Books for/about - firewalls


 

 
Cisco ASA and PIX Firewall Handbook, First Edition

Publisher: Cisco Press
Authors: David Hucaby

ISBN: 1587051583
List Price: $60.00
Amazon Price: $37.80
Usually ships in 24 hours

Buy this book 
from amazon.com

or from
amazon.co.uk

Avg Cusomer Rating: 5
Reviews:
Summary: Excellent Coverage of Cisco FWs
Cisco ASA and PIX Firewall Handbook (ISBN 1-58705-158-3) by David Hucaby is an intermediate to advanced level book on Cisco firewalls. It primarily concentrates on the Cisco PIX firewall (which now apparently is becoming known as Cisco security appliance) but also provides coverage of the Firewall Services Module (found in Cisco's high end switches) and the IOS software firewall. Simply put, the author does a superb job of presenting a complex and broad subject in relatively easy-to-understand terms. Nevertheless, if you do not have any experience with Cisco firewalls, this book is not for you. Rather it is meant for someone who has been working with PIX firewalls but wants to gain a better and more in-depth understanding of the subject matter with an eye towards how to get something done - hence the term "handbook" in the title of the book.

If you're sitting at a bookstore browsing through a number of books on PIX firewall trying to decide which one to buy, skim through chapter 3 in this book. If you're really pressed for time, read through the coverage of VLAN hopping and firewall topology considerations in this chapter. If you're still not impressed by level of knowledge that the author brings to the table, either you already know so much that you don't need this book (and probably should think about writing one yourself if you're half-way-decent in conveying your ideas) or the material is too advanced for you and you'd be better off getting an introductory book on the topic. For an average network security engineer responsible for maintaining the Cisco firewall series of appliances, the material presented in this book is invaluable (and up-to-date).

Of course the material is not always revelatory throughout the book. There are sections which present information that most Cisco admins would already know. But nevertheless the author uses certain stylistic practices which are most helpful in understanding the differences between various areas of coverage. For example, for every command presented in the book, the author makes it a point to lay out the syntax for PIX v. 6.3, PIX v. 7.0 and FWSM next to each other. Further, whenever necessary, the author highlights the additional functionality found in version 7.0 and how it differs from version 6.3 in the PIX firewall. For example, the coverage of FW contexts (virtual FWs), new in version 7.0, is covered in sufficient detail - enough so that the administrator can actually implement it in his/her environment if needed. (By the way, this section is a good illustration of the author's knowledge about the inner workings of the Cisco firewalls and provides for an enlightening look at how traffic actually passes through the FW.)

In all fairness, I must point out that I was little disappointed in not finding any coverage of VPN tunnels in managing/administering the FWs. There is hardly any coverage given to the topic of remotely managing FWs (on the outside interface) while (IMHO) it happens to be a critical element of any FW administration scheme. Even though the author refers the reader to another book (Cisco IPSec VPN Handbook) for coverage of VPN functionality, I feel that the topic of FW management is simply not complete without discussing remote management - and tunneling is necessary when management has to be done from the outside. Nevertheless, I hope that the author can take this into consideration if a decision is ever made to issue a second edition.

Overall, this is a must-have book for any Network Security Engineer working with Cisco FWs. I highly recommend it and look forward to reading other books by this author.

Summary: The Ultimate Handbook and Guide for any Firewall Engineers and Administrator
I do not think the subtitle "The Complete Guide to the most popular Cisco firewall security features" goes to the level of credit that this book truly goes too. David Hucaby did not only write a guide, he wrote a book that will clearly sit on my quick grab shelf right next to my desk for years to come (or until the next version). For as the introduction states "the book is meant to be used as a tool in every day activities." and that is clearly what it does. David wrote for both from the introduction and the structure of the book to the index, a complete guide and tool that deserves ranting and raving. As you begin flipping through the book the knowledge and understanding of how a security engineers or administrator operate becomes clear. While the structure alone being designed to support both chapters and sections within the chapters, help to ensure details are easily located and quickly referenced. Combine with the detailed index in this book, ensure he does not miss a beat. From the beginning you see the level of both understanding and time that was done when David wrote this book.

