<?xml version="1.0" encoding="utf-8" standalone="yes" ?>
<feed xmlns="http://www.w3.org/2005/Atom">

	<title>blogs.bit10.net</title>
	<link rel="self" href="http://blogs.bit10.net/atom.xml"/>
	<link href="http://blogs.bit10.net/"/>
	<id>http://blogs.bit10.net/atom.xml</id>
	<updated>2008-07-25T16:17:06+00:00</updated>
	<generator uri="http://www.planetplanet.org/">Planet/1.0 +http://www.planetplanet.org</generator>

	<entry xml:lang="en">
		<title type="html">Has your Hotmail and Live Messenger been hacked?</title>
		<link href="http://www.benking.me.uk/2008/07/21/has-your-hotmail-and-live-messenger-been-hacked/"/>
		<id>http://www.benking.me.uk/2008/07/21/has-your-hotmail-and-live-messenger-been-hacked/</id>
		<updated>2008-07-21T18:27:41+00:00</updated>
		<content type="html">&lt;p&gt;I have in the past &lt;a href=&quot;http://www.benking.me.uk/2007/02/12/my-hotmail-has-been-hacked/&quot; title=&quot;My Hotmail has been hacked.&quot;&gt;posted&lt;/a&gt; about my experience when I got my Hotmail account hacked and how I subsequently recovered it. To save everyone the hassle of wading through my blog for the answer (and earn me a few quid hopefully), I have now written a handy document that helps you understand:&lt;/p&gt;
&lt;p&gt;1) Why and how your Hotmail/Live Messenger was compromised in the first place.&lt;br /&gt;
2) How to go about getting it back.&lt;br /&gt;
3) How to stop it happening again.&lt;/p&gt;
&lt;p&gt;All for a mere $10&amp;#8230; you can buy it &lt;a href=&quot;https://www.payloadz.com/go/sip?id=489237&quot; title=&quot;Hotmail Hacked - Recovery Guide&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;P.S. I appreciate the irony that if you have had your Hotmail account compromised you have probably lost your &lt;a target=&quot;_blank&quot; href=&quot;http://www.paypal.com&quot; title=&quot;Paypal&quot;&gt;Paypal&lt;/a&gt; account as well, so can&amp;#8217;t actually pay me! Unfortunately its a chicken and egg problem you will have to sort out, as I can&amp;#8217;t be arsed to set up another payment mechanism - sorry!&lt;/p&gt;
&lt;p&gt;&lt;a target=&quot;paypal&quot; href=&quot;https://www.payloadz.com/go/sip?id=489237&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://www.paypal.com/images/x-click-but23.gif&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</content>
		<author>
			<name>Ben King</name>
			<uri>http://www.benking.me.uk</uri>
		</author>
		<source>
			<title type="html">benking.me.uk</title>
			<subtitle type="html">The world according to Ben...</subtitle>
			<link rel="self" href="http://www.benking.me.uk/feed/"/>
			<id>http://www.benking.me.uk/feed/</id>
			<updated>2008-07-21T19:17:03+00:00</updated>
		</source>
	</entry>

	<entry xml:lang="en">
		<title type="html">Pizza Express Coventry - Food Fail 2</title>
		<link href="http://www.benking.me.uk/2008/07/04/pizza-express-coventry-food-fail-2/"/>
		<id>http://www.benking.me.uk/2008/07/04/pizza-express-coventry-food-fail-2/</id>
		<updated>2008-07-04T08:38:58+00:00</updated>
		<content type="html">&lt;p&gt;After our first food fail and followup discussion with the Pizza Express operations manager, Debbie Phillips,&#160;I thought that maybe we had the &lt;a target=&quot;_blank&quot; href=&quot;http://www.benking.me.uk/2008/06/27/and-while-we-are-at-it-pizza-express-coventry/&quot; title=&quot;Pizza Express - Food Fail 1&quot;&gt;issue resolved&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Last Tuesday&#160;evening we went back to test the&#160;theory.&lt;/p&gt;
&lt;p&gt;The first&#160;failure came early in the day when &lt;a href=&quot;http://www.senokian.com/barking/&quot; title=&quot;Jake Stride - Barking&quot;&gt;Jake&lt;/a&gt; popped in to check what time they were shutting that evening (their &lt;a target=&quot;_blank&quot; href=&quot;http://www.pizzaexpress.com/find-a-restaurant/restaurant/1461/?lat=52.40766&amp;amp;lon=-1.50846&amp;amp;pc=coventry&amp;amp;baby=0&amp;amp;takeaway=0&amp;amp;bar=0&amp;amp;meetingroom=0&amp;amp;alfresco=0&amp;amp;livemusic=0&quot; title=&quot;Pizza Express Coventry&quot;&gt;website&lt;/a&gt; says 10.30pm), Jake was in fact told they were shutting at 10pm that evening.&lt;/p&gt;
&lt;p&gt;7 of&#160;us turned up at 9.45pm (i.e. &#160;giving them a bit of slack), the conversation went like this (I have bolded the &lt;strong&gt;fails&lt;/strong&gt;):&lt;/p&gt;
&lt;p&gt;Me: &amp;#8216;Good evening, please can we have a table for 7.&amp;#8217;&lt;/p&gt;
&lt;p&gt;Pizza Express Waitress 1: &amp;#8216;Hold on I will just check.&amp;#8217; &lt;strong&gt;Fail 2 (The answer we were looking for was &amp;#8216;Yes of course, I will see what we have available&amp;#8217;).&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Pizza Express Waitress 1 (who from now on will be known as &amp;#8216;The Nice One&amp;#8217;) runs off and has a chat with Pizza Express Waitress 2&#160;(who from now on will be known as &amp;#8216;Short Angry One&amp;#8217;), there is obviously some debate as Short Angry One returns to talk to us.&lt;/p&gt;
&lt;p&gt;Short Angry 1: Yes you can come and sit over here.&lt;/p&gt;
&lt;p&gt;Me: Thanks, but that is only a table for 6 and its in the corridor, next to Kitchen, can we just go and sit upstairs.&lt;/p&gt;
&lt;p&gt;Short Angry 1: Sorry, the upstairs restaurant is closed this evening. &lt;strong&gt;Fail 3 (The answer we were looking for is &amp;#8216;Yes, no problem, please come this way&amp;#8217;.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Me: I am sorry I don&amp;#8217;t really want to sit in the corridor with one of us on the end of a table, please can we go upstairs.&lt;/p&gt;
&lt;p&gt;Short Angry One: No, as I said upstairs is shut. &lt;strong&gt;Fail 4 (We gave you a second chance, you should have taken the hint).&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Me: Do you mind if we have a quick chat in private&amp;#8230; (we both move to one side).&lt;/p&gt;
&lt;p&gt;Me: I wouldn&amp;#8217;t normally argue any further, but your boss, Debbie Phillips assured me that we would always be able to be seated upstairs and it would never be closed, now please can we sit upstairs.&lt;/p&gt;
&lt;p&gt;Short Angry One: I DON&amp;#8217;T CARE, I SAID UPSTAIRS IS CLOSED, NOW PLEASE STOP INVADING MY SPACE. &lt;strong&gt;FAIL 5 (Don&amp;#8217;t raise your voice to me or any other customer ever, plus you just passed up you third and final chance).&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Me: Okay, as you wish.&lt;/p&gt;
&lt;p&gt;We were shown to our &lt;a target=&quot;_blank&quot; href=&quot;http://www.benking.me.uk/2008/07/04/pizza-express-coventry-food-fail-2/pizza-express-coventry-table/&quot;&gt;table in the corridor&lt;/a&gt;. We then tried to shoot a video message (Tracy has blogged and posted it &lt;a target=&quot;_blank&quot; href=&quot;http://picklejarcommunications.blogspot.com/&quot; title=&quot;Picklejar&quot;&gt;here&lt;/a&gt;), and Pizza Express Waitress 3 (Slightly taller angry but marginally concerned one) told us to stop filming! Incredible!&lt;/p&gt;
&lt;p&gt;Anyway we ordered, and the food was good, so that was okay.&lt;/p&gt;
&lt;p&gt;We decided then to keep drinking and stay as long as we could (just to see how long it would take them to kick us out), we asked when they would be shutting the bar, they said 11pm, so at 10.55 we did the right thing and ordered a round, this consisted of:&lt;/p&gt;
&lt;p&gt;3&#160;x Double Jack Daniels and Coke&lt;br /&gt;
1 x Double Vodka and Red Bull&lt;br /&gt;
2&#160;x Peroni&lt;br /&gt;
1 x Coke (for the designated driver).&lt;/p&gt;
&lt;p&gt;Now I am willing to bet there isn&amp;#8217;t much change out of &#163;25 at Pizza Express prices, however Short Angry One said &amp;#8216;Sorry, I am not serving you anymore alcohol, you have had enough I think&amp;#8217;. Which we hadn&amp;#8217;t and was, IMHO, purely an act of bitterness.&lt;/p&gt;
&lt;p&gt;Sigh&amp;#8230; Another call to Debbie coming up.&lt;/p&gt;</content>
		<author>
			<name>Ben King</name>
			<uri>http://www.benking.me.uk</uri>
		</author>
		<source>
			<title type="html">benking.me.uk</title>
			<subtitle type="html">The world according to Ben...</subtitle>
			<link rel="self" href="http://www.benking.me.uk/feed/"/>
			<id>http://www.benking.me.uk/feed/</id>
			<updated>2008-07-21T19:17:03+00:00</updated>
		</source>
	</entry>

