5 ms·
Nothing stops you from using a self-signed certificate with a ridiculous expiration period for HTTPS between the reverse proxy and the device in question.
by 9dev 1y ago
Nothing stops you from using a self-signed certificate with a ridiculous expiration period for HTTPS between the reverse proxy and the device in question.
- FuriouslyAdrift 1y agoExcept browsers and other software that are becoming hard-coded to block access to such devices. We used to use Firefox solely for internal problem devices with IP and subnet exclusions but even that is becoming difficult.
- fanf2 1y agoUse the self-signed cert between the proxy and the problem device; everything else talks to the proxy.
- cpach 1y agoOr Wireguard.
- FuriouslyAdrift 1y agoUsing VPNs on server infrastructure to punch a hole is a resume generating event.
- 9dev 1y agoWireguard is not a VPN, it’s a protocol that can be used for a lot of things.
- FuriouslyAdrift 1y agoThe wireguard protocol is an encapsulation or tunneling protocol... which is, by definition, a virtualized private network protocol. It's not different from IPSec, GRE, VXLAN, etc. It's just the new hotness. We use VXLAN extensively in our network, btw, and IKEv2/IPSec tunnels between sites.
- 9dev 1y agoWireGuard can be used to create a virtualised private network, but doesn't do so on its own, or without additional infrastructure. WireGuard tunnels network packages securely, with high throughput, from an arbitrary point A to an arbitrary point B. No more, no less. Just because it can be used to recreate VPNs traditionally used to remotely dial into a secure network zone doesn't mean it shouldn't be used in far smaller use-cases. WireGuard doesn't constitute anything like a full VPN solution on its own.