Not only is David's book designed to be more than a reference guide. By going through the step by step process and understanding, but it details numerous features, commands and methods to help individuals understand what they are seeing or expecting. While exploring the book I found several nice facts including a quick bit in chapter 3 "Configuring Interfaces" where David talks about Priority Queue and the differences between current 6.x and new 7.x code. As we have learned with PIX code up to version 7.x it was all best-effort, but then has begun to change for the future. Thus this section while small is an excellent section to show the detail packed and excellent example of why this book needs to be on every security engineers and administrators desk or bookshelf. Other features in this book is provide us the reader with excellent examples of the evolution of Cisco's firewall operating code as it moves from version 6.x to 7.x platform.

Cisco has begun to introduction new features and support new platforms like the Firewall Service Module (FWSM) and the new Cisco ASA into an already growing product line in high demand. With the book David spends time showing how the same configuration items behave with each different code level or hardware platform that Cisco has introduced and currently supports. This alone can clearly help any individual attempting to understand and compare Cisco Firewalls product lines. Yet while this is another excellent example of why the book is a must have, the final that comes to mind is the detailed Appendix's that David has included from a complete list of error codes for all PIX syslog errors or messages to A "Well-Known Protocol and Port Numbers" section.

At one point I found myself looking from chapter to chapter and spot to spot without realizing I was jumping around. Cause regardless of where you are in the book you too will find yourself jumping around to either review something or cross-reference an item. If I was to change anything in the book, it would be the cover cause the material is as perfect as possible considering the length and time clearly spent learning and comparing the differences that the book contains. Why do I say the cover needs to be changed you ask? Well I think that as a security engineer or administrator you will be referencing this material so much that the soft cover will become damaged and show the wear and tear that comes with true usage and appreciation of a book of this caliber.
Summary: A Cisco Security Manual.
David Hucaby demonstrated his flair for Cisco Security offerings with his clear and concise presentation of the Cisco Adaptive Security Appliance and Cisco PIX Security appliance. This book was surprisingly easy to read for such a highly technical text. Within the first three hours of my receiving the text, I had already gone through the first four chapters.

The layout of the text endears it to Cisco Solutions professionals. Organized into thirteen chapters, the text starts with a brief overview of firewall technology and quickly delves into Cisco IOS commands to demonstrate the concepts described. Hucaby presents the materials in a logical order, starting from Chapter one on firewall overview, chapter 2 reviews basic configuration options for the Cisco PIX and ASA platforms. Chapter three on connectivity explores interface and VLAN connectivity with specific examples. IP version 6 connectivity was also described here. The book moves into more device and user management and firewall policy settings in chapters 4 through five and discussed fault tolerance and reliability in firewall designs in chapter 7

Chapter eight provided more hands-on treatment of firewall reliability with an in-depth description of failover implementations for Cisco firewall load balancing appliance (FWLB).

Not a generic text on firewall or security, this book is essentially a Cisco Security Implementation manual and its title should be taken literarily. The material is presented in a manner that lends itself to junior to intermediate Cisco security device administrators. The deep emphasis on Cisco Technology in this volume, limits the texts utility to non Cisco device administrators and thus the over all reader base of the text.

A CCNP candidate or PIX firewall specialist is sure to benefit from owning a copy of Hucaby's book, as would CCIE Security certification candidates. If your job is to manage Cisco PIX, ASA and related devices, then owning a copy of Hucaby's text will be well worth it. Independent consultants will also benefit from the reference like collection of materials in this handbook.

If you expect this book to provide you with insight into generic firewall technology, you will find only limited help here. Also if you do not expect to implement Cisco Security solutions, you do not need a copy. The treatment on syslog, without any mention of the state of the art in syslog technology (syslog-ng) leaves one wondering when the book was written.

This is really a difficult text to review, given the excellent presentation skill demonstrated by the author in his presentation of the material, the ease with which one can get through the materials, the scope of the technical how-to, presented by the author, and yet, the obvious gap in presenting the state of the art in the industry as against just being Cisco centric.

