a non-technical role still need to be well integrated into a solid security program.
Regarding Security centric certifications, Cisco offers the following certifications and specializations. Some of these programs are being discontinued, but may still be associated with individuals.
  • CCNA Security
  • CCSP
  • CCNP Security
  • CCIE Security
  • ASA Specialist
  • Firewall Security Specialist
  • IOS Security Specialist
  • IPS Specialist
  • Network Admission Control Specialist
  • VPN Security Specialist
  • Security Sales Specialist (Reseller Specialization not relevant to the enterprise infosec role)
As you can see Cisco is not only represented with actual security products, but also offers a wealth of security certifications and specializations. However, Cisco isn’t the only security vendor in the security arena. From a security perspective, I consider Cisco a network security vendor. There are other network security vendors who have security certification programs. Examples of these are PaloAlto Networks and Juniper. There are also security certification vendors that do not have an affiliation with specific product vendors. For example, ISC2 offers the CISSP certification and SANS has a variety of information security certifications.
General Security
When I think about information security, I think about data and technology. What can we do to efficiently and effectively protect these resources? A three letter acronym is often used to describe three areas of data protection— Confidentiality, Integrity, and Availability (aka CIA). Obviously this is only one viewpoint or dimension of data protection, but those key points must be maintained across critical systems and corporate data. There are actually several different types of roles that encompass these concepts and different types of people to fill the roles.

Roles

The first security role that I must mention is everyone else. Everyone else is actually everyone in the organization that does not have the word “security” in his or her title. How “everyone else” is used will largely determine the security posture of an organization. Furthermore, if you are reading this article and have the desire to get into security position, you are most likely part of “everyone else”. Security leaders who are reading this article realize that creating a security ecosystem is much easier if "everyone else" is working with you instead of against you.

So what can and should this group of employees do for security? First and foremost, they can familiarize themselves and follow the organizations policies. Possibly even more importantly, they can familiarize themselves with the norm. This will vary widely from position to position, but when someone notices a deviation from the norm, it could be a red flag that something is going on. Good security managers realize that they should never make someone feel unwelcome to bring forth such concerns.

Security Centric Roles
Now let’s talk about the positions in the organization that are security centric. These positions fall into a few categories. The first major category that I would mention is what I call operational security. Later we will also discuss audit and compliance, penetration testers, and security management (a subset of which can also be integrated into any of these roles).
Information Security Roles
When dealing with information security and security in general, operational security personnel are those who have day to day jobs that directly configure, monitor and otherwise maintain the systems that are responsible for the security of corporate data. I often find that security operations is further broken down, into network security, application security and general security operations. In my experience, it is actually difficult to find a single individual who is an experts in all of these areas.

Network Security Roles

Of these three subcategories, Cisco is obviously more prevalent in the network security. Network Security, or netsec, involves securely configuring and monitoring network devices and protocols, building appropriate security boundaries, and configuring secure connections. This infrastructure is then utilized to provide a secure and reliable connectivity for systems and applications. Netsec individuals will likely be responsible for one or more of the following:

  • Firewalls
  • IPS/IDS
  • Router Security
  • Switch Security
  • Network Monitoring System
  • Security Information and Event Management (SIEM)
  • Network Protocol Security
  • Virtual Private Networks (VPNs)
The environment that a network security individual works in (or desires to work in), influences what certifications he or she might have or be seeking. As you can see from the list above, Cisco is well integrated into this area of information security. The depth and breadth an individual is responsible for might also influence the certifications he or she might choose to pursue. For example, someone who is only making day to day firewall changes in a Cisco environment might pursue the Cisco Firewall Specialist. Someone who is making regular ASA Firewall and VPN changes might pursue the Cisco ASA Specialist certification.

If this individual is promoted (or desires to be promoted) from a firewall administrator to a firewall architect or engineer, he or she might pursue the CCNP Security or CCIE Security certification. Typically a person in this field of work who is an engineer or an architect has a broader and deeper knowledge. This person has very likely performed advanced work in many or all of these key netsec areas. Additionally, this senior person will likely manage and/or mentor those who work in their respective areas so they can gain a deep knowledge of the components they are responsible for and how they affect other areas of netsec and the organization holistically.

Application Security Roles
The next key area of information security is application security. Honestly if application security could always be solid, netsec professionals would only need to secure the underlying infrastructure and protocols. Since application security is often overlooked, netsec professionals make an effort to augment the shortcomings. So why is application security such an issue? My opinion is that most developers are naturally focused on providing functionality. Even though they may have concerns about security, it is usually not the primary concern. As a result, a lot of software bugs and vulnerabilities exist. From a netsec perspective, firewall administrators typically permit or deny traffic based on IP addresses, protocols and ports. As a result it is difficult for a firewall to detect anomalous traffic that is potentially malicious against a service that is provided by vulnerable software. This is especially true when the applications perform some type of encryption to further hide conversation details from network security professionals.
So what can an application security professional do? The answer to that really depends on the type of environment that he or she is working in. In some cases, an organization develops their own software, or software for other organizations to use. In those cases, the application security professional might oversee a secure development process. In other organizations, only commercial software may be used. In those cases, an application security professional would need follow various bugtrack sites and understand the ramification of vulnerabilities that have been found in the software used by their organization. In my personal experience, it is difficult to find a single person who is strong in both application security and network security. SANS offers certifications and training that are fairly relevant to application security.

General Operation Security Roles
In the operational security category, there is one more group or type of individual. This position might be simply called operation security (even though it is a subset of the operational security category that I initially mentioned), or something similar. This crucial position or discipline is interested in how an organization processes interact with one another as well as interact with the network and applications securely. Even if an organization has a relatively secure network with relatively secure applications, the methods in which the systems and technology are used can leave the organization very vulnerable. Additionally, a single process may not have any apparent risks. However when that process is combined with other processes in an organization, the risks may be exponential.
A person in this general security position should understand the interaction between systems and processes, making the organization fully aware of operation risks. In a smaller organization, this may be part of the role of the CSO or CISO. This category of individual would benefit from knowledge gained in appsec and netsec as well as understanding the business process that make up their organization. Since these processes vary so widely from organization to organization, certifications may be less relevant. A certification program that provides a broad scope, such as ISC2’s CISSP, may be beneficial though.
Audit and Compliance Roles
I grouped the last three categories of security professionals into one major group that I called operation security. Audit and Compliance is typically a separate group but most work closely with other areas of security. One reason for the separation is to avoid conflicts of interest. This area must be intimately familiar with the ins and outs of all applicable regulatory guidelines. They must work with the respective individuals to establish how each of the guidelines are being met. If there are shortcomings or inadequacies, audit and compliance professionals may further educate the nonconforming area of the regulatory requirements. Although InfoSec is a major component of audit and compliance, it is not the only area of concern.
Penetration Testers:
Earlier I mentioned that it is difficult to find someone who has solid expertise in application security, network security and general operational practices. Penetration Testers, or pen testers, must have expertise in all of these areas. These professionals are individuals who break into systems for fun and profit. The purpose is not to humiliate those responsible for inadequate controls, but to educate the organization regarding weaknesses in their systems.
Penetration testing should be done to some degree by the individual network and application security professionals. This would to test the adequacies of the controls they configured. However, penetration testing that is to be reported to a CEO, board of directors, or other responsible or certifying party, should be performed by an independent third party that has no conflicting interest. It certainly makes little sense for the person who designed and configured a firewall to be the person who is reporting to the board of directors how secures the implementation is. If security is important, an independent assessment should be done. Furthermore, a pen test should go beyond just a firewall, but test the processes and the security posture holistically.
Responsibility
Thus far we have talked about different roles that are actively involved in security. We have also discussed roles that confirm that the organization is compliant with any regulatory mandates. Additionally, we have touched on the role of a pen tester, who can also look for vulnerabilities that may have otherwise been missed. Now we need to talk about responsibility. Responsibility can be assigned at almost any point in the organization. In all actuality, everyone is responsible for their own actions. However, the person I am now talking about is likely an officer in the corporation. When something happens, this is the person that will have to answer the tough questions and explain how this could have happened (given the investment that the company has already made [or thinks it has] in security).
In a larger organization, this person may be the CIO (Chief Information Officer), CISO (Chief Information Security Officer) or CSO (Chief Security Officer. The CIO is typically the person that is responsible holistically for the information systems and data. The CSO and CISO are more focused on security. CSO is more generically related to security, where CISO is focused on information security. Organizations can have any or all of these roles. The CIO often reports directly to the CEO or in some cases, directly to the board of directors. A CISO or CSO may report to the CIO, another member of executive management or directly to the board.

