3 ms·
Why is fronting these systems with a central haproxy with TLS termination or similar not an option?
by 9dev 1y ago
Why is fronting these systems with a central haproxy with TLS termination or similar not an option?
- whatevaa 1y agoFronting a switch management interface with haproxy? Are you sure that is a good idea?
- 9dev 1y agoYes. If we're talking about handling TLS termination and putting an IP behind a sensible hostname, I don't see what's wrong about using a reverse proxy. Note that this does not imply making it accessible on the internet.
- FuriouslyAdrift 1y agoYet more infra that must now be managed and a point of failure. No thank you.
- 9dev 1y agoWell. That, or maintaining bespoke PKI and internal CA, along with manually renewing certificates with ever-shortened expiration periods as demanded by browsers. Pick your poison.
- FuriouslyAdrift 1y agoWindows infra so certificate services is already baked in for 802.1x, etc.
- dvdkon 1y agoBecause then you have plain HTTP running over your network. The issue here (I presume) is not how to secure access over the Internet, but within an internal network. Plenty of people leave these devices without encrypted connections, because they are in a "secure network", but you should never rely on such a thing.
- 9dev 1y agoNothing stops you from using a self-signed certificate with a ridiculous expiration period for HTTPS between the reverse proxy and the device in question.
- FuriouslyAdrift 1y agoExcept browsers and other software that are becoming hard-coded to block access to such devices. We used to use Firefox solely for internal problem devices with IP and subnet exclusions but even that is becoming difficult.
- fanf2 1y agoUse the self-signed cert between the proxy and the problem device; everything else talks to the proxy.
- cpach 1y agoOr Wireguard.
- FuriouslyAdrift 1y agoUsing VPNs on server infrastructure to punch a hole is a resume generating event.
- 9dev 1y agoWireguard is not a VPN, it’s a protocol that can be used for a lot of things.
- FuriouslyAdrift 1y agoThe wireguard protocol is an encapsulation or tunneling protocol... which is, by definition, a virtualized private network protocol. It's not different from IPSec, GRE, VXLAN, etc. It's just the new hotness. We use VXLAN extensively in our network, btw, and IKEv2/IPSec tunnels between sites.