I will rate this book 3 out of 5. A great book for Cisco professionals, particularly PIX, FWSM (firewall switch module), ASA and IOS security administrators, Cisco centric network designers and managers and aspiring Cisco Security certification candidates. Mostly of little use to non-Cisco professional.
Summary:


       search for firewalls at amazon.comamazon.co.ukgoogle.com

Silence on the Wire: A Field Guide to Passive Reconnaissance and Indirect Attacks

Publisher: No Starch Press
Authors: Michal Zalewski

ISBN: 1593270461
List Price: $39.95
Amazon Price: $26.37
Usually ships in 24 hours

Buy this book 
from amazon.com

or from
amazon.co.uk

Avg Cusomer Rating: 5
Reviews:
Summary: The best (most unique, most interesting) security book I've read, period.
I have an extensive library of computer security books, and this is by far the most interesting, most novel, most entertaining computer security book I own. I am actually going through each of the footnotes, reading every paper mentioned in the book. This books is not a textbook for system cracking or defending your system, like O'Reilly's Practical Unix and Internet Security (my second favorite security book). Instead Zalewski has gone somewhere entirely new, showing how your computer leaks information to other parties without 99.999% of the population realizing it. I do network security for a living, am a privacy fanatic, and figured I'd learn a few new things. I was overwhelmed by the amount of new information I learned. Reading this book was a humbling yet exhilirating experience. Some of the sections are written so clearly a lay person could understand them, but other sections assume a great deal of knowledge of computer lore, particularly TCP/IP networking. Buy this book, then run silent, run deep.
Summary: Recommended to the attention of technophiles with an interest in computer security
Silence On The Wire: A Field Guide To Passive Reconnaissance And Indirect Attacks by computer security and programming expert Michal Zalewski focuses upon fundamentals of computing so that even non-specialist general readers can understand network design and their own computing activities, becoming able to address computer security issues. Silence On The Wire follows the path of a piece of information from the moment the user's hand touches the computer keyboard to the instant when it is received by a remote party on the other end of the wire. Zalewski notes that security concerns don't simply stem from a set of isolated faults that can be worked around, but represent issues associated with every process and system, and therefore they need to be understood and studied within that broader and more comprehensive context. Informed and informative, thoughtful and thought-provoking, Silence On The Wire should be considered mandatory reading for all security professionals, and is enthusiastically recommended to the attention of technophiles with an interest in computer security for themselves and their associates.

Summary: This One Goes On The Short List of
Excellent!

Zalewski's book is packed with information. The level of detail and technical difficulty of a lot of the information seem to make the book geared more toward those already familiar with computer security and information warfare rather than security novices. Those who are familiar with computer and network security may feel that parts of the book are too basic or beneath the level they are looking for, but Zalewski generally has a goal in mind and is just laying the groundwork to build up to it.

Most people in computer security, and even home users with little understanding of network security, are familiar with the major types of overt attacks (viruses, worms, phishing scams, spyware, etc.) and the countermeasures to protect their systems (antivirus, antispyware, firewalls, IDS, etc.), but this book uncovers the ominous volumes of data that can be extracted and exploited using passive reconnaissance techniques.

The book is called a "Field Guide" in the subtitle and it reads more or less like one. It provides the information and details you need in the trenches to wage an effective war against information insecurity. This is one that I would dub a "must read" for anyone working directly with network security.

[...]
Summary:


       search for firewalls at amazon.comamazon.co.ukgoogle.com

Dr. Tom Shinder's Configuring ISA Server 2004

Publisher: Syngress
Authors: Thomas W. Shinder Debra Littlejohn Shinder Martin Grasdal

ISBN: 1931836191
List Price: $49.95
Amazon Price: $32.97
Usually ships in 24 hours

Buy this book 
from amazon.com

or from
amazon.co.uk

Avg Cusomer Rating: 3
Reviews:
Summary: fair
I bought this book based upon recommendations from the reviews. It didn't live up to the hype.

The information was O.K. but I found it missing detail on the different variations on where to install the device. It talked about rings of security but didn't really go into "detail" on how to set up different types.

Different types being a edge firewall, front firewall, back firewall, or parallel configuration.

Summary: It waited more!
I found that the book more entered deep on configurations of the ISA server with the Exchange server and the other applications as Web Cache.
Summary: Awesome book for the COMPLETE ISA installation
This book is a great book if your are putting in the full intended version of ISA 2004. If you are looking to put ISA in and not use all the features this book might confuse you. If you are a beginner with ISA this book is a great starting point. It will give you a good comfort level with ISA.
Summary:


       search for firewalls at amazon.comamazon.co.ukgoogle.com

Configuring Netscreen Firewalls

Publisher: Syngress
Authors: Rob Cameron CJ Cui Thomas Byrne Dave Killion Kevin Russell Chris Cantrell

ISBN: 1932266399
List Price: $49.95
Amazon Price: $34.97
Usually ships in 24 hours