	<entry xml:lang="en">
		<title type="html">New Mayflower Chinese Restaurant Coventry - FOOD FAIL</title>
		<link href="http://www.benking.me.uk/2008/07/01/new-mayflower-chinese-restaurant-coventry-food-fail/"/>
		<id>http://www.benking.me.uk/2008/07/01/new-mayflower-chinese-restaurant-coventry-food-fail/</id>
		<updated>2008-07-01T08:34:25+00:00</updated>
		<content type="html">&lt;p&gt;Last night we decided to have a cheeky Chinese take away. Our usual take away, the Ruby House, is shut on Mondays so had to find another.&lt;/p&gt;
&lt;p&gt;We decided on trying the &amp;#8216;Net Mayflower Chinese Restaurant&amp;#8217; in Cheylesmore, it used to be okay a few years back, it isn&amp;#8217;t anymore.&lt;/p&gt;
&lt;p&gt;We ordered:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Crispy Chicken in Chilli&lt;/li&gt;
&lt;li&gt;Barbeque Spare Ribs in Chilli and Salt&lt;/li&gt;
&lt;li&gt;Beef Black Bean Sauce and Green Pepper&lt;/li&gt;
&lt;li&gt;Egg Fried Rice&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The first worrying sign was in the car driving home, when the smell was something that we can only describe as &amp;#8216;rotten wet bread&amp;#8217;.&lt;/p&gt;
&lt;p&gt;When we got it home, the ribs were dry and tough, the chicken was dry, tough and tasteless, the egg fried rice looked very brown and manky like it had seen better days&amp;#8230;&lt;/p&gt;
&lt;p&gt;The icing on the cake (I wish it was), was the beef which appeared to be the source of noxious odour.&#160;I put the first piece of beef in my mouth I actually had to work hard not to be sick.&lt;/p&gt;
&lt;p&gt;We disposed of the entire meal immediately.&lt;/p&gt;
&lt;p&gt;Worsed&#160;take-away&#160;ever, a definite FOOD FAIL!&lt;/p&gt;</content>
		<author>
			<name>Ben King</name>
			<uri>http://www.benking.me.uk</uri>
		</author>
		<source>
			<title type="html">benking.me.uk</title>
			<subtitle type="html">The world according to Ben...</subtitle>
			<link rel="self" href="http://www.benking.me.uk/feed/"/>
			<id>http://www.benking.me.uk/feed/</id>
			<updated>2008-07-21T19:17:03+00:00</updated>
		</source>
	</entry>

	<entry xml:lang="en">
		<title type="html">Berocca to the rescue of bloggers everywhere&#8230;</title>
		<link href="http://www.benking.me.uk/2008/06/30/berocca-to-the-rescue-of-bloggers-everywhere/"/>
		<id>http://www.benking.me.uk/2008/06/30/berocca-to-the-rescue-of-bloggers-everywhere/</id>
		<updated>2008-06-30T17:55:56+00:00</updated>
		<content type="html">&lt;p&gt;So the other day I had a hangover, a bad one. So I twittered about how &lt;a target=&quot;_blank&quot; href=&quot;http://www.berocca.co.uk&quot; title=&quot;Berocca&quot;&gt;Beroccca&lt;/a&gt; came to my rescue.&lt;/p&gt;
&lt;p&gt;Anyway &lt;a target=&quot;_blank&quot; href=&quot;http://www.outsideline.co.uk&quot; title=&quot;Outside Line&quot;&gt;Outside Line&lt;/a&gt;, the digital agency responsible for Beroccas online marketing contacted me, basically they have a special Berocca bloggers relief pack, which you can get yourself at this special microsite:&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.berocca.co.uk/bloggerrelief&quot;&gt;http://www.berocca.co.uk/bloggerrelief&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Clever stuff Berocca/Outside Line, I like it!&lt;/p&gt;</content>
		<author>
			<name>Ben King</name>
			<uri>http://www.benking.me.uk</uri>
		</author>
		<source>
			<title type="html">benking.me.uk</title>
			<subtitle type="html">The world according to Ben...</subtitle>
			<link rel="self" href="http://www.benking.me.uk/feed/"/>
			<id>http://www.benking.me.uk/feed/</id>
			<updated>2008-07-21T19:17:03+00:00</updated>
		</source>
	</entry>

	<entry xml:lang="en">
		<title type="html">And while we are at it Pizza Express Coventry&#8230;</title>
		<link href="http://www.benking.me.uk/2008/06/27/and-while-we-are-at-it-pizza-express-coventry/"/>
		<id>http://www.benking.me.uk/2008/06/27/and-while-we-are-at-it-pizza-express-coventry/</id>
		<updated>2008-06-27T17:49:43+00:00</updated>
		<content type="html">&lt;p&gt;Wednesday Evening 10pm, 5 of us very hungry, so we decide to go for a quick &lt;a href=&quot;http://www.pizzaexpress.co.uk&quot; title=&quot;Pizza Express&quot;&gt;Pizza Express&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;We walk into &lt;a href=&quot;http://www.pizzaexpress.co.uk&quot; title=&quot;Pizza Express&quot;&gt;Pizza Express&lt;/a&gt;, Coventry and its pretty full, all the staff are still on serving, and we ask for&#160;a table for 5, the girl serving us looked concerned and ran off upstairs to ask her manager.&lt;/p&gt;
&lt;p&gt;She came downstairs and said &amp;#8217;sorry no we can&amp;#8217;t serve you as we are closed&amp;#8217;, we went to great pains to explain that we come in all the time, and that we will be quick, and could we talk to the manager. Nothing, in fact she blanked us and walked off!&lt;/p&gt;
&lt;p&gt;This all makes no sense, its not like they had finished for the night, in fact we probably would probably have been in and out faster than some of the people having a more leisurely meal.&lt;/p&gt;
&lt;p&gt;We would have spent well in excess of &#163;100, been really happy that they served us, instead they have lost out on the revenue and 5 peoples goodwill.&lt;/p&gt;
&lt;p&gt;We ended up going to the wonderful&#160;&lt;a target=&quot;_blank&quot; href=&quot;http://www.coventry.thaidusit.co.uk/&quot; title=&quot;Thai Dusit&quot;&gt;Thai Dusit&lt;/a&gt;, where they were more than happy to feed us, take our money and stay open as long as we wanted.&lt;/p&gt;
&lt;p&gt;The Coventry Pizza Express constantly dissappoints in respect of customer service, I think that at least 25% of the time I go there one of the following occurs:&lt;/p&gt;
&lt;p&gt;1) Sorry we aren&amp;#8217;t serving anymore (despite the restaurant staff and other customers still being there).&lt;/p&gt;
&lt;p&gt;2) Sorry we are full (despite the fact that we know they have an upstairs seating area with no-one in it).&lt;/p&gt;
&lt;p&gt;Basically I am coming to the conclusion that Pizza Express just don&amp;#8217;t want my money, which is a shame because I like eating there!&lt;/p&gt;</content>
		<author>
			<name>Ben King</name>
			<uri>http://www.benking.me.uk</uri>
		</author>
		<source>
			<title type="html">benking.me.uk</title>
			<subtitle type="html">The world according to Ben...</subtitle>
			<link rel="self" href="http://www.benking.me.uk/feed/"/>
			<id>http://www.benking.me.uk/feed/</id>
			<updated>2008-07-21T19:17:03+00:00</updated>
		</source>
	</entry>

