4 ms·
If they have such hacking attempts, console access should be gated by a jumpbox that SSH/ipsec secured by SPA portknocking. For external services, have transpar
by king_nothing 8y ago
If they have such hacking attempts, console access should be gated by a jumpbox that SSH/ipsec secured by SPA portknocking. For external services, have transparent proxies with deep SPI/IPS and IP acls out in front.
- danielhlockard 8y agoPort knocking is security by obscurity. How about a VPN like a real company.
- azinman2 8y agoGoogle famously ditched VPNs because you can’t trust the inside networks either. https://www.blog.google/products/google-cloud/how-use-beyondcorp-ditch-your-vpn-improve-security-and-go-cloud/amp/ https://www.blog.google/products/google-cloud/how-use-beyond...
- gray_-_wolf 8y agoSure but it still adds another layer.