Buy this book 
from amazon.com

or from
amazon.co.uk

Avg Cusomer Rating: 5
Reviews:
Summary: Great Entry-Level Book for Learning Netscreen Firewalls
Configuring Netscreen Firewalls by Syngress Publishing is a great entry-level book for learning how to configure and deploy Netscreen firewalls in the real world. Although there were a few technical and grammatical errors in the book, the authors did a superb job of introducing the reader to the world of Netscreen and ScreenOS. Considering the fact that there are no other books out there focusing entirely on Netscreen Firewalls (besides the NCSA/NCSP literature from Juniper), I would highly recommend this book to anyone looking for a technical resource on the Juniper Netscreen firewall product line.
Summary: Content is OK, but this book was rushed to the printer
OK, so I'm sitting here, reading about setting up my route preferences (I'm on page 289), and the sentence trails off into nowhere--literally, not figuratively. It simply . . . disappears. This book is rife with incomplete sentences (and therefore, thoughts and instructions are left incomplete), misuse of language (affect vs. effect), misspellings, etc. Why is this important? In a technical manual, details matter. So, when I'm reading a technical manual, and it's clear that the author and editors have not paid close attention to detail, the rest of the instructions are suspect.

Here is another example. There is an entire section on Policy-Based VPN Configuration, which is fantastic; however, Juniper has basically stated and written in the solution brief "How Different VPN Approaches Affect Site-to-Site Scalability and Connectivity" that Policy-Based VPN's are the least preferred method of defining a VPN, because of connectivity and reliability issues. This is important because this book does not describe the process for configuring the alternative types of VPN's--route-based or dynamic route-based--but merely lends a paragraph to the former and a sentence fragment to the latter. This is a huge oversight by the authors, and leaves the reader fingering through other manuals to properly configure the device.

A few positive notes, the chapter on the Netscreen product line was helpful and informative, the screen shots helped walk me through several rudimentary procedures, and I found it to be a pretty good review for dusting off my old NCIA certification.

Craig Lockhart, JNCIA-FW, CCSE
Summary: Excellent Book to learn Netscreen Products and for Cert!
As an IT specialist for over 5 years now I have studied several different products and gained many certifications. I have worked with other firewalls, which can often be complex to configure with inadaquet documentation. I really feel that this book does a great job of thouroughly explaining all of the content in a very straighforward manner. Although this book is focused on how to configure the Netscreen product line (can be used across any product using the ScreenOS) it is also an invaluable tool for gaining your JNCIA-FWB certification. The reason why this is so important for gaining this certification is that you really need to fully understand how to configure and use the device in order to get the certificaiton--not just memorize facts. In fact, after reading this book, brushing up your certification knowledge is very minimal. If you desire more certificaiton practice the author made a testing engine which is availible at http://www.boson.com/tests/jper.htm
Summary:


       search for firewalls at amazon.comamazon.co.ukgoogle.com

Essential Check Point FireWall-1 NG: An Installation, Configuration, and Troubleshooting Guide

Publisher: Addison-Wesley Professional
Authors: Dameon D. Welch-Abernathy

ISBN: 0321180615
List Price: $54.99
Amazon Price: $38.49
Usually ships in 24 hours

Buy this book 
from amazon.com

or from
amazon.co.uk

Avg Cusomer Rating: 5
Reviews:
Summary: The Best Check Point Book
If you must install or work with Check Point FW-1 NG, this book is a must have. I am a consultant working with a customer who was upgrading from 4.1 to NG. We had numerous small issues, many of which were not effectively addressed by CP support. The new Firewall was up and running flawlessly within a day of buying this book. Dameon ("Phoneboy") is the ultimate expert on all things Check Point, and he is an excellent communicator who has written a very easy to read book. This book will also stay close at hand as a reference anytime a FW-1 question comes up. I have to buy another copy, since the customer above refused to give it back after seeing how useful it was.
Summary: Excellent Resource For Checkpoint Firewall-1 NG Admins
Each chapter of the book starts off with describing what the reader will learn or accomplish by reading that chapter. This sort of information is helpful for allowing readers to skip information that may not be useful to them and find the answers they seek. Many of the chapters also contain FAQ's and sample configurations and illustrations to help reinforce the information.

The book tries to cover a very broad scope and apply to a wide audience. It contains information all the way from holding the readers hand if they are new to Checkpoint Firewall-1 NG to providing detailed troubleshooting and configuration steps for experienced Checkpoint administrators.