	<entry xml:lang="en">
		<title type="html">RGB Direct - yet another customer service failure&#8230;</title>
		<link href="http://www.benking.me.uk/2008/06/27/rgb-direct-yet-another-customer-service-failure/"/>
		<id>http://www.benking.me.uk/2008/06/27/rgb-direct-yet-another-customer-service-failure/</id>
		<updated>2008-06-27T17:29:38+00:00</updated>
		<content type="html">&lt;p&gt;So two weeks ago I ordered a new Samsung LCD TV from RGB Direct (&lt;a href=&quot;http://www.rgbdirect.co.uk/&quot;&gt;http://www.rgbdirect.co.uk&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;I should have known better when the onerous ordering system forced me to supply home phone and mobile before continuing (My only home phone line is for ADSL and fax), but I ploughed on.&lt;/p&gt;
&lt;p&gt;I selected the free delivery because although it said delivery would take 14 days, I didn&amp;#8217;t really need it yet, so I could wait.&lt;/p&gt;
&lt;p&gt;The next day I got a hassling call from their logistics trying to talk me into paying for delivery so I could get it quicker, and that I would have to wait for the tv to be delivered &amp;#8216;directly from the manufacturer&amp;#8217;.&lt;/p&gt;
&lt;p&gt;I eventually convinced them, that I was happy with the free delivery option (though I sensed I would regret it).&lt;/p&gt;
&lt;p&gt;Yesterday they phoned me to say that delivery would be today between 10 and 6, I ensured that there was someone at the house all day. They happened to turn up while I was out with the TV, and then demanded to see the credit card I paid with (despite it being delivered to the same address as the card). The card was of course with me, so they took the TV away again. In addition they revealed how they lied to&#160;me, it was their own people delivering the TV to me rather than &amp;#8216;direct from the manufacturer&amp;#8217;, so basically their free delivery option is them delivering it whenever they can be bothered.&lt;/p&gt;
&lt;p&gt;I phoned up to rearrange delivery and they told me that redelivery would cost me &#163;35 - more than if I had taken their&#160;2 day delivery option in the first place.&lt;/p&gt;
&lt;p&gt;I just went with the, fair enough&#160;I will cancel my order&amp;#8230; and now they are T&amp;amp;Cing me&amp;#8230; (see below).&lt;/p&gt;
&lt;p&gt;Basically rubbish, my recommendation is DO NOT USE RGB DIRECT.&lt;/p&gt;
&lt;p class=&quot;MsoPlainText&quot;&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;font&gt;&amp;#8212;&amp;#8211;Original Message&amp;#8212;&amp;#8211;&lt;br /&gt;
From: RGB Customer Services [mailto:service@rgbdirect.co.uk]&lt;br /&gt;
Sent: 27 June 2008 17:28&lt;br /&gt;
To: Ben King&lt;br /&gt;
Subject: RE: Failed Delivery Charge apply&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;font&gt;&#160;&lt;/font&gt;&lt;font&gt;Dear Sir,&lt;/font&gt;&lt;font&gt;&#160;&lt;/font&gt;&lt;font&gt;Further to your email , please note that any failed delivery are subjected&lt;/font&gt;&lt;font&gt;to a charge of &#163;35.00 for refund to process. With reference to the credit&lt;/font&gt;&lt;font&gt;card swipe , we always take manual verification swipe of Credit/debit card&lt;/font&gt;&lt;font&gt;on delivery this is completely for security reasons , we have also stated&lt;/font&gt;&lt;font&gt;clearly on our terms and conditions&lt;span&gt;&#160; &lt;/span&gt;www.rgbdirect.co.uk . &lt;/font&gt;&lt;font&gt;As you have placed order on internet , you must have seen the terms and&lt;/font&gt;&lt;font&gt;conditions of delivery . At this stage if you wish to cancel the order ,&lt;/font&gt;&lt;font&gt;there will be &#163;35.00 failed delivery charge apply to your account. Please&lt;/font&gt;&lt;font&gt;confirm accordingly and we will process the refund as per your request. &lt;/font&gt;&lt;font&gt;&#160;&lt;/font&gt;&lt;font&gt;&#160;&lt;/font&gt;&lt;font&gt;Thank you &lt;/font&gt;&lt;font&gt;Kind regards&lt;/font&gt;&lt;font&gt;&lt;span&gt;&#160; &lt;/span&gt;&lt;/font&gt;&lt;font&gt;Customer Services &lt;/font&gt;&lt;font&gt;Tel:&lt;span&gt;&#160; &lt;/span&gt;0208 478 1444&lt;/font&gt;&lt;font&gt;Mob:0796 696 8734&lt;/font&gt;&lt;font&gt;Fax: 0208 924 0114&lt;/font&gt;&lt;font&gt;Email:Service@rgbdirect.co.uk&lt;/font&gt;&lt;/p&gt;</content>
		<author>
			<name>Ben King</name>
			<uri>http://www.benking.me.uk</uri>
		</author>
		<source>
			<title type="html">benking.me.uk</title>
			<subtitle type="html">The world according to Ben...</subtitle>
			<link rel="self" href="http://www.benking.me.uk/feed/"/>
			<id>http://www.benking.me.uk/feed/</id>
			<updated>2008-07-21T19:17:03+00:00</updated>
		</source>
	</entry>

	<entry xml:lang="en">
		<title type="html">Vyatta - Desert Deployment!</title>
		<link href="http://www.benking.me.uk/2008/04/20/vyatta-desert-deployment/"/>
		<id>http://www.benking.me.uk/2008/04/20/vyatta-desert-deployment/</id>
		<updated>2008-04-20T11:34:17+00:00</updated>
		<content type="html">&lt;p&gt;I have deployed &lt;a target=&quot;_blank&quot; href=&quot;http://www.vyatta.com&quot; title=&quot;Vyatta&quot;&gt;Vyatta&lt;/a&gt; to a lot of different locations, however the deployment I did last week was a little different&amp;#8230;&lt;/p&gt;
&lt;p&gt;&lt;a target=&quot;_blank&quot; href=&quot;http://www.yasisland.ae&quot; title=&quot;Yas Island&quot;&gt;Yas Island&lt;/a&gt;&#160;is a naturual&#160;island on the coast of the United Arab Emirates of about 2,500 hectares or which 1,700 hectares is being developed. It is to be a&#160;$40&#160;billion&#160;playground of marinas, shops, theme park, water park, hotels and villas not to mention a &lt;a target=&quot;_blank&quot; href=&quot;http://www.formula1.com&quot; title=&quot;Formula 1&quot;&gt;Formula&#160;1&lt;/a&gt; track.&lt;/p&gt;
&lt;p&gt;At the minute though it is little more than a lot of sand, some mounds of earth, a few roads and a lot of cranes, and I get the pleasure on behalf of my client &lt;a target=&quot;_blank&quot; href=&quot;http://www.benoy.com&quot; title=&quot;Benoy&quot;&gt;Benoy&lt;/a&gt;&#160;(architects), of extending their existing Vyatta&#160;network to cover both their Abu Dhabi city office and their Yas Island site office.&lt;/p&gt;
&lt;p&gt;There were a number of challenges with the deployment:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;The connectivity; we had ordered a 2mbit/s leased line from &lt;a target=&quot;_blank&quot; href=&quot;http://www.etisalat.ae/&quot; title=&quot;Etisalat&quot;&gt;Etisalat&lt;/a&gt;, the UAE telco, this was being delivered via a microwave link back to Abu Dhabi, at the point of landing in the country, we had no idea of the reliability,&#160;IP Scheme and weren&amp;#8217;t even confident about the presentation!&lt;/li&gt;
&lt;li&gt;Disruption; the users were using a shared network provided by the client, which was painfully slow, but worked to give them email and basic web access, we had to minimise downtime.&lt;/li&gt;
&lt;li&gt;Reliability; we had to do ever&lt;a rel=&quot;attachment wp-att-105&quot; href=&quot;http://www.benking.me.uk/2008/04/20/vyatta-desert-deployment/yas-island-construction-office/&quot; title=&quot;Yas Island Construction office&quot;&gt;&lt;/a&gt;ything we could to ensure reliability and remote maintainability of the network once we had left.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;The Kit&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a target=&quot;_blank&quot; href=&quot;http://www.vyatta.com&quot; title=&quot;Vyatta&quot;&gt;V&lt;/a&gt;&lt;a target=&quot;_blank&quot; href=&quot;http://www.vyatta.com&quot; title=&quot;Vyatta&quot;&gt;yatta &lt;/a&gt;was the natural choice not only because we were using it across the rest of the &lt;a target=&quot;_blank&quot; href=&quot;http://www.benoy.com&quot; title=&quot;Benoy&quot;&gt;Benoy&lt;/a&gt; network, but also because of the cost effectiveness of the hardware required to deploy a resilient configuration.&lt;/p&gt;
&lt;p&gt;At each site we deployed 1U &lt;a target=&quot;_blank&quot; href=&quot;http://www.dell.co.uk&quot; title=&quot;Dell 860s&quot;&gt;Dell&lt;/a&gt; 860s, with:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Dual core Xeon processors&lt;/li&gt;
&lt;li&gt;2GBs of Ram&lt;/li&gt;
&lt;li&gt;Hardware mirrored Sata drives&lt;/li&gt;
&lt;li&gt;Additional Intel Dual&#160;NIC card (giving 4&#160;ethernet interfaces&#160;in total)&lt;/li&gt;
&lt;li&gt;Vyatta 2.3.1&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;The Configuration&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;4 Subnets: Workstations, Servers, Internet 1 (leased line), Internet 2 (ADSL)&lt;/li&gt;
&lt;li&gt;All subnets clustered across the two routers&lt;/li&gt;
&lt;li&gt;DHCP for workstation subnets (split across the two routers)&lt;/li&gt;
&lt;li&gt;Masquerade NAT for internal subnets&lt;/li&gt;
&lt;li&gt;Incoming NAT for email and video conferencing&lt;/li&gt;
&lt;li&gt;IPSec VPN tunnels back to the UK network and the other Abu Dhabi site&lt;/li&gt;
&lt;li&gt;Internal and external firewalling&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;The Microwave Link&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The microwave link was a V35 serial presentation that we passed through a Cisco 1841 before passing onto the Vyattas, the resulting connection performed remarkably well giving us about 14ms round trip on pings back to the main Abu Dhabi office.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The Result&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The end result is fantastic, speed and response&#160;of performance at both sites far exceeded expectations. At the main site we were replacing a Firebox VPN tunnel back to London, which had proved to be a little unreliable and extremely slow, we were putting this down to the quality of the Etisalat connection, however once we replaced it with&#160;the Vyatta VPN the network response and reliability was far in excess of expectations and performs as well as the MPLS circuits we have connecting other sites.&lt;/p&gt;
&lt;p&gt;Martin Neal, IT Director of Benoy, said&#160;&amp;#8217;&lt;font&gt;&lt;em&gt;I am really pleased with the speed and also the &amp;#8220;feel&amp;#8221; of the network.&lt;/em&gt;&amp;#8216;&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Photos&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The Yas Island site office&amp;#8230;&lt;/p&gt;
&lt;p&gt;&lt;a rel=&quot;attachment wp-att-105&quot; href=&quot;http://www.benking.me.uk/2008/04/20/vyatta-desert-deployment/yas-island-construction-office/&quot; title=&quot;Yas Island Construction office&quot;&gt;&lt;img src=&quot;http://www.benking.me.uk/wp-content/uploads/2008/04/16042008015.thumbnail.jpg&quot; alt=&quot;Yas Island Construction office&quot; /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The Benoy team at Yas Island&amp;#8230;&lt;/p&gt;
&lt;p&gt;&lt;a rel=&quot;attachment wp-att-106&quot; href=&quot;http://www.benking.me.uk/2008/04/20/vyatta-desert-deployment/yas-island-benoy-office/&quot; title=&quot;Yas Island Benoy Office&quot;&gt;&lt;img src=&quot;http://www.benking.me.uk/wp-content/uploads/2008/04/16042008004.thumbnail.jpg&quot; alt=&quot;Yas Island Benoy Office&quot; /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Our Microwave Link&amp;#8230;&lt;/p&gt;
&lt;p&gt;&lt;a rel=&quot;attachment wp-att-107&quot; href=&quot;http://www.benking.me.uk/2008/04/20/vyatta-desert-deployment/our-microwave-link/&quot; title=&quot;Our microwave link.&quot;&gt;&lt;img src=&quot;http://www.benking.me.uk/wp-content/uploads/2008/04/16042008011.thumbnail.jpg&quot; alt=&quot;Our microwave link.&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</content>
		<author>
			<name>Ben King</name>
			<uri>http://www.benking.me.uk</uri>
		</author>
		<source>
			<title type="html">benking.me.uk</title>
			<subtitle type="html">The world according to Ben...</subtitle>
			<link rel="self" href="http://www.benking.me.uk/feed/"/>
			<id>http://www.benking.me.uk/feed/</id>
			<updated>2008-07-21T19:17:03+00:00</updated>
		</source>
	</entry>

