3 ms·
Even now, some large traditional sites put static public IPs on workstations. When I was a lbl.gov, you got a (minimally firewalled) public ip via dhcp, and the
by subway 8y ago
Even now, some large traditional sites put static public IPs on workstations. When I was a lbl.gov, you got a (minimally firewalled) public ip via dhcp, and the hostname sent by your workstation was used to create a dns record of foo.dhcp.lbl.gov. You could request a static address for your host, and you'd be assigned an even less firewalled ip along with a foo.lbl.gov record.
A decade later this still seems to be at least partly in place, as I'm able to browse the webserver running on an old colleague's desktop.
- 0xffff2 8y agoWow. I work for another US government agency down the road from LBNL, and here I can't even see many internal servers from my laptop because there is a firewall between the (wired!) laptop-accessible network and the inner ring that the servers are on. I think my sysadmin group would have a collective heart attack if they saw that setup! It's quite incredible to me how independent various parts (and pseudo parts like the national labs) are from each other.
- subway 8y agoLBNL is an incredibly open, yet monitored network (in the spirit of the collaborative research that goes on there.) You can be certain that most every packet in, out, or through the place gets captured and inspected by Bro (errr, I guess Zeek now. https://www.zeek.org/ https://www.zeek.org/ ) I should also mention that not every host had a public IP. I worked with the group that managed midrange compute clusters, which were always behind NAT, with bastion login nodes.