I have never administered a Checkpoint firewall personally, but I found the information mostly straight forward and understandable. Again, this is not a book one would typically read casually, but for anyone who administers a Checkpoint firewall or is looking at installing a Checkpoint Firewall-1 NG system this is an excellent source of information.

(...)
Summary: Excellent!!!!!
There is a book called `the Best Damn Firewall Book Period'. But it is the wrong title, this is the Best Damn Firewall Book.

The author bleeds info about fw-1.

If you need one fw-1 book, this is it!

Summary:


       search for firewalls at amazon.comamazon.co.ukgoogle.com

Cisco ASA : All-in-One Firewall, IPS, and VPN Adaptive Security Appliance

Publisher: Cisco Press
Authors: Omar Santos Jazib Frahim

ISBN: 1587052091
List Price: $70.00
Amazon Price: $70.00
Usually ships in 24 hours

Buy this book 
from amazon.com

or from
amazon.co.uk

Avg Cusomer Rating: 5
Reviews:
Summary: A good book for a good design
I was surprised to see that Cisco was able to publish a book about ASA configuration/implementation. The authors had done a good job in explaining how the commands work and what kind of configurations can be used to implement IPS/VPN solutions.

The book really helps to understand what kind of implmentation can be done by the ASA.

If you were to use ASA for your company, I would suggest to buy this book and go through the information provided. Its an excellent guide and well written by the authors.
Summary: Great book on the Cisco ASA
Cisco ASA : All-in-One Firewall, IPS, and VPN Adaptive Security Appliance (Paperback)
by Omar Santos, Jazib Frahim
ISBN: 1587052091
Lately there is a fashion to say that now the network layer has been secured and so application security rules and that is what we need to worry about. Nothing can be further from the truth, imagine if a VPN implementation is not working as desired is it possible to still have a secure application layer, I think not. That is why they are called layers as they work in perfect harmony with each other.
The book on Cisco ASA provides a very good understanding of the Adaptive behaviour of the next generation of cisco products which do the work of detection, prevention and combatting network threats. The book explains in a very lucid way to implement and configure a complex device which handles the work of a virus scanner, content filter, firewall and VPN.
Through various confguration examples and designs the book explains the complex task of troubleshooting and that itself is worth the price of the book. The tips on how to use the various debug commands to fine tune the device are invaluable and a must for any one attempting to tame this beast.
The coauthor Jazib Frahim, CCIE is a senior network security engineer in the Worldwide Security Services Practice of Advanced Services for Network Security at Cisco.
The coauthor Omar Santos is a senior network security engineer in the Worldwide Security Services Practice of Advanced Services for Network Security at Cisco.
I give this book 5 stars on a scale of 5, 5 being the highest. I strongly recommend this book.
Niloufer Tamboly, CISSP


Summary: Securing a Network the Cisco Way
Computer security would be really easy IF. If the computer were in a room by itself, if it wasn't connected to a communications line, and if no one ever brought in a floppy disk or other media. Unfortunately that's not the real world.

In the real world, we set up web servers because we want the outside world to come to them and get information, send us credit card information and more. Now, all of a sudden you have a different set of problems, how to let in all the people you want, and make it easy for them to do what they need, but keep out the bad guys who have other motives.

The Cisco Adaptive Security Appliance or ASA is a single integrated box that provides about as close to perfect security as can be had in today's world. Being 'Adaptive' means that the system can change to provide security against new forms of attack. It also means that the system is not the simplest thing in the world to set up, nor can it simply be installed and then ignored forever.

This book begins with a general introduction to Network Security and what the bad guys are doing. It then discusses the various major functions of the ASA: Firewall, Intrusion Prevention System, and finally securing your Virtual Private Network.

Both of the authors are current Cisco employees with a great deal of experience in security.
Summary:


       search for firewalls at amazon.comamazon.co.ukgoogle.com

Squid: The Definitive Guide

Publisher: O'Reilly Media, Inc.
Authors: Duane Wessels

ISBN: 0596001622
List Price: $44.95
Amazon Price: $40.41
Usually ships in 24 hours

Buy this book 
from amazon.com

or from
amazon.co.uk

Avg Cusomer Rating: 5
Reviews:
Summary: This book is awesome!!!
For the new comer I recommend to buy this book if your finding an alternative for Microsoft box like ISA or MSProxy 2.0.

Squid is robost and a very stable Proxy Server, you can use it even in Entreprise consumption..trust me I use it since 2001.

If your looking for technical books or documents about Squid, this is the one your looking for...


Summary: "The" book for Squid
Squid: The Definitive Guide by Duane Wessels is a great book for someone with aspirations of setting up and getting the most out of Squid. It is lengthy at just over 400 pages, but that is to be expected and desired in O'Reilly's "The Definitive Guide" series. One point worth mentioning is that Duane Wessels (the author, for those with short synaptic cycles) is the one who started Squid and still works on it today. Each chapter builds nicely on subsequent chapters, so there isn't any skipping around. If you're just looking to set it and forget it, this book is probably not for you. Otherwise, read on.

The first three chapters are pretty basic: history of Squid, downloading then installing. For those with no concern of going through downloading and installing, there is a nice section describing each configure switch and, while weighing in at a healthy 48 options, it may be helpful to have this as a reference.

Chapter Four, Configuration Guide For the Eager, is an often desired, but often left out chapter in technical books. By just reading chapters one through four, it is possible to have a fully functional setup of Squid, albeit not very secure or ready for the pounding of the masses. You will, however, begin to understand how Squid operates. This chapter discusses the most often used settings, such as: minimum/maximum size of cached objects, log files and ACLs to restrict addresses, etc.

Chapter Five, Running Squid, covers what you expect. It includes such topics as, boot scripts, chrooting and rotating log files. Again, basic stuff, but necessary for the sake of completeness.

Chapter Six, All About Access Controls, covers one of Squid's major powers and attractions, access controls. ACLs give the administrator extremely fine-grained tuning. Some of the choice highlights for limiting access to addresses/domains include, but not limited to: filter by subnet, MAC, IP address or administrator assigned group. Furthermore, regular expressions can be used to filter URLs or URIs. A most likely seldom used, but very cool, feature is the ability to filter by BGP AS (Border Gateway Protocol Autonomous System) numbers. HTTP request methods such as POST, PUT, DELETE, etc. can also be filtered. Filtering by time or restricting access by user name is also supported. Each topic is assiduously explained and leaves little to be desired.

Chapters Seven and Eight cover disk caching with chapter Seven being basic material and then Eight covering more advanced topics. Discussions on object pruning, size limits, cache replacement policies and many other cache optimizations are covered in these chapters and are necessary to thoroughly understand if you are situated in a relatively large environment or just want to squeeze every bit of performance from your Squid.

Chapter Nine, Interception Caching, covers transparent proxying. This chapter discusses the benefits (no need to configure clients) and drawbacks (cannot do user authentication) of implementing such a system. It then goes on to discuss how to configure Alteon/Nortel, Foundry, Extreme Networks, Arrowpoint, iptables, pf and ipfw to perform the routing to the Squid box.

Chapter ten, Talking to other Squids

Scalability is another favorable attribute of Squid. Running in parallel with previous chapters, this chapter details the advantages (load balancing and increasing your cache hits) and the disadvantages (security problems with having to trust neighboring Squids) of a caching hierarchy. In addition, it explains how to configure connect timeouts and other tweaks to keep Squids aware of when their siblings are down.

Chapter eleven, Redirectors, covers another great attribute of Squid. Redirectors can be used, among other possibilities, to remove advertisements in web pages or rewrite client requests based on their given URL or URI. This chapter details how they work, from a protocol level, and provides example configuration settings such as sending only specific users through the redirector or conversely, letting specific users bypass the redirector altogether.

Squid can be configured to use various user authentication methods to allow or deny access. Chapter Twelve, Authentication Helpers, covers these options. Squid can talk HTTP Basic, HTTP Digest and NTLM. Each type is well explained in how it works and detailed in how to setup.

Chapter Thirteen and Fourteen fully explain logging and monitoring. The logging chapter explains the type of information each log file catches, a full description of each error or information type (which is a great reference that I made full use of) and configuration directives that change what is logged or how it is logged. Monitoring Squid covers the Squid Cache Manger (A web front-end to many great statistics), a brief mention of using Squid-RRD and using SNMP. Such monitoring statistics include, file descriptor allocation, byte hit ratios, cache hits and cache misses and a wealth of other useful information.

Chapter Fifteen, Server Accelerator Mode, explains Server Accelerator Mode, which is also known as Surrogate Mode. It is a neat trick where Squid stills runs as a proxy, however, the Squid server is proxying the world (or a select few) to your server. One obvious advantage includes performance (or Slashdot hardening if you will). There are several config directives explained here as well as some gotchas.