	<entry xml:lang="en">
		<title type="html">Public transport is Virgin on disaster&#8230;</title>
		<link href="http://www.benking.me.uk/2008/04/20/public-transport-is-virgin-on-disaster/"/>
		<id>http://www.benking.me.uk/2008/04/20/public-transport-is-virgin-on-disaster/</id>
		<updated>2008-04-20T09:55:44+00:00</updated>
		<content type="html">&lt;p&gt;&#160;&amp;lt;rant&amp;gt;&#160;&lt;/p&gt;
&lt;p&gt;I live in Coventry, which is as near as damnit slap bang in the middle of the UK, and within spitting distance of our second city, Birmingham, given this fact why is it soo damn difficult to get to the UKs biggest airport (Heathrow) on public transport?!&lt;/p&gt;
&lt;p&gt;Normally when I fly&#160;its always easier and quicker to get to go from&#160;Birmingham to&#160;Frankfurt, Schipol or Copenhagen than it is to Heathrow, but this time it just wasn&amp;#8217;t possible so I committed to Heathrow.&lt;/p&gt;
&lt;p&gt;The options to travel from Coventry to Heathrow are:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Drive, while you have to endure the M40, M25, and the extortionate parking fees at Heathrow, it is nethertheless the flexible option.&lt;/li&gt;
&lt;li&gt;Train to London, underground to Heathrow/Paddington then Heathrow express. This always strikes me as a dog leg of a journey and you have to suffer the underground with luggage. At least though the wheels keep turning.&lt;/li&gt;
&lt;li&gt;Train to Reading, bus to Heathrow.&lt;/li&gt;
&lt;li&gt;Train to Watford, bus to Heathrow.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;There really is no optimum choice, and despite knowing better I went for option 4, what really irks me is that I am sure there used to be a train from Watford to Heathrow.&lt;/p&gt;
&lt;p&gt;This should be easy but alas&amp;#8230; my journey was:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Cab to Coventry Train station (less than a mile, easily done).&lt;/li&gt;
&lt;li&gt;Virgin Train to Watford, just like going to London no issues.&lt;/li&gt;
&lt;li&gt;1.5 hours spent stood in the wrong place at Watford, the signs being in the wrong place for the bus. Rather than leaving from the bus terminal at the station, it leaves from over the road and down the street a bit, out of site from the station. There were about 10 of us all stood in the same wrong place, so I am confident it wasn&amp;#8217;t just me being stupid. To add insult to injury the bus drivers actually drove past the station and obviously could see a load of people with suitcases stood at the wrong bus stop and drove on regardless with an empty bus. I&#160;asked 3 members of station staff, until I got one ansy woman who said testily &amp;#8216;its obviously over the road&amp;#8217;, this deteriorated into a full on argument and she was completely unuseful and totally jobs worth.&lt;/li&gt;
&lt;li&gt;Finally I got a bus to Heathrow and once I was on it, it wasn&amp;#8217;t too bad.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Coming home.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Land at Heathrow.&lt;/li&gt;
&lt;li&gt;Go to designated bus stop, according to time table bus at 19:45, turns up 20:05 and departs with just 2 of us on it immediately, with no regard for the timetable.&lt;/li&gt;
&lt;li&gt;Arrive Watford Junction (approx 20:40), train apparently at 20:55 to Coventry, wait on platform 20:55 completely fails to turn up, no warning, just vanished off display and a 21:05 to Preston (calling at Rugby) turns up instead&amp;#8230; so I get on that.&lt;/li&gt;
&lt;li&gt;&#163;30 cab ride to Coventry from Rugby&#160;and I am home.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;I may as well have driven, it would have been easy, and probably cheaper in the end.&lt;/p&gt;
&lt;p&gt;Until this country gets public transport right, people will stay in their cars. Nuff said!&lt;/p&gt;
&lt;p&gt;&amp;lt;/rant&amp;gt;&lt;/p&gt;</content>
		<author>
			<name>Ben King</name>
			<uri>http://www.benking.me.uk</uri>
		</author>
		<source>
			<title type="html">benking.me.uk</title>
			<subtitle type="html">The world according to Ben...</subtitle>
			<link rel="self" href="http://www.benking.me.uk/feed/"/>
			<id>http://www.benking.me.uk/feed/</id>
			<updated>2008-07-21T19:17:03+00:00</updated>
		</source>
	</entry>

	<entry xml:lang="en">
		<title type="html">The Number of the Beast of a Bill&#8230;</title>
		<link href="http://www.benking.me.uk/2008/04/20/the-number-of-the-beast-of-a-bill/"/>
		<id>http://www.benking.me.uk/2008/04/20/the-number-of-the-beast-of-a-bill/</id>
		<updated>2008-04-20T09:46:59+00:00</updated>
		<content type="html">&lt;p&gt;&lt;a target=&quot;_blank&quot; href=&quot;http://www.rotana.com/hoteldiningdesc-4-5-4-20.htm&quot; title=&quot;Prego's, Beach Rotana, Abu Dhabi&quot;&gt;Prego&amp;#8217;s Italian Restaurant, Beach Rotana Hotel, Abu Dhabi,&lt;/a&gt; dinner and drinks for three&amp;#8230; 666.00 UAD&amp;#8230;&lt;/p&gt;
&lt;p&gt;How scary is that?!&lt;br /&gt;
&lt;img src=&quot;http://www.benking.me.uk/wp-content/uploads/2008/04/666bill.jpg&quot; alt=&quot;666 Bill&quot; /&gt;&lt;/p&gt;</content>
		<author>
			<name>Ben King</name>
			<uri>http://www.benking.me.uk</uri>
		</author>
		<source>
			<title type="html">benking.me.uk</title>
			<subtitle type="html">The world according to Ben...</subtitle>
			<link rel="self" href="http://www.benking.me.uk/feed/"/>
			<id>http://www.benking.me.uk/feed/</id>
			<updated>2008-07-21T19:17:03+00:00</updated>
		</source>
	</entry>

