ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    What Are You Doing Right Now

    Scheduled Pinned Locked Moved Water Closet
    time waster
    88.9k Posts 287 Posters 52.3m Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JaredBuschJ
      JaredBusch @brandon220
      last edited by

      @brandon220 said in What Are You Doing Right Now:

      EASILY convinced a new client not to place a new server directly on a public IP with port 3389 open. I thought it was going to be a battle. Have them on board for a VPN.

      Why complicate it? Or is this not something that really needs to be public?

      brandon220B 1 Reply Last reply Reply Quote 1
      • scottalanmillerS
        scottalanmiller @1337
        last edited by

        @Pete-S said in What Are You Doing Right Now:

        Trying to get back into a switch after locking myself out with some erroneous vlan config. Hooked up to the console port now.

        Whoops

        1 Reply Last reply Reply Quote 0
        • brandon220B
          brandon220 @JaredBusch
          last edited by

          @JaredBusch I honestly assumed that it was no longer a good idea in terms of security. I have done it before with a NAT mapping and it worked fine. What is your view on this?

          scottalanmillerS 1 Reply Last reply Reply Quote 0
          • scottalanmillerS
            scottalanmiller @brandon220
            last edited by

            @brandon220 said in What Are You Doing Right Now:

            @JaredBusch I honestly assumed that it was no longer a good idea in terms of security. I have done it before with a NAT mapping and it worked fine. What is your view on this?

            We just had a thread on this last week about how RDP already is inside a VPN and the whole "need another VPN" thing is mostly just security theater based off of fake threats. Essentially all RDP risks come from having the port "too open" and leaving users exposed with really insecure passwords. No one every breaks into RDP, they always just guess the password. And if the VPN is secured the same, it's equally risky.

            JaredBuschJ 1 Reply Last reply Reply Quote 2
            • scottalanmillerS
              scottalanmiller
              last edited by

              Here is a thread on RDP Security specifically.

              https://mangolassi.it/topic/16698/the-myth-of-rdp-insecurity/

              1 Reply Last reply Reply Quote 0
              • JaredBuschJ
                JaredBusch @scottalanmiller
                last edited by

                @scottalanmiller said in What Are You Doing Right Now:

                @brandon220 said in What Are You Doing Right Now:

                @JaredBusch I honestly assumed that it was no longer a good idea in terms of security. I have done it before with a NAT mapping and it worked fine. What is your view on this?

                We just had a thread on this last week about how RDP already is inside a VPN and the whole "need another VPN" thing is mostly just security theater based off of fake threats. Essentially all RDP risks come from having the port "too open" and leaving users exposed with really insecure passwords. No one every breaks into RDP, they always just guess the password. And if the VPN is secured the same, it's equally risky.

                Right, I have a client that had a locally hosted LOB application. The main office users used a normal thick desktop app. The branch office users used RDP. The RDP was over the interoffice VPN that was already in place. Then their remote users used RDP over public internet. But I used basic firewall rules on the router to only allow RDP from their known IP blocks (I did a lookup on their home ISP and allowed from those entire CIDR blocks. A risk, but a very small one.

                Password policy was minimum of 14 characters.

                scottalanmillerS 1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @JaredBusch
                  last edited by

                  @JaredBusch said in What Are You Doing Right Now:

                  @scottalanmiller said in What Are You Doing Right Now:

                  @brandon220 said in What Are You Doing Right Now:

                  @JaredBusch I honestly assumed that it was no longer a good idea in terms of security. I have done it before with a NAT mapping and it worked fine. What is your view on this?

                  We just had a thread on this last week about how RDP already is inside a VPN and the whole "need another VPN" thing is mostly just security theater based off of fake threats. Essentially all RDP risks come from having the port "too open" and leaving users exposed with really insecure passwords. No one every breaks into RDP, they always just guess the password. And if the VPN is secured the same, it's equally risky.

                  Right, I have a client that had a locally hosted LOB application. The main office users used a normal thick desktop app. The branch office users used RDP. The RDP was over the interoffice VPN that was already in place. Then their remote users used RDP over public internet. But I used basic firewall rules on the router to only allow RDP from their known IP blocks (I did a lookup on their home ISP and allowed from those entire CIDR blocks. A risk, but a very small one.

                  Password policy was minimum of 14 characters.

                  And you can add extra controls like two factor authentication or brute force attack mitigation as well, if you feel the need.

                  1 Reply Last reply Reply Quote 0
                  • DashrenderD
                    Dashrender @JaredBusch
                    last edited by

                    @JaredBusch said in What Are You Doing Right Now:

                    On the phone with a Mitel tech trying to make it talk over the SIP trunk we have setup.

                    what's different from the setup I got working?

                    scottalanmillerS JaredBuschJ 2 Replies Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @Dashrender
                      last edited by

                      @Dashrender said in What Are You Doing Right Now:

                      @JaredBusch said in What Are You Doing Right Now:

                      On the phone with a Mitel tech trying to make it talk over the SIP trunk we have setup.

                      what's different from the setup I got working?

                      Yours works?

                      jajaja

                      DashrenderD 1 Reply Last reply Reply Quote 0
                      • DashrenderD
                        Dashrender @scottalanmiller
                        last edited by

                        @scottalanmiller said in What Are You Doing Right Now:

                        @Dashrender said in What Are You Doing Right Now:

                        @JaredBusch said in What Are You Doing Right Now:

                        On the phone with a Mitel tech trying to make it talk over the SIP trunk we have setup.