Chapter Sixteen, Debugging, is the is one of the few chapters that I did not need to reference. Although, if you need to, there is some good information provided.

Appendix A comes with a config file reference that actually provides more information then the comments in the configuration file (Holy moley!...they better trademark that idea before other authors catch on!).

Appendix B briefly covers memory caching and optimization.

Appendix C shows how to use delay pools to limit user bandwidth.

Appendix D details file system performance benchmarks to show you filesystem and operating system differences.

Appendix E discusses running Squid on Windows using Cygwin.

Appendix F covers auto configuration of Squid clients to avoid needing to physically visit the many machines you administer.

In conclusion:

Pros: This is "The Book" for Squid. No skipping from chapter to chapter, the author was also the designer and still one of the maintainers, fuller descriptions of the configuration file directives that the configuration file comments. It is a great reference.

Cons: Really the only thing that I didn't like was that he only discussed HTTP proxying. There is a brief mention of FTP and SMTP, but only a couple of sentences. To be fair, in the preface he did mention that he would would of liked to written on these topics but didn't have time.


Summary: Well Worth The Wait
Back in 1998 when I was running my own ISP, Squid was a lifesaver because it allowed me to provide excellent web response to customers over a very modest upstream connection.

When I moved on to consulting Squid was the answer to a wide variety of client problems from employee Internet access control (Redirectors) to company website performance (Server Accelerator Mode) to plain old web page load times (Proxy Cache).

Now that I've moved in-house in a large corporation (30,000+ employees) and I've found out what commercial vendors are charging for their solutions to each of these problems, I have gladly used my knowledge of Squid to save us money.

Of course, that knowledge was not easily won, at least not for me. Because Squid was an open source project there was a lot of information available on the Web, but, of course, because Squid was an open source project, it was hard to find a definitive answer to my particular problem without asking a lot of dumb questions on newsgroups or making a lot of trial and error attempts tweaking compile time options, system changes and configuration file settings.

I have waited for this book for a long time.

I was concerned that it might be too detailed to be readable. Thankfully, Duane Wessels, the primary architect of Squid , has laid out this book to provide simple access at the Macro level. The chapter arrangement and organization are very intuitive. And yet the book still contains enough information to satisfy almost every question.

The one caveat I would make to a reader is to maintain situational awareness while delving into a chapter because, without noticing it, you can suddenly be confronted with pages and pages of configuration file details. There's no avoiding it, when a book says `Definitive Guide' on the cover you expect to have full coverage. It's just that the book is so lucidly written that the transition from high-level discussions to detailed facts might catch you un-aware.

And, really, it's that kind of feeling that lets you know that you're reading a very valuable text. I spent the first hour after I got this book skimming each chapter, happy at each additional topic I discovered. Then I went back and asked it the two hardest questions I have faced using Squid over the past year, in each case the answer was easily found and fully explained (Mr. Wessels deserves an award for making transparent proxying understandable).

The wait for this book was well worth it. I highly recommend it to any person working with, or thinking about working with, Squid.


Summary:


       search for firewalls at amazon.comamazon.co.ukgoogle.com

Essential Mac OS X Panther Server Administration

Publisher: O'Reilly Media, Inc.
Authors: Michael Bartosh Ryan Faas

ISBN: 0596006357
List Price: $49.95
Amazon Price: $32.97
Usually ships in 24 hours

Buy this book 
from amazon.com

or from
amazon.co.uk

Avg Cusomer Rating: 3
Reviews:
Summary: Not for Web Server help
If you are looking for OS X web server inside information, this is not it. Only about 15 pages, out of 800, discuss the web server. And the information on those pages mostly just covers the already intuitive interface. It would not be fair for me to dis the whole book based on this one gaping whole - but since that was the information I was looking for more information on, I was sorely tempted.
Summary: The most complete OS X Server reference around
Where this book shines is as a reference for obscure settings. For example:
I've been trying to replace a Mac OS X Client machine with a Mac OS X Server machine, but I needed to make AFP work the same way it did under Client (so some users are chrooted into their home folders while other users can access the enclosing sharepoint). Two days of beating my head against it, trying to compare com.apple.AppleFileServer.plist files and NetInfo records got me nowhere. Fifteen minutes with this book and pages 371-373 have solved all my problems. (It actually took me under five minutes to find the answer I needed, but the book was so interesting I read another ten minutes before I remembered I had a job to do.)

