Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Guy Axlerod
Dec 29, 2008
I'm looking for a new Security Gateway that will handle Site-to-Site and Client VPN. I'm no expert in this area, and neither is my coworker.

We have about 15 people at my site, and about 5 at the other, and we'd be connecting to AWS as well.

I'd really like it if the client VPN would work with the OS native VPN clients on both OSX and Windows. Failing that, the client needs to be readily available and not be garbage.

I'm asking for a thing that probably doesn't exist here, but it would also be really nice if they somehow used Google Apps to authenticate, because that's the closest thing we have to single sign-on at the moment.

Adbot
ADBOT LOVES YOU

Guy Axlerod
Dec 29, 2008
Thanks for the advice all.

Last time I looked at the Meraki MX, it sounded like they wouldn't handle the AWS VPN which was a dealbreaker for us. I'll have to look at them again, maybe ask for a trial.

Also, we're 90% OSX, am I wrong in thinking that AD doesn't make sense for us?

Guy Axlerod
Dec 29, 2008
You pay for office for interoperability with clients/suppliers/government, or whatever applies to your business. People who don't interact with the outside can probably get away with something else. But then, you probably want to manage just one thing, so pick one depending on where your critical mass is.

Guy Axlerod
Dec 29, 2008
I led a couple training classes for Xerox service reps. They were good and nice, but then they decided dealership networks should do all the sales and service. So unless you're on a government contract, or some other $Bigmoney customer, you don't have real Xerox service and it probably shows.

Guy Axlerod
Dec 29, 2008
My spam folder is full of "Are you stuck under a rock? I'll send help!" gently caress off with your default drip campaign.

Guy Axlerod
Dec 29, 2008

BonoMan posted:

You know that black mirror style phishing attack that claims they have you watching porn or something and you gotta bitcoin them or they'll tell all your contacts?


I was hoping this was a suggestion to help the previous poster with people abusing sudo. I have pictures of you jacking off, but as long as you don't do something stupid with sudo I will not release them.

Guy Axlerod
Dec 29, 2008

IUG posted:

My boss wants me to make a script that will rebuild a Linux system on failure. One part of that is recreating a SSH account to connect to other systems. That would involve a SSH private and public key being stored somewhere. I'm trying to avoid checking in a private key into Git of course.

Is Conjur any good as a secrets storage system? I'm been looking at it, but it seems like yet another under documented piece of open source software, and I don't want to invest the time in learning it unless it's worth it..

I wouldn't reuse the private key. Regenerate a new keypair on build, and have the new public key added where it needs to be. That has some assumptions about the other systems you are connecting to though.

Guy Axlerod
Dec 29, 2008
Yeah, that's weird because that isn't a documented API action. Sometimes there are actions that use a permission with a different name, like s3:headobject needs the s3:getobject permission.

You can try adding the workdocs:UpdateUser action like the other poster suggested, or you can try just applying the policy as generated and ignore the error.

Guy Axlerod
Dec 29, 2008
You'd have just an exporter on the target nodes. If you have it at all, I mostly have apps that expose their metrics in Prometheus format. Then a central instance of Prometheus to scrape those exporters/endpoints.
I do have multiple instances of Prometheus, each with their own areas of responsibility.this gets tricky when I want to correlate metrics on different instances, but I make do.

Guy Axlerod
Dec 29, 2008
No wonder the DevOps guy left.

Guy Axlerod
Dec 29, 2008
I should have a keybind for sudo !! but I'd probably just forget that too.

Guy Axlerod
Dec 29, 2008
Some of the commands are just mindless, expect to look up the syntax every time. Consulting the documentation is not a bad thing.

Adbot
ADBOT LOVES YOU

Guy Axlerod
Dec 29, 2008
I'm pretty sure op is dealing with Sony playstation devkits so they probably can't virtualize this. My friend is a solo dev and complained about the static IP requirement.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply