qtslogo10.gif (7142 bytes)
ad1.gif (2831 bytes)
hvl_home.gif (1239 bytes) hvl_about.gif (1244 bytes) hvl_techres.gif (1285 bytes) hvl_customers.gif (1285 bytes)
hvl_stay.gif (1256 bytes) hvl_contact.gif (1236 bytes) hvl_sitemap.gif (1230 bytes) hvl_jobs.gif (1261 bytes)

February 2004  

Volume 4 Issue 2

February 23, 2004

To view this update as a Web page, copy this link into your browser: http://www.qtsnet.com/stayinformed/quiknews/quiknews_february2004.htm.

To subscribe or unsubscribe, please follow instructions at the bottom of this page.


Welcome to the February edition of QTS QuikNews, our monthly e-mail newsletter. In this monthly e-mail, you will receive an update of what's new at QTS - new products we support, new patches and upgrades, solution ideas and promotions to save you money, and information about our company and our clients.

In this issue:


QTS NEWS

QTS OFFERS FREE SYSTEMS STRATEGY CHECK-UPS
Having developed this unique engagement jointly with Microsoft, QTS is now offering Systems Strategy Check-Up engagements to qualified customers and prospects throughout New Jersey and New York.  This high-value, half-day consulting engagement helps businesses evaluate how they are using Microsoft technologies and identifies best practices and recommendations for how to best deploy Microsoft technologies in a business.  For more information on this no-charge engagement, contact your QTS Account Manager.

WELCOME ABOARD, AND BEST WISHES
There has been a lot of activity at QTS over the last month.  Please join us in welcoming aboard:

        Rohan Robinson, who joins us as a Systems Specialist and will work out of our Customer Support Center after a few years at IBM.

        Will Kang, who joins us as a Senior Systems Engineer on the project team, after working on the Active Directory/DNS migration at Johnson & Johnson;

        Rob Grayson, who joins us as a Senior Systems Engineer on the project team, after working as a Microsoft/Citrix specialist for another New Jersey integrator.

Also, two QTS �old-timers� are moving on to new positions outside of QTS.  Please join us in wishing Paul Sawchuk and Ernie Forsyth the best of luck in their new careers.

QTS IS HIRING!
QTS is recruiting for senior level technical personnel, as well as entry and senior level sales staff/telemarketers.  If you know anyone who might be a good fit, please have them submit their resume to Liz Meechan, our Office Manager. Liz can be reached at lmeechan@QTSnet.com, or (973)984-7600 x223.

SUCCESS STORIES

WILENTZ, GOLDMAN & SPITZER
QTS helped one of New Jersey�s largest law firms move to Windows 2000 Server, Exchange 2000 and Active Directory.
http://www.qtsnet.com/about/success stories/wilentz success story.pdf

PRESS RELEASES

QTS AND MICROSOFT LAUNCH PHASE TWO OF SYSTEMS STRATEGY CHECK-UP CAMPAIGN
2/23/2004: QTS announced today that QTS and Microsoft have concluded the �pilot� stage of their joint Systems Strategy Check-Up initiative and are moving into a broader second phase of the campaign based on initial successes.  Read more at http://www.QTSnet.com/stayinformed/l3_stay_pr48.htm

Back to Top


EVENTS

No new events have been scheduled.

Back to Top


PRESIDENT'S CORNER

Every so often, a paradigm shift occurs in the way companies use technology, and in the technologies vendors deliver to customers.  One of the more significant recent shifts is the �Clientless VPN.�

A clientless VPN is just what the name implies � a VPN where there is no client software on the PCs connecting to the VPN.  A VPN, after all, merely encrypts data transmitted between systems, based on successful authentication (login) to the VPN.  Traditionally, implementing a VPN requires a VPN endpoint (often the firewall) and then VPN client software on each remote PC being connected.  This technology is based on an industry standard, IPSec, for how systems authenticate and encrypt data.

Security is a major consideration when implementing VPNs, particularly on the client side.  Once a PC connects to a VPN, that PC is an extension of the LAN.  This has some major issues.  First, any viruses, worms or hostile code on the PC can now travel onto the LAN.  Second, if the PC is hacked or hijacked, the attacker can now ride a secure, encrypted tunnel through the firewall and into your network.  Lastly, patch management becomes an issue in making the remote PC vulnerable to attack, and thus your network vulnerable as well.  So all VPN clients need to have (1) personal firewall software, (2) antivirus software with current signatures and scan engines and (3) current patches for operating systems and applications.  Managing these three elements for dozens, hundreds or thousands of remote computers can be a real headache, or worse.  Another undesirable side-effect is the lack of flexibility � only computers that are running VPN client software, properly configured, can connect.  Like most security measures, this has its pros and cons.