Bartosh may be a better author than he is an instructor, and he's a superb instructor. This book should be on every Mac OS X administrator's desk.
Summary: Best.OSX.Server.Book.Ever
If you run any level of Mac OS X Server, you need to have this book. Period. Run, don't walk. It's one of the most useful sysadmin references I've ever read, and within a week of me buying it, it showed me how to fix an Open Directory Replica problem I was having, along with explaining what the hell was going on to cause the problem. So not only did I fix the problem, but I know why the problem happened in the first place, all because of this book.

Any book that shows me the how, what, and why of a problem that fast is worth whatever it costs, and I'll be buying the Mac OS X 10.4 book as well.

Wait, here's another one...I helped write a book on shell scripting. If you have to pick between the two, buy this book.
Summary:


       search for firewalls at amazon.comamazon.co.ukgoogle.com


Computers and Electronics Books || Automotive Books || Misc Books






Computers and Electronics Books
| 3d | 3d animation | 3d graphics | 3d studio | 3ds max | Abap | Administrator | adobe acrobat | adobe after effects | adobe audition | adobe bridge | adobe golive | adobe illustrator | adobe image ready | adobe pagemaker | adobe photoshop | adobe premier | ADSL | amazon com books | apache | aplication server | Apple | asp | asp.net | autocad | avid | avid media composer | avid symphony | avid xpress | bind | BlueRay | C sharp | c++ | C++ Builder | Cambridge ICT Starters | certification | certification books | Cisco | Cisco BCMSN | Cisco BCRAN | Cisco BGP | Cisco BSCI | Cisco BSSC | Cisco CCDA | Cisco CCDP | Cisco CCIP | Cisco CCNA | Cisco CCNP | Cisco CCSP | Cisco CIT | Cisco CSIDS | Cisco CSPFA | Cisco DESGN | cisco firewall | Cisco ICND | Cisco INTRO | Cisco MPLS | Cisco QoS | Cisco SECUR | cobol | ColdFusion | combustion | Computer Associates | Computer Science | CORBA | css | db2 | deko | design patterns | dhtml | digital production | DirectX | DirectX9 | dll | dns | dns server | DVD | e-Learning | eBay | ECDL | ECDL Advanced | Final Cut | Final Cut Pro | firewalls | flash 8 | flash mx | Flash Studio 8 | fortran | game cube | Game Programming | Google | Graphic Design | graphics | graphics development | hacking | haking | Hardware | hardware hacking | html | Intel | internet | irix | isdn | J2EE | Jakob Nielsen | java | javascript | LDAP | linux | LSAT | mac | mac os | Macromedia | macromedia actionscript | macromedia dreamweaver | macromedia flash | Macromedia Studio 8 | mail server | mail servers | max 3d | maya | Microsoft Application Developer | microsoft c# | Microsoft Certified | Microsoft Database Administrator | Microsoft Desktop Support Technician | microsoft exams | microsoft excell | microsoft frontpage | microsoft iis | microsoft office | microsoft powerpoint | microsoft reader | Microsoft Solution Developer | microsoft sql server | Microsoft Systems Administrators | Microsoft Systems Engineer | microsoft visual basic | microsoft visual studio | microsoft windows 2000 | microsoft windows 2003 | microsoft windows server | microsoft windows xp | microsoft word | microsoft works | Mini DV | mysql | networking | Object Analysis and Design | ocx | Open Source | opengl | oracle | oracle 10g | oracle 9i | Oracle administration | oracle application server | Oracle programming | palm os | palm reader | pascal | pda | pdf | Photoshop CS2 | php4 | php5 | Pinnacle | Pinnacle Liquid | Pinnacle Studio | playstation | plc | pocket pc | PocketPC | postscript | powerbuilder | programming | samba | sap | SAP ABAP | SAS | sco | sco unix | search engines | smartphone | SOA | soap | solaris | sql | svg | sybase | tcp/ip | Telecommunications | telecoms | uml | Unisys | usability | User Interface Design | vb net | vb script | vbx | Video Games | Virus | Visual Studio 2005 | Visual Studio.NET | VoIP | web | Web Services | Web Usability | webdesign | website development | websites | WebSphere | WiFi | Windows 2003 Server | Windows Administrator | Windows XP Pro | Windows XP Profesional | Windows XP Professional | wireless networking | x-box | xhtml | xml | xslt | Yahoo



| home |