	<entry xml:lang="en">
		<title type="html">Vyatta - Glendale is coming&#8230; and I am excited!</title>
		<link href="http://www.benking.me.uk/2008/03/31/vyatta-glendale-is-coming-and-i-am-excited/"/>
		<id>http://www.benking.me.uk/2008/03/31/vyatta-glendale-is-coming-and-i-am-excited/</id>
		<updated>2008-03-31T16:32:18+00:00</updated>
		<content type="html">&lt;p&gt;The next major release of Vyatta (VC4 - codename Glendale) is due for final release on 22nd April, and I am soo excited!&lt;/p&gt;
&lt;p&gt;This release promises to deliver plethora of new features and functionality, including:&lt;/p&gt;
&lt;p&gt;1) &lt;strong&gt;FusionCLI&lt;/strong&gt; - A new CLI based around bash that gives simultaneous access to Vyatta configuration and the underlying Linux shell. Woohoo - no more exiting from xorpsh to do basic bash stuff.&lt;/p&gt;
&lt;p&gt;2 ) &lt;strong&gt;Remote Access VPN&lt;/strong&gt; - Remote vpn clients are now supported via both PPTP and L2TP/IPSec.&lt;/p&gt;
&lt;p&gt;3)&#160; &lt;strong&gt;Tunnel Interfaces &lt;/strong&gt;-&#160; GRE support means that we can now tunnel both non-ip tunnels (Appletalk, etc. - should you really want to), as well as more importantly ip in ip tunnels, which are somewhat more useful, not least for doing resilient routing via backup VPN links.&lt;/p&gt;
&lt;p&gt;4) &lt;strong&gt;QOS &lt;/strong&gt;- Although QOS via TC has long been available to the &amp;#8216;hardcore&amp;#8217; under the hood via tc and the shell, this is the first time that Vyatta have exposed this functionality to masses via the CLI. The initial release notes suggest that it will just be SFQ (Stochastic Fair Queuing), and shaping around packet marking. As is always the case with Vyatta they start simple and grow from there, so you can expect to see HTB, etc. added later on. Personally I am hoping they have ticked the 2.6 kernal option to enable IFB (Intermediate Functional Block), to enable traffic shaping over multiple interfaces&amp;#8230; we will see!&lt;/p&gt;
&lt;p&gt;5) &lt;strong&gt;Redesign of Routing Protocols&lt;/strong&gt; - Vyatta has in the past been criticised for its routing protocol performance particularly in terms of BGP convergence, I am guessing this is one of the many reasons they have completely revisited the router manager. And they are keen to shout about it, this &lt;a href=&quot;http://www.vyatta.com/download/whitepapers/Tolly208289VyattaBGPPerfMar2008.pdf&quot; title=&quot;Vyatta vs Cisco&quot; target=&quot;_blank&quot;&gt;Tolly report&lt;/a&gt; demonstrates $8000 of Vyatta running on an IBM server, giving $30,000+ of Cisco 7204 a complete and utter kicking.&lt;/p&gt;
&lt;p&gt;6) &lt;strong&gt;VRRP interfaces by VIF &lt;/strong&gt;- This one is worth special mention because it was my first Vyatta enhancement request that has made it through to release (given I have only ever submitted 2 thats not bad going!). Basically VRRP could only previously be deployed on real ethernet interfaces, great unless like me you subnet networks up and run a &amp;#8216;router on a stick&amp;#8217; configuration, in which case you need to be able to deploy VRRP across VIFs, you now can! woohoo!&lt;/p&gt;
&lt;p&gt;This is but the tip of the iceberg, there are many other great improvements.&lt;/p&gt;
&lt;p&gt;I will be deploying a version of Glendale soon, in a test environment, and I will report back!&lt;/p&gt;</content>
		<author>
			<name>Ben King</name>
			<uri>http://www.benking.me.uk</uri>
		</author>
		<source>
			<title type="html">benking.me.uk</title>
			<subtitle type="html">The world according to Ben...</subtitle>
			<link rel="self" href="http://www.benking.me.uk/feed/"/>
			<id>http://www.benking.me.uk/feed/</id>
			<updated>2008-07-21T19:17:03+00:00</updated>
		</source>
	</entry>

	<entry xml:lang="en">
		<title type="html">Shanghai - Life behind the great firewall of China&#8230;</title>
		<link href="http://www.benking.me.uk/2008/02/15/shanghai-life-behind-the-great-firewall-of-china/"/>
		<id>http://www.benking.me.uk/2008/02/15/shanghai-life-behind-the-great-firewall-of-china/</id>
		<updated>2008-02-15T02:26:01+00:00</updated>
		<content type="html">&lt;p&gt;When you connect to the Internet in China you don&amp;#8217;t get the real Internet you get a government controlled version, which limits access to sites that are offensive to/or go against the political views of the Chinese government. This is known as the Golden Shield Project or by its lovable nickname, &amp;#8216;The Great Firewall of China&amp;#8217;.&lt;/p&gt;
&lt;p&gt;The Golden Shield Project is an estimated $800m project of the Chinese government to not only control online content but use modern technology to monitor the movements and activities of their people.&lt;/p&gt;
&lt;p&gt;In simple terms as a visitor&#160;this means that they block a bunch of websites,&#160;for&#160;anything about human rights for example Amnesty International (&lt;a href=&quot;http://www.amnesty.org/&quot;&gt;www.amnesty.org&lt;/a&gt;), anything that mentions Tiananmen Square, the Dalai Lama and a whole bunch of other stuff, they particularly don&amp;#8217;t like anything with user generated content that allows their people to express their views to the world or for their people to see what the rest of the world is up to.&lt;/p&gt;
&lt;p&gt;In practical terms this was annoying for me because, it meant all the following are blocked&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;BBC News (&lt;a href=&quot;http://news.bbc.co.uk/&quot;&gt;http://news.bbc.co.uk&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Wikipedia (&lt;a href=&quot;http://en.wikipedia.org/&quot;&gt;http://en.wikipedia.org&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;YouTube (&lt;a href=&quot;http://www.youtube.com/&quot;&gt;http://www.youtube.com&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Flickr (&lt;a href=&quot;http://www.flickr.com/&quot;&gt;http://www.flickr.com&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you want to see a more thorough list (and you aren&amp;#8217;t inside China), then there is a nice article on &lt;a href=&quot;http://en.wikipedia.org/wiki/List_of_websites_blocked_in_the_People%27s_Republic_of_China&quot; title=&quot;Sites blocked by the Great Firewall of China&quot;&gt;Wikipedia here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In truth though the firewall represents little or no challenge to circumvent, not only due to the amount of proxying sites available, but also if you have access to machines outside of China you can easily VPN or SSH your traffic via them circumventing the problem.&lt;/p&gt;
&lt;p&gt;The blocking isn&amp;#8217;t just IP based either, they also do some nasty DNS poisoning, which causes you to be misdirected to another site rather than the one you intended, again this wasn&amp;#8217;t a problem for me as I run my own DNS server on my laptop, but in general a little irritating.&lt;/p&gt;
&lt;p&gt;You can&amp;#8217;t help but feel then that the Chinese efforts to control Internet access&#160;are more than a little futile&amp;#8230;&lt;/p&gt;</content>
		<author>
			<name>Ben King</name>
			<uri>http://www.benking.me.uk</uri>
		</author>
		<source>
			<title type="html">benking.me.uk</title>
			<subtitle type="html">The world according to Ben...</subtitle>
			<link rel="self" href="http://www.benking.me.uk/feed/"/>
			<id>http://www.benking.me.uk/feed/</id>
			<updated>2008-07-21T19:17:03+00:00</updated>
		</source>
	</entry>

	<entry xml:lang="en">
		<title type="html">Shanghai - am I really in China??</title>
		<link href="http://www.benking.me.uk/2008/02/15/shanghai-am-i-really-in-china/"/>
		<id>http://www.benking.me.uk/2008/02/15/shanghai-am-i-really-in-china/</id>
		<updated>2008-02-15T01:36:12+00:00</updated>
		<content type="html">&lt;p&gt;&amp;#8230;is the question I am asking myself right now&amp;#8230;&lt;/p&gt;
&lt;p&gt;I am in Shanghai, a city of some 18 million people, the biggest city in China and in the top 5 largest in the world, the answer should be obvious.&lt;/p&gt;
&lt;p&gt;However, here I am sat in Starbucks (one of&#160;two in this building alone, an one of five that I can think of within a couple of minutes walk), sipping on my &amp;#8216;Venti Cappuccino&amp;#8217; reading the Wall Street Times (Asia edition), looking out across the shopping mall at a&#160;McDonalds full of Chinese eagerly stuffing their faces on whatever&#160;crap it is&#160;that McDonalds sell in the morning, I begin to wonder&amp;#8230;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;http://www.benking.me.uk/wp-content/uploads/2008/02/15022008_small.jpg&quot; alt=&quot;McDonalds and Starbucks in Shanghai&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This one of the many many shopping centers along the &lt;a href=&quot;http://http://en.wikipedia.org/wiki/Nanjing_Road_(Shanghai)&quot; title=&quot;Nanjing Road (Wikipedia)&quot;&gt;Nanjing Road&lt;/a&gt;, Shanghai showcase shopping experience, it runs 5km East to West through the center of Shanghai. The array of shops is staggering with&#160;pretty much every brand (so many Rolex dealerships I have lost count) you care to mention and a string of car dealerships including Mercedes, Porsche, Maserati and Ferrari.&lt;/p&gt;
&lt;p&gt;You would be forgiven for thinking that the prices would be cheaper, it being China and all, and to an extent it is, however my cappuccino&#160;has set me back&#160;31RMB (about &#163;2.20), and the nice new Samsung&#160;LCD screen I am about to buy for home is exactly the same price in the shops here as back in blighty.&lt;/p&gt;
&lt;p&gt;So who is buying this stuff?? Westerners? I don&amp;#8217;t think so, unlike Hong Kong, when you see another non-Asian here, its still a case &amp;#8216;oh look someone white like me&amp;#8217;, they are generally pretty easy to spot as well&#160;due to clearing the surrounding populace by a clear foot. The other day I took a walk&#160;the entire length of&#160;&lt;a href=&quot;http://http://en.wikipedia.org/wiki/The_Bund&quot; title=&quot;The Bund (Wikipedia)&quot;&gt;the Bund&lt;/a&gt;, a 1.5km river side walk, it being Chinese new year it was packed with tourists, 1000s of them, during the entire walk I never saw another non Asian, not one!&lt;/p&gt;
&lt;p&gt;It is the Chinese,&#160;the door is open to&#160;western capitalism and they are embracing it as fast as they can, and best of luck to them.&lt;/p&gt;
&lt;p&gt;I suspect however they are lining themselves up to a serious class divide issue, there are people paid a minimum amount to do every job, meanwhile people at the other end of the scale are getting very rich.&lt;/p&gt;
&lt;p&gt;Shanghai for example is clean, really really clean, you never even the smallest bit of litter, cigarette butts, or even chewing gum, why not? Well thanks to having &#160;plenty of people and not&#160;being hindered by such idiocies as minimum wage, they throw manpower at everything, from street cleaners, to traffic assistants on every junction, and not just one, sometimes 3 or 4 people per road junction just to ensure you make it across the road!&lt;/p&gt;
&lt;p&gt;&#160;&lt;img src=&quot;http://www.benking.me.uk/wp-content/uploads/2008/02/15022008001_small.jpg&quot; alt=&quot;Traffic assistants in Shanghai&quot; /&gt;&lt;/p&gt;
&lt;p&gt;There are lots of fine examples of throwing manpower at the problem, the hotel I am staying in for example, okay its 4* and its costing a mighty &#163;48 per night, all week though I haven&amp;#8217;t had to open the door to the hotel, 24/7 they have at least 4 people manning the doors! When you go into a restaurant its often the case that the staff outnumber the customers, the same in shops, this Starbucks has 5 staff on at the moment.&lt;/p&gt;
&lt;p&gt;I am quite a fan of Shanghai, its lacks the outright outright debauchery and exuberance&#160;of Hong Kong, however in its place comes an air of refined proud elegance.&lt;/p&gt;
&lt;p&gt;To answer my&#160;original question, I am physically in China, however I suspect this far from reflects the real China&amp;#8230; I suspect&#160;if I travel even 1 hour from Shanghai the picture will be very different&amp;#8230;&lt;/p&gt;</content>
		<author>
			<name>Ben King</name>
			<uri>http://www.benking.me.uk</uri>
		</author>
		<source>
			<title type="html">benking.me.uk</title>
			<subtitle type="html">The world according to Ben...</subtitle>
			<link rel="self" href="http://www.benking.me.uk/feed/"/>
			<id>http://www.benking.me.uk/feed/</id>
			<updated>2008-07-21T19:17:03+00:00</updated>
		</source>
	</entry>