However, SSL encryption is an alternative approach that has been in use for some time, mainly on web servers.  With SSL, client (typically a browser) is programmed to trust servers with digital certificates from �Certificate Authorities� they have been programmed to trust.  These �Trusted CAs� act like a passport office, vouching for the electronic identity of the business and its web server.  For example, if your browser trusts Verisign (which it undoubtedly does), and Verisign trusts QTS (because we pay them a fee to verify us and do so), then your browser trusts QTS.  When you connect to our site (in this example) the browser recognizes the digital certificate, establishes an SSL connection (on port 443 rather than 80, via redirection most likely) and the connection becomes encrypted (which you can tell from the little lock icon in the lower right of your screen).  This is how eCommerce sites protect your identity.

An operative point here, however, is that nothing special is configured on the client PC.  The PC merely has a browser, which is by default an SSL client.  So virtually any PC, on any network, can leverage SSL for encryption.  However, because computing can still be local, the same security issues exist around antivirus, personal firewall and patch management.

It is interesting how the SSL VPN market went from a niche market to a gold rush in the past year.  People had been implementing traditional client to site VPNs for the last few years, and this drive had achieved a level of critical mass.  However, the SSL VPN turned this upside down by accomplishing fundamentally the same result, with less work and more flexibility.  Some vendors built their own SSL VPN appliances � Netilla and Neoteris were early leaders here.  Others, like Symantec, bought companies that had such appliances, and integrated them into the product line.  Cisco is adding this capability to its VPN Concentrator product, so the device can either be an IPSec or SSL VPN endpoint.

SSL VPNs are particularly powerful when combined with �thin client� technologies such as Microsoft Terminal Services and Citrix MetaFrame.  With thin client technologies, remote users are simply viewing a screen of a remote host session, and sending keystrokes and mouse clicks to that session.  No computing is actually occurring locally, and bandwidth needs are minimal since screen images are easily compressed, and keystrokes and mouse clicks are very small amounts of data.

The advantages of combining these approaches are significant.  The IT organization now no longer needs to worry about the condition of the remote systems connecting to the network, because nothing is actually happening on those systems.  They are just screens and keyboards.  So they don�t necessarily need to be running personal firewalls, current antivirus software, or current security patches (though of course this doesn�t hurt).  This significantly lowers the work required of IT to facilitate remote connectivity, while improving an organization�s security posture (by removing the points of vulnerability beyond the firewall � the firewall is returned to being the true perimeter of the network).

Citrix offers a nice end-to-end solution in this space, with MetaFrame XP.  Included in the software, at no additional charge, are two components that build exactly this solution.  Citrix Web Interface (formerly known as NFuse Classic) is a web front-end that allows a browser to connect to a back-end MetaFrame server through a web login page, and after authentication be presented with a list of applications or desktops he/she has rights to use.  The ICA client, a single DLL, is auto-downloaded, and the application or desktop opens inside the browser.  It is a totally clientless solution, and can be integrated with strong authentication solutions such as RSA�s ACE/Server and SecurID tokens.  Citrix Secure Gateway adds the SSL encryption to the web server(s).  Thus a company can deploy secure remote access to dozens or hundreds or thousands of users, without ever touching the remote systems (and in fact, this provides complete flexibility to use any Internet connected system).  Server placement and firewall rules are critical in architecting this solution, to properly secure it.

As a point of interest, this approach was particularly appealing to one of our law firm clients, because many of the attorneys had spouses who worked for other firms and already had VPN clients on their home PCs.  Adding another, competing VPN client and personal firewall to those systems would have created support issues that make me shudder to think of.  The clientless VPN solution made that all into a moot point, and wiped out the need to add staff to support the solution.

I am absolutely convinced that this combination is a major, positive change our industry has taken, and almost all major players in this space have recognized it.  I suggest you give some consideration to these needs, and to how you currently provide remote access to your systems.  This approach is a winner.

As always, feel free to email me your comments or thoughts at nrosenberg@QTSnet.com. Thank you.

Neil Rosenberg
President & CEO
Quality Technology Solutions

Back to Top


PARTNER SPOTLIGHT

This month QTS is spotlighting its business solutions partner, AKA Enterprise Solutions. AKA is a highly focused solution provider that provides services around Microsoft Business Solutions � currently, the Dynamics (formerly Great Plains) accounting systems, and Microsoft CRM. These solutions are a great fit for most of QTS� mid-market customers.

For more than a decade, AKA Enterprise Solutions has been a leading partner dedicated to the sales, consulting, service and support of Microsoft Business Solutions. AKA Enterprise Solutions provides solutions that address Enterprise Resource Planning (ERP), Customer Relationship Management (CRM), e-Commerce and Business Process Consulting and Custom Application Development.

AKA�s dedication and focus on the Microsoft Great Plains and Microsoft CRM products benefits their clients by providing increased access to knowledge and dedicated resources for all areas of customer care. As a certified Microsoft Business Solutions partner, AKA shares Microsoft's commitment to long lasting customer relationships exemplified by a 93% client customer retention rate and consistently high satisfaction ratings.

AKA Enterprise Solutions has been the recipient of numerous industry awards and national honors that serve to reflect the combined talents, innovation, and enthusiasm of the team members. AKA was the 2001 recipient of the Eagle Award, the highest award given to Microsoft Business Solutions partner organizations recognizing strong leadership, a commitment to excellence and extreme dedication to customers and partners. Of the 4,000 Microsoft Business Solutions partners worldwide, AKA is routinely ranked within the top fifteen companies in the world. As part of their dedication to Microsoft Business Solutions, AKA has maintained the only North East certified Microsoft Great Plains Education Center for the past three years.

As an InterDyn company, AKA Enterprise Solutions offers clients the advantage of specialized talents and industry expertise of each of our locations to maintain the highest quality of customer care services. With more than 500 certified professionals in locations around the world, InterDyn supports over 3,500 customers- making us the largest, most comprehensive, and most experienced Microsoft Business Solutions partner worldwide. For more information about AKA Enterprise Solutions visit http://www.akaes.com, or contact your QTS Account Manager.

QTS and AKA Enterprise Solutions work together for our customers to build new solutions that create competitive advantage, reduce costs or create opportunity - with QTS providing the infrastructure and AKA the software solutions, in a highly integrated fashion.

Back to Top

Visit www.QTSnet.com for company information.

QUIKSECURE TIP OF THE MONTH

Each month, we now provide a security recommendation to our QuikNews readers based on content from our recent QuikSecure Security Assessments.  One of these reports typically includes 100-200 specific recommendations such as this, but we�re providing some �free advice� here to our readers.

ISSUE � Is web site data located on the C drive of your Microsoft IIS web servers?
 
IMPACT � Browsing users hit the drive containing the data, and can utilize hacking technique to traverse to the web server software and/or operating system.  If the operating system and web server software is on a different drive letter, it is much harder to attack the server.

RECOMMENDATION � Move your sites and content to a different drive letter.

Back to Top

PATCHES & UPGRADES

Call the Customer Support Center to have us apply QTS-standard patches and keep your systems current. The following patches have been recently released and are generally recommended by QTS:

* New Security Updates are available in February for Symantec ESM, ITA, VA, Manhunt, SGS and HIDS, in addition to January updates for NetRecon and Incident Manager.
* Microsoft Cumulative Security Update for IE 6 SP1.

Also, please click here for applicability of Microsoft Security Bulletins to the products in use at your environment. Contact your QTS Account Manager if you would like our Customer Support Center to monitor these bulletins for you and advise with recommendations for your environment upon release of new bulletins.

Note that Microsoft has moved to releasing security patches on the second Tuesday of each month, starting last November. New Security Updates to Windows and Office are available, and recommended.

Symantec (formerly Norton) Antivirus Corporate Edition signature files are currently at version 602220g (2/20/2004). CA InoculateIT 4.x signature files are currently at version 46.11 (2/20/2004) and 6.x signature files are currently at version 23.64.11 (2/20/2004). McAfee VirusScan / NetShield signature files are currently at version 4326 (2/18/2004). Please keep your antivirus signatures, and your scan engines, current! If you do not have your system set up to automatically distribute updates from your server to your PCs, please call your QTS Account Manager or the Customer Support Center.

Some patches can cause problems, especially in combination with other software programs or patch levels. Please talk to us to verify whether we see any possible problems in your environment before patching your systems independently. We make best efforts to test patch combinations but cannot guarantee compatibility between software and hardware manufacturers� products.