Physical Security
The final thing that should be mentioned about security is that we must not forget about physical security. So those individuals in the organization who are responsible for physical security are very relevant to information security as well. We can install the best firewalls, anti-virus and use the strongest possible encryption. If someone can walk through the front door and carry out a storage enclosure, our information security was all for naught. Hopefully we had full drive encryption, but we are still taking an outage (and that is the third component of CIA).

Conclusion
Security is a constantly evolving area. Specifically with information security, new vulnerabilities are found daily. New threats are coming from some of the least suspecting sources. Like other areas of technology, my advice is to always gravitate toward areas that interest each person individually. If you enjoy deep and broad research and application of technology, information security might be a good career choice.

Ref:
Security Roles

Tuesday, September 27, 2011

Network Management and Operations - Tools of the Trade

Cisco has most recently addressed this in their Service Provider Operations certification track, however there has always been a certain degree of an "ops" perspective seeded throughout most Professional certifications. My approach is more about the tools, methodologies, and tasks that one utilizes on a daily basis to successfully maintain an enterprise network.
Before we embark down the path of being truly successful in managing our enterprise, let us examine why they call it "Operations":
Quoted from http://dictionary.reference.com/browse/operation
op·er·a·tion [op-uh-rey-shuhn] noun
1.an act or instance, process, or manner of functioning or operating.
2.the state of being operative (usually preceded by in or into ): a rule no longer in operation.
3.the power to act; efficacy, influence, or force.
4.the exertion of force, power, or influence; agency: the operation of alcohol on the mind.
5.a process of a practical or mechanical nature in some form of work or production: a delicate operation in watchmaking.
For us, bullet points 1 and 5 are most relevant. As a fellow VIP - Scott Morris - has mentioned more than once, you can often break down any given task into a subset of smaller, simpler tasks. Network Management is the epitomy of this if you really dive into the details; this is why "operations" is the key word given to most groups that execute the Network Management responsibility. It is a series of processes and acts that collectively comprise a full suite of capabilities to help you maintain your IT infrastructure, in this case specifically the network. As most folks that have been in the industry for a bit know by now, networks grow - whether organically or by design. With that growth comes the need to scale your operations to maintain efficiency and reign in costs. Several tools and processes come to mind which allow us to do just that, which we'll discuss in this blog series. Several of these topics will be expanded on in successive blog posts independantly. However, the holistic goal here for now is to show people what tools are out there from a conceptual perspective, why they are important, and what they can do for you individually.

Network Monitoring
One of the primary tools that will enable us to run our networks is a capable network monitoring system. This facilitates near real-time visibility into the status and health of our network. Tools such as SolarWinds Orion, HP OpenView, NetCool, SMARTS, all give the network team the ability to see what is happening based on SNMP and Up/Down tracking of devices. Often called "alerts", when the notification comes through that any given metric has surpassed a threashold, it allows the Network Team to react to it. Most times this involves a ticket being created to track this event. I'll circle back around to incident management down the road, but that is the system you would ideally have in place to facilitate these "tickets".
When you first roll out a monitoring tool, especially if this is the initial introduction of a tool like this in that environment, you may choose to start only with up/down monitoring enabled. This allows the IT staff to really come to terms with dealing with alerts, having the network tell them what is going on, how to use the software, etc. Up/Down alerts are a good way to break staff into this kind of growth of responsibilities/capabilities. Over time you can introduce link status, errors, utilization, et al.
Here are a few favorite alarms that I've seen companies track:
  • Up/Down Status
  • CPU Utilization
  • WAN Link utilization
  • WAN Link health (errors, drops, etc)
  • Critical LAN link status/health
There are myriad more alerts that most systems employ, but those are ones you typically see at any given shop, earning them a spot on the list of what I call universal favorites.
Configuration Management