	<entry xml:lang="en">
		<title type="html">Kung Hei Fat Choi</title>
		<link href="http://blogs.bit10.net/cathie/2008/02/03/kung-hei-fat-choi/"/>
		<id>http://blogs.bit10.net/cathie/2008/02/03/kung-hei-fat-choi/</id>
		<updated>2008-02-03T16:06:55+00:00</updated>
		<content type="html">&lt;p&gt;Or &amp;#8220;Congratulations and be prosperous&amp;#8221; as Chinese New Year is almost upon us.&#160; However it is also the day &lt;strong&gt;not&lt;/strong&gt; to be buying new shoes as this is considered bad luck amongst some Chinese. The word &amp;#8220;shoes&amp;#8221; is a homophone for the word &amp;#8220;rough&amp;#8221; in Cantonese, or &amp;#8220;evil&amp;#8221; in Mandarin.&#160;&#160; So I will resist the urge to buy shoes on the 7th February!&lt;/p&gt;
&lt;p&gt;Still, at least there is one good thing - it is bad luck to sweep the floor, so the housework will have to have been done by then (fortunately for me, my cleaner works on Wednesdays so my house will be sorted for Chinese New Year).&lt;/p&gt;
&lt;p&gt;This will be the Year of the Rat&#160;who are leaders, pioneers and conquerors.&#160; They are charming, passionate, charismatic, practical and hardworking.&lt;/p&gt;
&lt;p&gt;However, if like me, you were born under the Ox , then you are blessed with the sign of prosperity through fortitude and hard work.&#160; Apparently, this sign is a born leader, quite dependable and possesses an innate ability to achieve great things.&#160; As one might guess, such people are dependable, calm, and modest.&#160; Like their animal namesake, the Ox is unswervingly patient, tireless in their work, and capable of enduring any amount of hardship without complaint [Wikipedia].&lt;/p&gt;
&lt;p&gt;Er - on second thoughts, maybe I was born in a different year&amp;#8230;&lt;/p&gt;</content>
		<author>
			<name>Cathie Gibbens</name>
			<uri>http://blogs.bit10.net/cathie</uri>
		</author>
		<source>
			<title type="html">Cathie's blog...</title>
			<subtitle type="html">Title says it all really.</subtitle>
			<link rel="self" href="http://blogs.bit10.net/cathie/feed/"/>
			<id>http://blogs.bit10.net/cathie/feed/</id>
			<updated>2008-02-03T16:17:07+00:00</updated>
		</source>
	</entry>

	<entry xml:lang="en">
		<title type="html">Six black cocks and a little white kitten&#8230;</title>
		<link href="http://www.benking.me.uk/2008/02/02/six-black-cocks-and-a-little-white-kitten/"/>
		<id>http://www.benking.me.uk/2008/02/02/six-black-cocks-and-a-little-white-kitten/</id>
		<updated>2008-02-02T12:02:35+00:00</updated>
		<content type="html">&lt;p&gt;On boys night, when&#160;we play cards and drink far too much, we tend to have the timeless classic &amp;#8216;&lt;a href=&quot;http://www.imdb.com/title/tt0120735/&quot; title=&quot;Lock, Stock and Two Smoking Barrels&quot;&gt;Lock, Stock and Two Smoking Barrels&lt;/a&gt;&amp;#8216; on in the background.&lt;/p&gt;
&lt;p&gt;A subject of much debate has been what are the endings to jokes they are telling each other in the car journey, that due to the editing, you never get to hear the punchline, well a bit of Googling I found a (possibly not real) answer to one of them (warning! - a little bit rude):&lt;/p&gt;
&lt;p&gt;&amp;#8211;&lt;/p&gt;
&lt;p&gt;TOM: There&amp;#8217;s six black cocks and a little white kitten sitting on the side of the road. How many beaks have they got between them?&lt;/p&gt;
&lt;p&gt;SOAP: Six.&lt;/p&gt;
&lt;p&gt;TOM: How many wings have they got between them?&lt;/p&gt;
&lt;p&gt;SOAP: Twelve.&lt;/p&gt;
&lt;p&gt;TOM: How many feet?&lt;/p&gt;
&lt;p&gt;SOAP: Er, well, twelve.&lt;/p&gt;
&lt;p&gt;TOM: That&amp;#8217;s right. So how many whiskers has the little white kitten got?&lt;/p&gt;
&lt;p&gt;SOAP: How the fuck should I know?&lt;/p&gt;
&lt;p&gt;TOM: How come you know so much about black cocks and so little about white pussy?&lt;/p&gt;
&lt;p&gt;&amp;#8211;&lt;/p&gt;
&lt;p&gt;If anyone knows the end of the following one, let me know!:&lt;/p&gt;
&lt;p&gt;&amp;#8216;All right, there&amp;#8217;s this brass standing on the corner.&amp;#8217;&lt;br /&gt;
&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&lt;br /&gt;
&amp;#8216;Dwarf walks up to her carrying a suitcase&amp;#8230;&amp;#8217;&lt;/p&gt;</content>
		<author>
			<name>Ben King</name>
			<uri>http://www.benking.me.uk</uri>
		</author>
		<source>
			<title type="html">benking.me.uk</title>
			<subtitle type="html">The world according to Ben...</subtitle>
			<link rel="self" href="http://www.benking.me.uk/feed/"/>
			<id>http://www.benking.me.uk/feed/</id>
			<updated>2008-07-21T19:17:03+00:00</updated>
		</source>
	</entry>

	<entry xml:lang="en">
		<title type="html">Test Post</title>
		<link href="http://blogs.bit10.net/ross/2008/01/31/test-post/"/>
		<id>http://blogs.bit10.net/ross/2008/01/31/test-post/</id>
		<updated>2008-01-31T15:55:29+00:00</updated>
		<content type="html">&lt;p&gt;Testing the new blog.&lt;/p&gt;
&lt;p&gt;&#160;and pimping the volvo blog: &lt;a href=&quot;http://loveforthevolvo.blogspot.com/&quot;&gt;http://loveforthevolvo.blogspot.com&lt;/a&gt;&lt;/p&gt;</content>
		<author>
			<name>Ross Greenhalf</name>
			<uri>http://blogs.bit10.net/ross</uri>
		</author>
		<source>
			<title type="html">Why doesn't money grow on trees?</title>
			<link rel="self" href="http://blogs.bit10.net/ross/feed/"/>
			<id>http://blogs.bit10.net/ross/feed/</id>
			<updated>2008-03-11T17:17:06+00:00</updated>
		</source>
	</entry>

	<entry xml:lang="en">
		<title type="html">World of Warcraft hits 10 million players</title>
		<link href="http://www.benking.me.uk/2008/01/23/world-of-warcraft-hits-10-million-players/"/>
		<id>http://www.benking.me.uk/2008/01/23/world-of-warcraft-hits-10-million-players/</id>
		<updated>2008-01-23T12:23:35+00:00</updated>
		<content type="html">&lt;p&gt;So Blizzard must be delighted, WOW finally hits 10 million paying subscribers, is there no stopping it&amp;#8230;&lt;/p&gt;
&lt;p&gt;I find myself wondering why, after the initial excitement, the last expansion (The Burning Crusade) took a lot of shine off the game.&lt;/p&gt;
&lt;p&gt;The unrelenting need to grind for rep and better items eventually takes its toll and to add to that our guild, Go Rin No Sho, (&lt;a href=&quot;http://www.gorinnosho.co.uk&quot; title=&quot;Go Rin No Sho&quot; target=&quot;_blank&quot;&gt;www.gorinnosho.co.uk&lt;/a&gt;), despite having arguably some of the best and most committed players on our server (Bronzebeard) , we still struggle with the higher level content. The curve is just too steep, other than for people who really have no life whatsoever.&lt;/p&gt;
&lt;p&gt;With the next expansion (&lt;a href=&quot;http://www.amazon.co.uk/gp/product/B000UTOE8A?ie=UTF8&amp;amp;tag=bekibl-21&amp;amp;linkCode=as2&amp;amp;camp=1634&amp;amp;creative=6738&amp;amp;creativeASIN=B000UTOE8A&quot;&gt;World of Warcraft: The Wrath of the Lich King Expansion Pack (PC)&lt;/a&gt;&lt;img src=&quot;http://www.assoc-amazon.co.uk/e/ir?t=bekibl-21&amp;amp;l=as2&amp;amp;o=2&amp;amp;a=B000UTOE8A&quot; border=&quot;0&quot; height=&quot;1&quot; width=&quot;1&quot; /&gt;), still sometime away (Amazon are listing it as September 2008), it seems likely that some of us will get bored and fall away before then.&lt;/p&gt;
&lt;p&gt;Having said that I still have 3 level 70 characters and another one on the way!&#160; &lt;img src=&quot;http://www.benking.me.uk/wp-includes/images/smilies/icon_smile.gif&quot; alt=&quot;:)&quot; class=&quot;wp-smiley&quot; /&gt;&lt;/p&gt;</content>
		<author>
			<name>Ben King</name>
			<uri>http://www.benking.me.uk</uri>
		</author>
		<source>
			<title type="html">benking.me.uk</title>
			<subtitle type="html">The world according to Ben...</subtitle>
			<link rel="self" href="http://www.benking.me.uk/feed/"/>
			<id>http://www.benking.me.uk/feed/</id>
			<updated>2008-07-21T19:17:03+00:00</updated>
		</source>
	</entry>