Back to Top

PRODUCT SUPPORT LIFECYCLE WATCH

The following products are pending �end of life� status by their manufacturers, and therefore customers should be planning for system upgrades or replacement.

* Windows 98, Windows 98 Second Edition and Windows ME have had support extended by Microsoft through June 30, 2006.  This covers paid incident support and security hotfixes.
* Windows NT Workstation 4.0 Service Pack 6a security support has been extended to June 2004.  NT Workstation reached end-of-life for normal support in June 2003.
* Windows NT Server 4.0 non-security hotfix support ended on 12/31/03. Security hotfixes and paid incident support will end on 12/31/04.
* Mainstream Support for Exchange 5.5 ended on 12/31/03.
* Microsoft Proxy Server 2.0 reached the end of Extended Support on 12/31/03.
* Microsoft Office 97 and Outlook 98 reach the end of Extended Support on 1/16/04.
* Novell Account Management 2.1 reached end of life on 12/30/03.
* Novell GroupWise 6.0 will reach end of life on 8/4/04.
* Novell NetWare 4.2 will reach end of life on 6/1/05.

Please remember that end of life for a product does not only impact that product, but also other products that interact with it.  For example, end of life status for an operating system means that no new software products that are released will run on that operating system, as the manufacturers will no longer receive support from the operating system vendor.

Back to Top

SOLUTION SPOTLIGHT: SURFCONTROL MAIL FILTER

SurfControl Mail Filter is technology that lets you control inbound and outbound email, by applying content filtering rules.  SurfControl Mail also includes a robust anti-spam agent which classifies possible spam based on a comprehensive database of spam signatures, as well as on content rules you can create.  It is a logical complement to, and enforcement tool for, your Information Security Policy.

SurfControl Mail Filter runs on a Windows 2000 or 2003 Server, ideally situated in your DMZ.  As such, it can serve as an SMTP "screening server" and act as the recipient of Internet mail for your organization.  This way, mail is content screened before it reaches your internal mail server, thus protecting that server from access directly via the Internet, and reducing disk storage needs on that server.

Rules can be granularly configured based on message headers and/or content, and on a wide variety of criteria.  The anti-spam agent performs daily downloads from SurfControl's database of spam signatures.

For more information, click here.

Back to Top

SPECIAL OFFERS

MICROSOFT PROMOTIONS
Microsoft is offering a 20% discount on ISA Server when purchased with Software Assurance, from March through May 2004.  Contact your QTS Account Manager for more information.

SYMANTEC PROMOTIONS
Symantec is currently running several promotions, on the following products:

* Symantec Client Security upgrades from SAV Corporate or Enterprise Editions � up to 70% discount on Gold Support renewal;
* Symantec DeepSight Alert Service;
* Symantec Gateway Security 5400 Series Competitive Upgrades.

Contact your QTS Account Manager for more details.

CISCO PROMOTIONS
Cisco is offering special promotions for new Cisco customers who purchase $5,000 or more in Cisco equipment, and also is running a competitive upgrade program for switches. Contact your QTS Account Manager for more details.

SURFCONTROL PROMOTIONS
SurfControl is offering a number of promotions, including bundles with its Instant Message Filter software.  Contact your QTS Account Manager for more details.

Back to Top

QUIKNEWS ARCHIVES
For access to past issues of QTS QuikNews dating back to January 2001, click here.

Back to Top

 

SUBSCRIPTION INFO

This newsletter is distributed to QTS clients, recent contacts, and "friends of QTS." We respect your privacy and never share your contact information with others.

To Comment on this newsletter, send an email to QuikNews@QTSnet.com.

To Remove yourself from this mailing list please send a reply to this message with the word UNSUBSCRIBE in the subject field, or contact your QTS Account Manager.

To Subscribe to this Newsletter, go to http://www.qtsnet.com/contact/QuikNews.htm.

To View an archive of QTS QuikNews newsletters, please visit http://www.QTSnet.com/stayinformed/QuikNews/QuikNews_Index.htm.

(c) Quality Technology Solutions, Inc. All rights reserved.

Quality Technology Solutions, Inc.
201 Littleton Road, 2nd Floor
Morris Plains, NJ  07950

Tel: (973)984-7600
Email: QuikNews@QTSnet.com
Web: www.QTSnet.com

Back to Top


This site last updated 08/31/07
� 1999 Quality Technology Solutions, Inc.
201 Littleton Road, Morris Plains, New Jersey 07950
telephone: 973.984.7600       fax: 973.984.7650
email: info@qtsnet.com