With a capable configuration management tool you can automate many tasks that may otherwise tie up valuable man-hours. Suppose you need to update an on-call number within SNMP for EVERY DEVICE in the network. That could be 30k devices! If you have 30, maybe logging in and changing that one variable is feasible. However, for 30k, that could literally take weeks. With configuration management, you are looking at writing a script to update the configuration, and then selecting the scope of devices to run the script against, and viola - done! Just be sure your script works prior to blasting it out to 30k devices......
Another example is deploying devices - you can have your staff deploy a switch with the meat of the config, VLANs, VTP, uplinks, etc. They get it up and running - and then you pull it into the management domain and deploy your management template. This can include SNMP, AAA, security ACLs, etc. All centrally managed - which reduces the chance of error.
These tools can often be useful as well to execute custom poll scripts to devices. This can help you tool reports to specifically target a special case that exists on your network, or target specific information you need without having to poll through an entire "show run" or "show tech". This is especially useful the larger your network gets.
Biggest benefits you often gain out of configuration management systems:
  • Historical configuration backup
    • Easy way to find last known good config during outage
  • Mass change function
    • Intelligent scripting can cut time on large-scale simple changes
  • Config reporting
    • Ability to quickly poll a stored data set for patters/configs w/o impacting production network
Incident Management
This is the fabled "ticketing system", which tracks incidents via records, also known as trouble tickets, event tickets, work orders, task orders, etc. There are as many names for it as there are versions out there. Remedy is one prevalent platform, as is Heat. I've worked on several internally developed platforms that usually outperform both, but that is because they were built from scratch for exactly those environments. Tough to do from a template.

The Incident Management System(IMS) is typically seen as the chronological life of the network from an operations perspective. You can track chronic issues at sites, you can track trends, you can track man-hours spent on projects, you can track the utilization of your personnel, etc. Often times you can use these metrics to justify a project/expenditure : "we currently work 3000 unique tickets a week, with this upgrade we could cut that to 500, freeing up X man hours". On the flip side, the IMS can also serve as the record for changes made on the network for break-fix situations.

Common things that IMS tickets are used to track are as follows:
  • Timeline for incident
  • What troubleshooting was done
  • What was found to be the exact problem
  • What actions were taken to resolve
  • What was root cause of problem
The need to document all of the above cannot be overstated. To be able to sit down and say "we have 12 tickets with this root cause a week, we need to investigate why this is occurring", is invaluable. If you can resolve the root cause moving forward, you have then just avoided those future issues. While this kind of analysis typically benefits larger scale organizations, the thought-process and methodology can benefit any size shop. This is the kind of optimization that can really save a company money under the IT budget, and everyone loves doing that.
Change Management Controls
This is many people's worst enemy - change management! The idea is to keep a historical record of all the changes that go on in the lifecycle of the network. The benefit of having this kind of looking glass into the past is multifaceted; metric tracking, root cause analysis, accountability to stakeholders(more on that later....), and perhaps above all - providing visibility into the stability of the network.
Part of the difficulty many organizations face with change management is fully integrating the business facet into the IT world. Not only does this require the IT group accepting the fact that the business has the power to approve/decline changes, it also requires the business to understand the strategic and tactical nature of how their IT systems support and/or drive their business vertical. Without going into specifics, if a business is in the process of making you money, you want the network to ASSIST in that process, not be the cause for financial loss. Robust, well developed, and fully integrated change management policies paired with an easy to use tool to track this is critical for companies to develop stringent control over the lifecycle of the network.
When a business unit fully realizes the control and peace of mind that can result from this kind of framework, they often buy into it and get involved. Balancing business versus IT needs can often be precarious at best, a well forumalted decision matrix can help ease those tensions. When the change control process is followed dogmatically by all of the parties involved, two huge benefits are realized. The vertical can now hold IT accountable for outages they cause - which makes for a more calculated approach to dealing with network changes. On the other hand, the IT group can then say "we made no changes", and the business vertical should have a reasonable level of trust that this is true by looking into the change management system. Checks and balances should always exist, and I've seen large scale shops build in scripting tools to track EVERY keystroke of an engineer and log it to a third party within the company for reconciliation purposes. While this is an extreme case - it goes to show you how far this kind of concept can be taken to balance the need for action and the requirement to follow policy.
More to Follow.....
With that background, in future blogs I will go on to show you how you can tie these tools together using policies and processes. Each of these tools alone provide great value in and of themselves, but they truly shine and provide an exponential ROI when your internal practices leverage them properly. Before I can show you that, though, they would need to be up and running in your environment, no? So, I will give you a few walk-throughs on basic deployment of these tools within your environment. Considerations that need to be addressed, how to pick the best product, the pros and cons of buying Commercial Off The Shelf products versus developing some of them in-house, and so on.
Once we can get them up and running, we are going to discuss integrating your business model as an IT shop around them, how to work with your customers - whether internal or external - and re-tool your relationship with them based on these new capabilities. In addition I'll try and show you can leverage them to provide SLA agreements with internal customers, what you can do to use these tools to bring truth in advertising to other groups within your organization, and a few other neat features that you'll find.
I hope you've enjoyed this blog, if you have any questions or requests, please leave a comment! I will try to respond as best I can, if you don't get a timely response PM me and point me towards the thread.
Thanks everyone for reading!