                        what's different from the setup I got working?

                        Yours works?

                        jajaja

                        You're a funny guy.

                        1 Reply Last reply Reply Quote 0
                        • WrCombsW
                          WrCombs
                          last edited by

                          Halfway through Coffee Number 4, And water number 2.
                          Debating on what's for lunch...

                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @WrCombs
                            last edited by

                            @WrCombs said in What Are You Doing Right Now:

                            Halfway through Coffee Number 4, And water number 2.
                            Debating on what's for lunch...

                            Probably a bathroom break, lol.

                            WrCombsW 1 Reply Last reply Reply Quote 1
                            • WrCombsW
                              WrCombs @scottalanmiller
                              last edited by

                              @scottalanmiller said in What Are You Doing Right Now:

                              @WrCombs said in What Are You Doing Right Now:

                              Halfway through Coffee Number 4, And water number 2.
                              Debating on what's for lunch...

                              Probably a bathroom break, lol.

                              I've had a few... LOL

                              1 Reply Last reply Reply Quote 0
                              • JaredBuschJ
                                JaredBusch @Dashrender
                                last edited by

                                @Dashrender said in What Are You Doing Right Now:

                                @JaredBusch said in What Are You Doing Right Now:

                                On the phone with a Mitel tech trying to make it talk over the SIP trunk we have setup.

                                what's different from the setup I got working?

                                Not a SIP trunk to the outside. THis is using a SIP trunk to interconnect a FreePBX install to a Mitel.

                                DashrenderD 1 Reply Last reply Reply Quote 1
                                • scottalanmillerS
                                  scottalanmiller
                                  last edited by

                                  Kids are still asleep here!

                                  1 Reply Last reply Reply Quote 0
                                  • DashrenderD
                                    Dashrender @JaredBusch
                                    last edited by

                                    @JaredBusch said in What Are You Doing Right Now:

                                    @Dashrender said in What Are You Doing Right Now:

                                    @JaredBusch said in What Are You Doing Right Now:

                                    On the phone with a Mitel tech trying to make it talk over the SIP trunk we have setup.

                                    what's different from the setup I got working?

                                    Not a SIP trunk to the outside. THis is using a SIP trunk to interconnect a FreePBX install to a Mitel.

                                    How is it coming?

                                    JaredBuschJ 1 Reply Last reply Reply Quote 0
                                    • RojoLocoR
                                      RojoLoco
                                      last edited by

                                      As we migrate from 1:1 physical servers to Hyper-V (yay, me!), I should have known these 1U little bastards wouldn't go quietly. Had to swap both drives from 1 machine with a borked RAID card to another that has been idle. Luckily it only took 2 reboots to sort the foreign config, and the devs have been given a stern "hurry up and move that data" warning.

                                      dafyreD 1 Reply Last reply Reply Quote 2
                                      • dafyreD
                                        dafyre @RojoLoco
                                        last edited by

                                        @RojoLoco said in What Are You Doing Right Now:

                                        As we migrate from 1:1 physical servers to Hyper-V (yay, me!), I should have known these 1U little bastards wouldn't go quietly. Had to swap both drives from 1 machine with a borked RAID card to another that has been idle. Luckily it only took 2 reboots to sort the foreign config, and the devs have been given a stern "hurry up and move that data" warning.

                                        You should give them a timeline. In 14 days it becomes your data is gone.

                                        RojoLocoR 1 Reply Last reply Reply Quote 0
                                        • RojoLocoR
                                          RojoLoco @dafyre
                                          last edited by

                                          @dafyre said in What Are You Doing Right Now:

                                          @RojoLoco said in What Are You Doing Right Now:

                                          As we migrate from 1:1 physical servers to Hyper-V (yay, me!), I should have known these 1U little bastards wouldn't go quietly. Had to swap both drives from 1 machine with a borked RAID card to another that has been idle. Luckily it only took 2 reboots to sort the foreign config, and the devs have been given a stern "hurry up and move that data" warning.

                                          You should give them a timeline. In 14 days it becomes your data is gone.

                                          These VMs have been ready since October. The owner gave them a deadline of xmas, then 1st of the year, now it's no real deadline. I really wish I could enforce any of what they have been told to do.

                                          dafyreD 1 Reply Last reply Reply Quote 0
                                          • dafyreD
                                            dafyre @RojoLoco
                                            last edited by

                                            @RojoLoco said in What Are You Doing Right Now:

                                            @dafyre said in What Are You Doing Right Now:

                                            @RojoLoco said in What Are You Doing Right Now:

                                            As we migrate from 1:1 physical servers to Hyper-V (yay, me!), I should have known these 1U little bastards wouldn't go quietly. Had to swap both drives from 1 machine with a borked RAID card to another that has been idle. Luckily it only took 2 reboots to sort the foreign config, and the devs have been given a stern "hurry up and move that data" warning.

                                            You should give them a timeline. In 14 days it becomes your data is gone.

                                            These VMs have been ready since October. The owner gave them a deadline of xmas, then 1st of the year, now it's no real deadline. I really wish I could enforce any of what they have been told to do.

                                            I'm sure you could arrange an unfortunate accident for them.

                                            DustinB3403D 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 4435
                                            • 4436
                                            • 4437
                                            • 4438
                                            • 4439
                                            • 4446
                                            • 4447
                                            • 4437 / 4447
                                            • First post
                                              Last post