3 ms·
Neat project. What we've been doing is using provider (software) firewalls for whitelisting IPs at the bastion level. In AWS we have a security group just for
by pquerna 10y ago
Neat project. What we've been doing is using provider (software) firewalls for whitelisting IPs at the bastion level.
In AWS we have a security group just for the Bastion inbound, and adding/removing IPs to that on-demand to allow access. I kind of assumed this was standard practice by now?
- tie_ 10y agoFiltering by IP addresses and ranges only gets you so far. What if one of the people who needs to log in logs in remotely? Or if a contractor is behind a dynamically changing IP address? Or if you have too many IP addresses and ranges to fit the limit of rules in a security group? So, while IP restriction is a standard practice, it is by no means the end of it all. I like the project as a cool and creative experiment,though, and that's what it says it is :)
- killerpopiller 10y agofiltering IP-adresses is an important security feature, if personnel needs to access it from non-white listed adresses, they first have to tunnel into Corporate Intranet you shouldn't expose your services for convenience