3 ms·
The biggest challenges are always internal/privileged access and policy/privilege, DR(ecovery|esponse), and maintenance/configuration management. You've covered
by jankedeen 10y ago
The biggest challenges are always internal/privileged access and policy/privilege, DR(ecovery|esponse), and maintenance/configuration management. You've covered
these well.
Couple notes:
* VPNs are not panacea. My own experience is that ssh and significant key management (no password or emergency password only) is a more scalable strategy than relying solely on VPNs for small business. The whole default port thing with ssh is a no-brainer (don't do it + restrictive configurations of ssh for port forwarding and tunneling) as are the standard approaches to dealing with abuse of any service (fail2ban, etc...) Add to this a design which sandboxes ssh access based on time/privilege and only allows escape|access to critical resources via another mechanism.
* WAFs are great but are extremely high maintenance and can be a productivity and production malf and bottleneck waiting to happen.
* DDOS mitigation: https://www.akamai.com/us/en/solutions/products/cloud-security/ddos-protection-service.jsp https://www.akamai.com/us/en/solutions/products/cloud-securi... or the like.
- itaifrenkel 10y agoSSH does not cover all use cases. One example if you have an internal web service, how would you restrict access only to employees (without having it open to the internet?). SSO is not enough since you want the ports closed to non employees. Another example is accessing a database that is not configured with SSL. You don't want your info travelling in plaintext on the internet.
- jlgaddis 10y agoI work remotely. SSH is exactly what I use to access our internal-only (web) services.
- itaifrenkel 10y agoDo you use ssh as a socks proxy?
- jlgaddis 10y agoYes. Typically: $ ssh -D 8888 <bastion host> I have a Firefox add-on that makes it very easy to switch the proxy settings on and off.
- itaifrenkel 10y agoAnd do you find that non-techies can also handle this? Also, I think this won't cover DNS changes that a vpn client does
- jankedeen 10y agossh covers both of these cases.
- itaifrenkel 10y agoSame question. Do you refer to using SSH and socks proxy. If so, is that a viable solution, in your experience, with less techy employees?
- BillinghamJ 10y agoLess techy employees shouldn't be on any private/internal networks. Just give them an HTTPS web panel to work on authenticated by the SSO system.
- itaifrenkel 10y agoSSO is not enough. In secure systems you are ussually required to provide both network access, and applicative access restrictions
- jankedeen 10y agoIt would be utterly transparent. Please don't be ignorant.
- itaifrenkel 10y agoThere is another issue, that US citizens ussually do not encounter. When you setup a VPN on amazon, for example, you would like only some of the traffic (intranet) to go through that VPN (or SSH socks proxy). The rest of the traffic should go directly to the internet. The reason being is that the roundtrip is too costly. I am not sure configuring these settings are trivial, and VPN clients provide that out-of-the-box.