July 2008
S M T W T F S
« Jun   Mar »
 12345
6789101112
13141516171819
20212223242526
2728293031  
Links

Another “Day Zero” Balancing Act…

I feel kinda lucky I am able to write this blog entry… or at least to upload it to this site… This morning I woke up, fired up the old laptop, clicked on IE7 … and …. nothing.  Everything just kept timing out.
Huh… what to do…what to do… I tried different browsers…Firefox, Opera, Safari, Polstergeist… same ole … same ole…

The first troubleshooting step I tried was ipconfig… Yep… I did indeed have a valid IP address all right, and in the right range too…huh… Let’s try…  ipconfig /release;  ipconfig /flushdns;  ipconfig /renew… I got the same IP address I originally had and the same problem too… No web browsing happening here.

Then I tried pinging one of the web sites for my Delaware network support company;  good old www.adminassociates.com …. Huh… weirder and weirder… no lost packets… ping works, so apparently the DNS server is servin’ too but still, browsers don’t work.

Then I tried disabling my Zonealarm Pro Firewall (but turned on the Windows firewall, just in case).  Wow… the browser now works fine… so what’s up with Zonealarm?  I looked at everything and nothing seemed out of  spec. I felt it was odd since this particular firewall has never a problem for me… very reliable; very easy to configure…very trustworthy.  I re-enabled  Zonealarm, disabled the Windows firewall, moved the “Internet Zone” slider down from high to medium and the browser started working again. Move the slider back up and the browser stopped working again.

Like I said… weirder and weirder…so it’s definitely a Zonealarm problem, but why…What could have happened?   Aha… yes… two days ago was patch Tuesday. I’ll have to Google this, but first, what else I need to find out what else is happening in my world.

I went back to my working combo of Windows Firewall on and Zonealarm off and started my email client.  About the third message I received was from Microsoft talking about a major bulletin revision … not a patch revision mind you, just the bulletin:

Bulletin Information:
=====================

* MS08-037 - Important

- http://www.microsoft.com/technet/security/bulletin/ms08-037.mspx
- Reason for Revision: V2.0 (July 10, 2008): Bulletin revised to
inform users of ZoneAlarm and Check Point Endpoint Security
of an Internet connectivity issue detailed in the section

So, in the final analysis, downloading a newer version of Zonealarm (that apparently wasn’t available before today) solved my problem, but can you imagine if this happened at a corporate office with a couple hundred workstations?

I know not too many offices use Zonealarm, but what if they did?  What a pain to update 200 workstations, in emergency mode (read pressure), and probably with the expectation that it would (could) be completed in one morning.

This is just another example of why all patches should be thoroughly tested on a lab unit before being put into a production environment.

Now, I became a victim by not following my own advice, but that was on my personal laptop.  I create an image of the drive at least every couple of days and sync important files to my basement server so I am never in danger of losing too much, but it’s a real balancing act when you are responsible for for than your own machine.

On one hand, you want to wait for version 2 of all the patches… let someone else report the pain…and at the same time you know “Day Zero” is a real threat and today might just be that day.

I always make sure I get a really good full backup, especially on Monday nights… just in case.

Good luck and good networking !

From way down in the trenches…. I’m Tom

 

 

Custom Search

Leave a Reply

You must be logged in to post a comment.