Thursday, 23 June 2011

Drobo Dashboard v2.0.2 is now available

The new Drobo dashboard is available, which has a much slicker look and feel compared to the previous version.  The image below is taken from the Drobo.com website:

AllDevicesPage.jpg

The new dashboard allows you to manage multiple Drobo devices, rather than just one device with the previous version.  The only shortcoming is that from my netbook, the whole interface can't be displayed on my 1024 x 600 screen, as the bottom is cropped.  This has been reported to Drobo and I expect this to be resolved in a future release of the dashboard.

The downloads are available here: http://www.drobo.com/support/updates.php

Sunday, 22 May 2011

DroboApps and Firefly iTunes server

After following the instructions on the DroboApps website: (http://www.drobo.com/droboapps), I installed Apache and the DroboApps Admin Utility.

Using the DroboApps Admin Utility, I installed the Firefly application. I then changed the server name and the default password, and I was up and running.  Browsing to the DroboApps share, I dropped my music into the media folder within the Firefly folder.

The only issue was that my iTunes could not see the shared library!  A bit of searching found this Apple support article: http://support.apple.com/kb/TS2972

It seems that my software firewall was not allowing TCP port 3689 and UDP port 5353. Once opened up, iTunes instantly found the shared library.

All my music is currently being moved off my netbook, into the secure and resilient environment of the Drobo.

- Posted using BlogPress from my iPhone

Saturday, 21 May 2011

Introduction to DroboApps

There is a strong community of developers, creating applications for the Drobo devices.  The applications are called DroboApps, and the download files can be found here: http://www.drobo.com/droboapps/

Being new to DroboApps, I went against my technical gut instinct, and read the manual!  There is a very useful document highlighting how to install DroboApps, along with some installation examples: http://support.datarobotics.com/app/answers/detail/a_id/468

Having enable the DroboApps functionality on the appliance, I had a look through to see what I need to download, along with what I wanted to download.

Going through the DroboApps, I downloaded the following:
  • DroboApps Admin Utility
  • Apache (required for the admin utility)
  • Firefly (iTunes library)
  • Fuppes (Media server with DLNA support)
  • Lighttpd (HTTP server)
  • Pure-ftpd (FTP server)
As mentioned previously, the reason Drobo caught my attention previously, was the fact I could have more just two hard drives in an appliance, and that it could be my iTunes library.

DroboApps Admin Utility, Apache and Firefly will be installed soon.  I will document and review the features then.

Thursday, 19 May 2011

Introduction to the Drobo Dashboard and Configuration

The hardware was very easy to put together, and the software was just as simple to set up.  There are a lot of screenshots here, but you can see it was pretty much a case of "next, next, next" to get the dashboard installed.  Once installed, you will have the dashboard up and running.

1. Once the Drobo Dashboard software is installed and running, it is looking for Drobo devices.


2. The Drobo device is detected, but at this point my device was still starting up.


3. Clicking on the "Advanced controls" and looking at the "Data" tab, I can see what is in the device and it has correctly identified my four 1TB 3.5" SATA hard drives.


4. The "Tools" tab, offers a number of commands, alert settings, device settings and updates.


5. The dashboard shows how much free space I have and the shares available.


6. Expanding the "How is my storage being used?" shows more drive information.


7. As I selected the option to check for updates, this box somes up.


8. Clicking on the highlighted option to change the Admin password, shown in images 6 & 7 above, brings up the "Admin" under the settings.  There is also an option to enable DroboApps (which I plan to investigate more in the future)


9. By default, the Drobo device will protect your data in the event of one hard drive failing.  There is a option to enable dual disk redundancy, which will protect the data in the event of two drives failing.  It does use more hard disk space, but I guess it depends how important you data is.  As my device will be holding family photos and my MP3s, I will be enabling the dual drive redundancy.


10. On the "Network" tab, the network settings can be configured.  I will be setting this to match my internal network.


11. On the "Shares" tab, shares and users can be created.  By default, you have one share called "Public" and the administrative user called "Admin" by default.


13. On the "Email Alerts" tab, the email server information can be configured.


As you can see, the software interface is clear and concise.  Lots of features are available and seems much easier to configure that my existing NAS device.  Now the device is on my network, I will be investigating more about DroboApps.

Introduction to the Drobo FS

I had a surprise at work today, as a box was left on my desk.  Drobo kindly shipped a Drobo FS to me to test and use.

At e92plus, we have just started distributing the Drobo range of products and like any technical person, the technology interested me, but hands on experience with a product is much more fun!

A number of things drew my attention to the Data Robotics (Drobo) range of drive enclosures, even before we signed them up to distribute their products.  I was aware that different makes and sizes of hard drives could be used within one enclosure.  This goes against the things that I have learnt about RAID technology and have been using for over 17 years, but then again RAID is over 25 years old!!

I was also aware that some of the Drobo range would allow applications (Drobo Apps) to be run on the device, so it could be a web server, FTP server, iTunes server, etc.

There was a boast that it was easy to set up without the complex configuration normally associated with RAID systems.  I think I had a head start as I have worked with RAID for a number of years, as well as already owning a Netgear NAS appliance at home.  I've been looking to replace this with a device that support the storage of an iTunes library, which my current device does not do.

After plenty of research, I came to the conclusion that I need a Drobo FS at home, and all of this was decided before I was even aware of it at work.  It was good to see that something I had researched a while ago was not only good enough for home, but have a number of devices suitable for business uses.

Here's the box that arrived today:




The box contained a number of items:
  • Drobo FS Device
  • Drobo FS User Guide
  • Drobo Resource CD
  • Straight Ethernet Cable
  • AC Adapter
  • Power Cords (UK & European)
The device is very attractive, metal chassis and a plastic front bezel, held on with magnets.  It has a very good blend of aesthetics with a quality/sturdy build quality.  It felt very solid compared to the my existing NAS appliance.




The instructions on the box were very straight forward:


  1. Install Drobo Dashboard from the Drobo Resource CD
  2. Insert at least two 3.5" SATA hard drives, metal side up (Note: Any data on the drives would be wiped)
  3. Connect an Ethernet cable and the AC adapter, then follow the dashboard instructions






I had four 1TB SATA hard drives spare, so this is what I'm using as part of this test.

Software installation to follow in the next post:

Thursday, 10 February 2011

UAG Registry Keys

Found this TechNet section when looking for something else and it may be very useful to you.

Here are the registry keys used by UAG:
http://technet.microsoft.com/en-us/library/ee809087.aspx

The one that is the most use, especially carrying out proof of concepts and "real" certificates are not being used:

HKEY_LOCAL_MACHINE\SOFTWARE\WhaleCom\e-Gap\Von\URLFilter\Comm\SSL


By default Forefront UAG validates both the certificate and the revocation list of each SSL backend server during the TLS handshake procedure. In the event where the certificate or the CRL are not valid, backend users are denied access to that given backend server. If a Forefront UAG administrator wishes to disable those validation tests, set the ValidateRwsCert and ValidateRwsCertCRL key values to 0, and then restart the IIS service on the Forefront UAG server.

As UAG checks certificates and CRL, where IAG really didn't this can be new to most people who have experienced IAG.

Friday, 1 October 2010

ActiveSync and email on iPhones (and other ActiveSync devices)

Recently I’ve been asked a lot about ActiveSync for iPhones, but I try to highlight the security implications for this.

I have spoken with a number of people who have ActiveSync running on their Exchange Servers, where they can access the server directly from the internet. I’m not a fan of having servers on the LAN available from the internet, but the pressure to deploy the access this is often overlooked. Especially as the Microsoft IAG and UAG solutions will allow you to reverse proxy the ActiveSync connection, eliminating the need for a direct connection to the Exchange server.

Ensure the handset you have has a level of encryption on it, as the company can be subject to hefty fines from the ICO, if personal data is not encrypted. Apple iPhones have AES 256-bit hardware encryption to protect the data at rest. The Nokia E-series that I have investigate have encryption on both device and storage memory.

Although as this is protecting data at rest, ensure there is at least a password on the device, or there is no point having the encryption. Enforcing password on the device, and comprehensive password policies can be created on from the Exchange server.
 
What is the handset is stolen? There is the ability to remote wipe the mobile device, as well as enforce a wipe if there are too many failed attempts to logon to the device.
 
The only concern is a number of requests for this access on personal iPhones, which is a worry from a data leakage perspective. Although a number of places have said they will ensure password policies and reserve the right to remote wipe the device when it is required, then make their employees agreeing to this. Personally, I am not a fan of this and would rather be working with corporate devices, where as a business you have more “rights” to your hardware.
 
From a technical perspective, you will need to do the following:
  • Ensure ActiveSync is configured and running on the Exchange server, with the relevant password, encryption and wipe policies. Assign the access to the users who should be able to access it, taking care to remove access from everyone else (so they are unable to connect up unauthorised or personal mobile devices).
  • Configure an ActiveSync portal on IAG, or create a portal for ActiveSync on UAG.
  • Ensure all the Exchange server settings are entered correctly.
  • Apply a real SSL certificate to the portal, as some mobile devices will not allow you to except a self signed SSL certificate.
  • Publish the portal.
  • Test the ActiveSync by defining the server name, domain/username and password here: https://testexchangeconnectivity.com/
  • Expect it to fail on the OPTIONS section, but everything else should pass.
  • Configure your device to point to the newly created portal.
  • Allow device to synchronise and enjoy emails on your mobile device!