4 ms·
By definition, everything installed increases your attack surface. The decision to use it or not should be a risk-based one considering the value of what you ge
by batch12 3y ago
By definition, everything installed increases your attack surface. The decision to use it or not should be a risk-based one considering the value of what you get from using the product against the additional exposure. Having a single, properly secured and managed VPN appliance is much better than many unmanaged or kinda-managed entry points into a network.
- josephcsible 3y agoIt's not VPN vs. no VPN. It's crapware like Ivanti and Zscaler vs. sane things like OpenVPN and WireGuard.
- batch12 3y agoMaybe I've missed it (very likely), is there an enterprise-grade product that allows easy management of WireGuard or OpenVPN for say 20-30k users/endpoints and that integrates easily with Active Directory and a centralized MFA provider? Do these products provide support agreements? To be fair, I have no love for Ivanti or Zscaler, but I do understand why companies choose them over some standalone, open source products.
- AgentK20 3y agoTailscale? Unless I'm misunderstanding the use-case (which I probably am)
- 1oooqooq 3y agoTailscale et al probably doesn't give kickbacks on large contracts like Ivanti et al do.
- simplyaccont 3y agovpn its just small part of what zscaler does. its a bunch of security related products
- josephcsible 3y agoYes, but the VPN is the only useful part. The rest is what makes it crapware.
- simplyaccont 3y agothe rest is what companies need and pay money for. vpn is door opener
- olyjohn 3y agoThis is the question I heard constantly when I was working in IT. You know what it led to? Us using trash like Ivanti and Solarwinds.
- tsujamin 3y agoMy advice tends to be using SASE things like AppProxy - you can have your less-than-stellar enterprise business apps exposed outside of the LAN without putting them up as a target on the public internet
- dfox 3y agoWhile you are right there is one pretty important additional point: the whole concept of network entry point. Building this kind of security perimeter invariable leads to internal security becoming ignored and everything inside the network having some completely informal and random trust relationships with other devices in the network (and usually when thats get documented for the purposes of setting up internal firewalls you get three versions: what really happens, which is subset of how the firewalls are configured and then how that is documented). And this kind of Enterprise VPN with bunch of buzzwords products tend to be correlated with exactly this approach of totally ignoring what is inside the perimeter and replacing careful design of that with some other “Enterprise Endpoint Security Non-solution”.