Can you imagine a world without zippers ? The Wikipedia entry about Zipper describes it
as a "slider that brings together two sides". We took that concept and brought together
our network configuration management product (ZipTie) and a security audit tool (Nipper)
to bring you Zipper - providing end users with security audits of their configurations!
Nipper stands for "Network Infrastructure Parser", an open source tool that performs
security audits of network configuration files. The report produced by Nipper includes
detailed security-related issues with recommendations and a configuration report.
The ZipTie-Nipper integration - a.k.a Zipper - enables users to run Nipper against
device configurations that ZipTie has backed up. All the user has to do is "right-click"
on the device, select the "Nipper" option, and voila : A Nipper Report is generated for
the device's configuration. Now the user can inspect Nipper's security audit and make
appropriate changes to the device using ZipTie to remediate any issues that Nipper might
have reported (see screenshot).
Now, how can you get your hands on the Zipper ;-) ?
Detailed instructions on downloading and installing Zipper can be found in our Documentation
Wiki under the NipperIntegration topic.
Nipper supports the following devices : IOS routers and switches, CatOS switches, Cisco
content switches (CSS/ArrowPoint), Cisco security appliances (PIX, ASA, and FWSM) and
Juniper's ScreenOS (formerly NetScreen), all of which are supported by ZipTie. More
information about Nipper can also be found at Titania and Sourceforge.
And finally, from now onwards, if your boss gives you a tough time about vulnerabilities
in your network, ask him or her to zip it !!
Cheers,
Kartick Suriamoorthy
ZipTie Community/Product Manager