REF:
Network Monitoring Tools



Friday, September 16, 2011

Network Specialist: Wireless Network Engineer

When looking at any specialization, the deeper you go, the more you realize how much you still have to learn. As I dig deeper into the Wireless area of networking, I have discovered just how much details are involved in being a Wireless Specialist! Although I work in many different Networking areas, wireless is one where I spend a considerable amount of time and an area I am getting deeper into.

First, a wireless specialist has got to have a solid understanding of the physical layer they are working with. That's right, I am talking about RF! All that boring talk in your physics class comes to life in wireless. Things like EIRP, dBm and bandwidth are foundational principles that will promise you failure in the wireless realm if you do not understand them. Understanding the electromagnetic spectrum is a wonderful start. This base RF knowledge is a requirement in performing one of the most important tasks that a Wireless Engineer can have, performing a site survey!

Now performing a site survey in and of itself can be a monumental task and takes a lot of time. There are several things to keep in mind just when preparing to do a survey.

1) Understand what the customer wants. This can be one of the hardest things especially if the customer isn't exactly sure what it is they want other than they want their wireless network to just work.

2) Understand what restrictions the FCC or any other regulatory body may impose on your RF environment.

3) Know the facility you are surveying. There may various procedures, policies and even restrictions that you need to keep in mind. For example, you may need a security clearance to even get inside the building before you can start a survey. There may be OSHA and other fire and safety requirements that must be followed.

4) Plan out what type of survey you are doing. Are you surveying for a Data network, Voice, Location or some combination? Each type will have different RF and AP requirements.

Once you have a plan, start your survey. Typically when I do surveys, I will go over a building map and trace the map with colored pencils what kind of walls, doors or windows there are and then import that map into WCS or some other predictive survey tool. Then, I enter such information to give me a semi accurate predictive survey. It’s a lot of work, but worth it. Next, I take a spectrum analyzer and do a walkthrough of the building just to see what potential interference issues I may come up against. You may be surprised at what you find.

Next, is the Layer 2 survey. Here is where you really look at signal strength, plan out channel placements and survey the overall performance and coverage of the AP you are surveying. I will try to place a few temporary APs in locations that I determined with my predictive survey tool. Then I would take a laptop and perform the Layer 2 survey by slowly walking through the building, gathering Wi-Fi stats from my WNIC. Now there are several ways to approach this. I started out just using the Advanced Stats on my Intel Pro WNIC. It gave be the basic information, but really didn't give things like data rates, transmission errors and those real details that happen in a live wireless network. During some studies, I was introduced to Airmagnet and anyone who is serious about doing a quality survey will want it or a tool like it.

Once your survey is complete, I have already walked the building at least 3 times if not more. First to get the details for my map, second, to perform a Layer 1 survey with a spectrum analyzer and then another with a Layer 2 survey.

Now it’s time to deploy your APs! Where are they being placed, how are they being mounted, how are you powering them up? There are many many considerations when deploying APs. I will typically mount APs in the ceiling when possible and will prefer to use Power over Ethernet to power up the devices and using APs with internal antennas. Now there will be special cases where you will want to use APs with external antennas.

During the survey and installation process a big issue is channel allocation. For the 2.4 GHz band, there are only 3 non over lapping channels. You need to make sure that your APs are using these channels and are all being separated from each other. There is nothing worse than causing your own interference problems by placing 2 APs on the same channel right next to each other! Technologies such as RRM are a big help in this regard.