	<entry xml:lang="en">
		<title type="html">UGC at its best&#8230;</title>
		<link href="http://www.benking.me.uk/2008/01/22/ugc-at-its-best/"/>
		<id>http://www.benking.me.uk/2008/01/22/ugc-at-its-best/</id>
		<updated>2008-01-22T11:15:44+00:00</updated>
		<content type="html">&lt;p&gt;Poor london &lt;a href=&quot;http://www.london-eating.co.uk/&quot;&gt;www.london-eating.co.uk&lt;/a&gt; has got stung with an amusing bit of UGC, read it while its still there (warning marginally rude!):&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.london-eating.co.uk/review-comments/123446.htm&quot;&gt;http://www.london-eating.co.uk/review-comments/123446.htm&lt;/a&gt;&lt;/p&gt;</content>
		<author>
			<name>Ben King</name>
			<uri>http://www.benking.me.uk</uri>
		</author>
		<source>
			<title type="html">benking.me.uk</title>
			<subtitle type="html">The world according to Ben...</subtitle>
			<link rel="self" href="http://www.benking.me.uk/feed/"/>
			<id>http://www.benking.me.uk/feed/</id>
			<updated>2008-07-21T19:17:03+00:00</updated>
		</source>
	</entry>

	<entry xml:lang="en">
		<title type="html">Jamie&#8217;s Fowl Dinners aka Jamie kills chickens!</title>
		<link href="http://www.benking.me.uk/2008/01/18/jamies-fowl-dinners-aka-jamie-kills-chickens/"/>
		<id>http://www.benking.me.uk/2008/01/18/jamies-fowl-dinners-aka-jamie-kills-chickens/</id>
		<updated>2008-01-18T00:59:42+00:00</updated>
		<content type="html">&lt;p&gt;I finally got around to watching the much hyped &amp;#8216;Jamie&amp;#8217;s Fowl Dinners&amp;#8217; which seems to have caused a bit of a ruck as we see our once favourite TV chef trying to shock us into not buying caged chicken.&lt;/p&gt;
&lt;p&gt;Before i go on lets get my personal buying habits out of the way, I strictly buy free range and where possible organic eggs and chickens, it tastes better and makes me feel better and frankly the for the small number of pennies different in price, why not?!&lt;/p&gt;
&lt;p&gt;I applaud Jamie for trying to raise awareness, and I did watch it with a bit of an attitude of &amp;#8216;its okay I buy organic already&amp;#8217;, shocking facts to me were:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;The price supermarkets pay to farmers for chicken, 2-&amp;gt;3p per chicken, surely that can&amp;#8217;t be right? I always apply a 30% rule to anything I buy in the supermarket, i.e. i pay &#163;3 for a chicken, and the farmer is getting a &#163;1&amp;#8230; apparently i am way wrong, can anyone clarify?! The messaged seemed to be that if you spend a &#163;1 more on a chicken for sunday dinner, that &#163;1 mostly made its way back to the farmer making a huge difference.&lt;/li&gt;
&lt;li&gt;Liquid eggs - makes sense I suppose, however the thought of it being in many products i buy is a bit sickening and I feel horribly powerless to do anything about it!&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Taking a step back I am interested in why Jamie Oliver is doing this, killing chickens live on TV is bound to upset some people, and apparently the &lt;a href=&quot;http://www.rspca.org.uk&quot; title=&quot;RSPCA&quot;&gt;RSPCA&lt;/a&gt; are more than a little pissed at him. Although Jamie Oliver has fallen in popularity over the past few years, I am sure there is plenty of money left for him to coast along for a good few years to come&amp;#8230; so I can only conclude that either he genuinely believes what he is doing now&amp;#8230; or he is taking a high risk approach to taking his career to a new level.&lt;/p&gt;
&lt;p&gt;PS &lt;a href=&quot;http://www.sainsburys.co.uk&quot; title=&quot;Sainsburys&quot;&gt;Sainsburys&lt;/a&gt; - bad on you for not appearing in the show - slap! to punish you I will be defecting for precisely one shop - oh wait like you care!&lt;/p&gt;</content>
		<author>
			<name>Ben King</name>
			<uri>http://www.benking.me.uk</uri>
		</author>
		<source>
			<title type="html">benking.me.uk</title>
			<subtitle type="html">The world according to Ben...</subtitle>
			<link rel="self" href="http://www.benking.me.uk/feed/"/>
			<id>http://www.benking.me.uk/feed/</id>
			<updated>2008-07-21T19:17:03+00:00</updated>
		</source>
	</entry>

	<entry xml:lang="en">
		<title type="html">DRM, Copyright, the saga goes on&#8230;</title>
		<link href="http://www.benking.me.uk/2008/01/11/drm-copyright-the-saga-goes-on/"/>
		<id>http://blogs.bit10.net/ben/2008/01/11/drm-copyright-the-saga-goes-on/</id>
		<updated>2008-01-11T10:02:19+00:00</updated>
		<content type="html">&lt;p&gt;&#160;Commenting on: &#160;&lt;a href=&quot;http://www.theregister.co.uk/2008/01/11/att_want_to_block_copyrighted_material_at_network_level/&quot;&gt;http://www.theregister.co.uk/2008/01/11/att_want_to_block_copyrighted_material_at_network_level/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The solution to all this is very very simple.&lt;/p&gt;
&lt;p&gt;I want the luxury of being able to download whatever material I want, when I want from where I want in whatever format I want. That as a customer is what I want, and the customer is always right.&lt;/p&gt;
&lt;p&gt;The only question is what I am prepared to pay for it, and how. As I don&amp;#8217;t want to be bound to any particular channel (iTunes for example), and I don&amp;#8217;t want to be paying per use, there is only one option which is some form of Digital&#160;Download License, which we pay an amount of money per year (say &#163;150), to do whatever we want online, bit like the TV license.&lt;/p&gt;
&lt;p&gt;The question obviously is, how do the respective rights holders get their slice of the pie, well simply offer a discount on the license fee to anyone happy to run some form of software that monitors what copyright material you are downloading and reports that somewhere for statistical analysis for revenue distribution.&lt;/p&gt;
&lt;p&gt;This won&amp;#8217;t work however if I am required to buy more than one license or there is in anyway some restrictions, for example you can download everything except shows by NBC.&lt;br /&gt;
&#160;&lt;/p&gt;</content>
		<author>
			<name>Ben King</name>
			<uri>http://www.benking.me.uk</uri>
		</author>
		<source>
			<title type="html">benking.me.uk</title>
			<subtitle type="html">The world according to Ben...</subtitle>
			<link rel="self" href="http://www.benking.me.uk/feed/"/>
			<id>http://www.benking.me.uk/feed/</id>
			<updated>2008-07-21T19:17:03+00:00</updated>
		</source>
	</entry>

	<entry xml:lang="en">
		<title type="html">Vyatta - Clustering</title>
		<link href="http://www.benking.me.uk/2008/01/04/vyatta-clustering/"/>
		<id>http://blogs.bit10.net/ben/2008/01/04/vyatta-clustering/</id>
		<updated>2008-01-04T10:48:29+00:00</updated>
		<content type="html">&lt;p&gt;The latest subscription release of &lt;a target=&quot;_blank&quot; href=&quot;http://www.vyatta.com&quot; title=&quot;Vyatta&quot;&gt;Vyatta&lt;/a&gt;, 2.3, has seen the addition of clustering capability, which has added greatly to the high availability features of the product.&lt;/p&gt;
&lt;p&gt;Previously high availability was really limited to VRRP, which was great but had a couple of issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;You couldn&amp;#8217;t use VRRP across VIF interfaces, which made high availability for &amp;#8216;router on a stick solutions&amp;#8217; tricky.&lt;/li&gt;
&lt;li&gt;We experienced a few issues with interface bouncing, especially on gigabit interfaces.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;VRRP is however a very nice solution, each virtual address is associated with a virtual MAC address that the currently actively router associates with the appropriate interface, the switchover is nearly instanteous.&lt;/p&gt;
&lt;p&gt;The new clustering functionality in Vyatta is based upon the &lt;a target=&quot;_blank&quot; href=&quot;http://www.linux-ha.org/&quot; title=&quot;Linux HA&quot;&gt;Linux HA&lt;/a&gt; project, which takes a slightly more simple but arguably more effective approach to the HA whereby when a failure is detected the virtual IP is reassigned to appropriate interface on the secondary router and a gratuitous arp sent out across the associated network segment to mitigate any arp cache issues.&lt;/p&gt;
&lt;p&gt;The HA functionality also allows for failover of the ipsec vpn service, at the moment this works pretty simplistically by simply stopping or starting the service as needed, thus on the currently inactive server the VPN service and therefore tunnels simply aren&amp;#8217;t up.&lt;/p&gt;
&lt;p&gt;Lets take a look at a relatively simple multisite HA Vyatta solution and the associated configuration.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.benking.me.uk/wp-content/uploads/2008/01/vyatta-cluster-example.jpg&quot; title=&quot;Vyatta Cluster Example&quot;&gt;&lt;img src=&quot;http://www.benking.me.uk/wp-content/uploads/2008/01/vyatta-cluster-example.thumbnail.jpg&quot; alt=&quot;Vyatta Cluster Example&quot; /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;We have two sites, each with a pair of Vyattas configured as router, vpn, firewall, and nat. Behind them is a multi-segment internal network.&lt;/p&gt;
&lt;h6&gt;Interfaces&lt;/h6&gt;
&lt;p&gt;ldn-router1 interfaces:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;interfaces {&#160;loopback lo { 