Whew! That is a lot of work and we are just getting started! Now this is just the survey and installation of a Wireless network. There are many other design aspects, such as what kind of security to use. Ah, security. You can't leave your wireless network without it, unless you want a pounding headache that not even morphine can cure! There are 2 aspects to security in Wireless. The first security aspect is authentication. You want to know who is on your network and permit who is and is not allowed to use it. Authentication is the mechanism to do this. There are various forms of authentication. The most popular are Open, which is basically no authentication, mac address authentication, although it is not scalable and very easy to spoof. Then we have EAP (Extensible Authentication Protocol). With EAP, there are various flavors and the Wireless Specialist will be familiar with those flavors and be ready to implement whatever their customer requires. The most popular EAP methods being:

EAP-TLS - which is certificate based
PEAP - uses user credentials passed through a secure tunnel
EAP-FAST - similar to EAP-TLS but does not use certificates, it uses a Pac file instead.

The second part of security is encryption. Typically in today’s networks, TKIP or AES encryption are used. If no encryption is used, it really isn't too hard to sniff traffic out of the air and see what is going on in the wireless world around you. Because I am paranoid, I will typically use a VPN when connected to a public Wi-Fi hot spot, just to provide encryption.

When choosing a security type, there are many considerations. The main consideration is "do your clients support it"? It won't do you good to choose EAP-FAST if your clients don't support it. PEAP and EAP-TLS, WEP and WPA-PSK are the typical methods that most clients support.

Wireless security doesn't stop there. Remember that the wireless network is an extension of the wired LAN and so you need to not only secure the clients and APs via the air, but you need to take measures to secure your APs on the wired side as well. One of the most deadly threats are rogue APs. You know, the APs that are not a part of your network but are seen by your network, either over the air or on the wire. Things like rogue detection, ACLs, MFP, vlans & firewalls, RADIUS servers, weather its ACS, IAS or some other kind of RADIUS server and the Wireless LAN Controller are all used to help protect your wireless network.

Once the WLAN is installed and secured and users are using it all is well, right? Maybe, hopefully, but there may be times where there are problems and you will need to troubleshoot what is going on.

Now, troubleshooting wireless is a little different than your standard wired network. Why? Unless you’re Superman, you can't see the physical layer. Part of troubleshooting a wired network is checking your physical layer. Well in wireless you need to use tools to help you detect and mitigate interference. One tactic is to use the 5 GHz band. Since most interference sources reside in the 2.4 GHz band, I try to use the 5 GHz band whenever I can. I also suggest to clients to try to get wireless devices that are dual band. There are a surprising amount of devices that claim that they are 802.11n, but only support the 2.4 GHz band. A great troubleshooting tool that helps with interference is Cisco's CleanAir technology that is found in their newer APs. These APs have a spectrum chip in them that help identify the interference sources, such as Bluetooth, analog cameras, microwaves and so on.

Also, look at the load of your APs. Remember, APs are half duplex like hubs and are a shared medium. The more clients on your AP, the slower it will get.

What else does a wireless specialist do? Well what is the point of having a wireless network? Usually it’s for mobility reasons. There is little point in having a wireless network if you don't need to roam around and be somewhat mobile. Things like roaming come into play, weather its setting up mobility groups on a controller or using WDS on an autonomous solution. Being mobile is what makes wireless so cool. A wireless specialist is going to make sure that mobility is one of the basic functions of your WLAN and that it works well.

As we live in the days of Unified networks, it won't be too uncommon where Specialists of various areas will work together to create the network as a whole. A Wireless Specialist may work with a Security specialist regarding wireless security. The Wireless Specialist may work with a Routing & Switching Specialist to tie in the WLAN to the wired back bone. The Wireless specialist may work with a Voice expert when a customer requests Voice over WLAN services.

A wireless specialist will also work with outdoor wireless such as MESH and wireless bridging. Although there seems to be many general areas of a wireless specialist and there are, the wireless specialist works with RF as the physical layer to deliver the same applications that we are used to using on the workstation that is plugged into the wall. As wireless continues to explode, you will continue to see a demand for the wireless specialist out in the field. All of today’s coolest gadgets are all wireless devices and they are not going away any time soon!

Ref:
Wireless Specilaist