&#160;address 10.1.1.251 { 

&#160;	prefix-length: 24 

&#160;} 

} 

ethernet eth0 { 

&#160;description: &quot;Internet&quot; 

&#160;address 98.76.54.31 

&#160;	prefix-length: 28 

&#160;} 

} 

ethernet eth1 { 

&#160;description: &quot;Servers&quot; 

&#160;address 10.1.10.251 { 

&#160;	prefix-length: 24 

&#160;} 

} 

ethernet eth2 { 

&#160;description: &quot;Workstations&quot; 

&#160;address 10.1.101.251 { 

&#160;	prefix-length: 24 

&#160;} 

} 

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;ldn-router2 interfaces:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;interfaces {&#160;loopback lo { 

&#160;address 10.1.1.252 { 

&#160;	prefix-length: 24 

&#160;} 

} 

ethernet eth0 { 

&#160;description: &quot;Internet&quot; 

&#160;address 98.76.54.32 { 

&#160;	prefix-length: 28 

&#160;} 

} 

ethernet eth1 { 

&#160;description: &quot;Servers&quot; 

&#160;address 10.1.10.252 { 

&#160;	prefix-length: 24 

&#160;} 

} 

ethernet eth2 { 

&#160;description: &quot;Workstations&quot; 

&#160;address 10.1.101.252 { 

&#160;	prefix-length: 24 

&#160;} 

} 

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The important thing to notice here is that, the virtual &amp;#8216;active&amp;#8217; addresses aren&amp;#8217;t configured on the network interfaces themselves, instead they come later in the cluster configuration.&lt;/p&gt;
&lt;p&gt;The New York site configuration is the same, except of course the IP addresses are changed accordingly.&lt;/p&gt;
&lt;h6&gt;Cluster&lt;/h6&gt;
&lt;pre&gt;&lt;code&gt;cluster {&#160;interface eth0 

&#160;pre-shared-secret: &quot;!secret!&quot; 

&#160;keepalive-interval: 2 

&#160;dead-interval: 10 

&#160;group &quot;ldn-cluster1&quot; { 

&#160;	primary: &quot;ldn-router1&quot; 

&#160;	secondary &quot;ldn-router2&quot; 

&#160;	auto-failback: true 

&#160;	monitor 12.34.56.73 

&#160;	service &quot;98.76.54.33&quot; 

&#160;	service ipsec 

&#160;	service &quot;10.1.10.1&quot; 

&#160;	service &quot;10.1.101.1&quot; 

&#160;} 

} 

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The cluster configuration on each router is identical (unless you want to do certain clever things such as run a different routing configuration in failover!). The interface definition is just for the interface that you want to monitor via. You can have multiple monitors however a failover will occur if &lt;strong&gt;any&lt;/strong&gt; monitor returns a failure, in some ways this is a help and some ways its a hindrance, personally I prefer to just monitor an outside address and if its not available then go to failover where hopefully it will be (especially if we use different external blocks by router).&lt;/p&gt;
&lt;p&gt;When a router becomes the active member of the cluster, it scans the route table for matches to the service IP and assigns the service IP to the appropriate interface, it then sends a gratuitous arp out of that interface to avoid any arp cache issues.&lt;/p&gt;
&lt;h6&gt;&lt;strong&gt;Routes&lt;/strong&gt;&lt;/h6&gt;
&lt;p&gt;One downside of the Vyatta downing the ipsec tunnel when that router is not active, is that you can then only address that router on its dedicated addresses, for example if I wanted to do some remote maintenance ldn-router2 from the New York site while it wasn&amp;#8217;t active, the only way I would be able to do so is either to log onto a machine on the London subnet and go via that, or use the public external IP (which I probably don&amp;#8217;t want publically accessible anyway).&lt;/p&gt;
&lt;p&gt;The solution is very simple, due to the way that VPN route matching works. When making a packet routing decision Vyatta checks the VPN tunnels for a local/remote match first, then checks against the routing table, therefore if we add a static route to each router for the whole internal network to go via its partner, we get a really neat solution:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;protocols {&#160;static { 

&#160;	route 10.0.0.0/8 { 

&#160;	next-hop: 10.1.10.252 

&#160;	} 

&#160;} 

} 

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Thus if a router has the VPN tunnel up (i.e. its active), it never checks the routing table and traffic goes direct, if the router has no VPN tunnel (i.e. its passive), it simply forwards the traffic to the active router.&lt;/p&gt;
&lt;h6&gt;VPN&lt;/h6&gt;
&lt;p&gt;The VPN configuration in a cluster is basically the same as a standard configuration, except the local and remote public IPs are the cluster addresses.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;vpn {&#160;ipsec { 

&#160;	ipsec-interfaces { 

&#160;	interface eth0 

&#160;} 

&#160;ike-group &quot;ike-ny&quot; { 

&#160;	proposal 1 { 

&#160;		encryption: &quot;aes256&quot; 

&#160;	} 

&#160;	lifetime: 3600 

&#160;} 

&#160;esp-group &quot;esp-ny&quot; { 

&#160;	proposal 1 { 

&#160;		encryption: &quot;aes256&quot; 

&#160;	} 

&#160;	proposal 2 { 

&#160;		encryption: &quot;3des&quot; 

&#160;		hash: &quot;md5&quot; 

&#160;	} 

&#160;	lifetime: 1800 

&#160;} 

&#160;site-to-site { 

&#160;	peer 12.34.56.73 { 

&#160;		authentication { 

&#160;		pre-shared-secret: &quot;secret&quot; 

&#160;	} 

&#160;	ike-group: &quot;ike-ny&quot; 

&#160;	local-ip: 98.76.54.33 

&#160;	tunnel 13 { 

&#160;		local-subnet: 10.1.0.0/16 

&#160;		remote-subnet: 10.3.0.0/16 

&#160;		esp-group: &quot;esp-ny&quot; 

&#160;	} 

&#160;} 

} 

&lt;/code&gt;&lt;/pre&gt;
&lt;h6&gt;NAT&lt;/h6&gt;
&lt;p&gt;An easy pitfall on the NAT configuration is to forget that Vyatta processes source NAT &lt;strong&gt;before &lt;/strong&gt;checking vpn or routing table matches. The fix is simply to exclude your internal network as a destination in the NAT configuration.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;nat {&#160;rule 101 { 

&#160;	type: &quot;source&quot; 

&#160;	outbound-interface: &quot;eth0&quot; 

&#160;	source { 

&#160;		network: &quot;10.1.101.0/24&quot; 

&#160;		} 

&#160;	destination { 

&#160;		network: &quot;!10.0.0.0/8&quot; 

&#160;	} 

&#160;	outside-address { 

&#160;		address: 98.76.54.31 

&#160;	} 

&#160;} 

} 

&lt;/code&gt;&lt;/pre&gt;
&lt;h6&gt;VIFs&lt;/h6&gt;
&lt;p&gt;As i mentioned earlier, Vyattas implementation of VRRP doesn&amp;#8217;t allow you to use VRRP on virtual VLAN interfaces, which is frankly a little annoying (although it will be fixed in the next release hopefully).&lt;/p&gt;
&lt;p&gt;However under clustering it works perfectly, as the service IP can match and be assigned to any interface, real or virtual.&lt;/p&gt;
&lt;h6&gt;Conclusion&lt;/h6&gt;
&lt;p&gt;The clustering in Vyatta has added just enough simple HA clustering functionality that &amp;#8216;just works&amp;#8217; to enable us to deploy far more complex and reliable solutions than was previously possible.&lt;/p&gt;
&lt;p&gt;This is also just the tip of the iceberg, in future releases we can expect to see multiple cluster (allowing Active/Active configurations) and extra services added to the failover capability.&lt;/p&gt;</content>
		<author>
			<name>Ben King</name>
			<uri>http://www.benking.me.uk</uri>
		</author>
		<source>
			<title type="html">benking.me.uk</title>
			<subtitle type="html">The world according to Ben...</subtitle>
			<link rel="self" href="http://www.benking.me.uk/feed/"/>
			<id>http://www.benking.me.uk/feed/</id>
			<updated>2008-07-21T19:17:03+00:00</updated>
		</source>
	</entry>

</feed>
