Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

anthonypants posted:

what's wrong with firewalld

host-based firewalls in the enterprise are lol as gently caress

Adbot
ADBOT LOVES YOU

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:


why's that (legit question)

Bulgogi Hoagie
Jun 1, 2012

We

690k line wlan driver, nice

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

windows firewall configured with GPO is Objectively Good and should be used in conjunction with proper zoning. linux is probably a clusterfuck to manage but nothing important happens on those garbage systems so whatever

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

Ciaphas posted:

why's that (legit question)

let's run the firewall on the same system normal users have access to, nothing could possibly go wrong

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
i bet someone will write some big effortpost about how actually it's not such a big deal because blah blah

have you considered that i'm right

FlapYoJacks
Feb 12, 2009

RISCy Business posted:

let's run the firewall on the same system normal users have access to, nothing could possibly go wrong

Normal users sure as poo poo don't have access to the engineering servers.

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

ratbert90 posted:

Normal users sure as poo poo don't have access to the engineering servers.

do you really want anyone besides network/security people to even have the possibility of touching your firewalls

compromised user account? rogue employee?

you're opening yourself up to way more risk than if you were to run a hardware firewall with good throughput on that network and only allow a much smaller subset of people to access it

also you wouldn't be janitoring firewalls on multiple different systems because you'd have really neat stuff like object groups

spankmeister
Jun 15, 2008






BangersInMyKnickers posted:

windows firewall configured with GPO is Objectively Good and should be used in conjunction with proper zoning. linux is probably a clusterfuck to manage but nothing important happens on those garbage systems so whatever

Look it's discount shaggar

FlapYoJacks
Feb 12, 2009

RISCy Business posted:

do you really want anyone besides network/security people to even have the possibility of touching your firewalls

compromised user account? rogue employee?

you're opening yourself up to way more risk than if you were to run a hardware firewall with good throughput on that network and only allow a much smaller subset of people to access it

also you wouldn't be janitoring firewalls on multiple different systems because you'd have really neat stuff like object groups

Who says I don't have a hardware firewall? :confused:

maskenfreiheit
Dec 30, 2004
ufc is mining bitcoin on people's machines

https://np.reddit.com/r/MMA/comments/7b4zdk/fight_pass_is_shady_ysk_ufc_fight_pass_is_using/dpf96js/

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

RISCy Business posted:

do you really want anyone besides network/security people to even have the possibility of touching your firewalls

compromised user account? rogue employee?

you're opening yourself up to way more risk than if you were to run a hardware firewall with good throughput on that network and only allow a much smaller subset of people to access it

also you wouldn't be janitoring firewalls on multiple different systems because you'd have really neat stuff like object groups

lol at thinking that you can't trust endpoint servers but also assuming your internal networks aren't hostile

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

east west threat model lol

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

RISCy Business posted:

do you really want anyone besides network/security people to even have the possibility of touching your firewalls

compromised user account? rogue employee?

you're opening yourself up to way more risk than if you were to run a hardware firewall with good throughput on that network and only allow a much smaller subset of people to access it

also you wouldn't be janitoring firewalls on multiple different systems because you'd have really neat stuff like object groups
having a firewall on your internal network is a fine idea, but why does that mean a firewall on a server is bad. what, specifically, is wrong with firewalld.

because if you can't explain why you think it's bad i'm just going to assume you hate it because it blocks you from doing things out-of-the-box, and that you hate selinux for similar reasons

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

PCjr sidecar posted:

lol at thinking that you can't trust endpoint servers but also assuming your internal networks aren't hostile

which is why you augment hardware firewalls with smart policy via gpo on windows or sudo policies on linux and firewall traffic in a way that makes sense?

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

anthonypants posted:

having a firewall on your internal network is a fine idea, but why does that mean a firewall on a server is bad. what, specifically, is wrong with firewalld.

if you have the resources to janitor potentially disparate iptables configs for hundreds or thousands of different servers then by all means, run firewalld

it's not specifically a firewalld issue, it's the issue of user accounts potentially having access to firewall configs to gently caress poo poo up in the first place

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

RISCy Business posted:

if you have the resources to janitor potentially disparate iptables configs for hundreds or thousands of different servers then by all means, run firewalld

it's not specifically a firewalld issue, it's the issue of user accounts potentially having access to firewall configs to gently caress poo poo up in the first place

what did you gently caress up to let user accounts have access to firewall configs

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
you know if you give someone sudo access on a box that doesn't automatically mean they get to use firewallctl, right

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

anthonypants posted:

you know if you give someone sudo access on a box that doesn't automatically mean they get to use firewallctl, right

oh geez i had no idea, thank you for enlightening me

spankmeister
Jun 15, 2008






At a ripe meeting a year or two ago DynDNS had a presentation about how they set p their nodes and they use iptables firewalls on their boxes and nothing else.

I wonder how that's working out for them.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

RISCy Business posted:

oh geez i had no idea, thank you for enlightening me
you're welcome. happy to help.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

spankmeister posted:

At a ripe meeting a year or two ago DynDNS had a presentation about how they set p their nodes and they use iptables firewalls on their boxes and nothing else.

I wonder how that's working out for them.

If you're consistent with it, which a large corporate with some kind of decent management platform should be, then you're probably sitting pretty good because even if an endpoint gets popped and opens up its own firewall everything else in the zone is going to ignore its traffic

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


quote:

Your username:

must be between 6 and 32 characters long.
must not contain spaces.
must not contain non-English characters.
must not start with pattern fp?-* and uni-*
can contain alphanumeric characters,-,_,@,.
cannot be the same as your password.


hmmmmm

edit: submitted the form, it gave a gateway timeout error. filled it out and resubmitted and got "that username is already in use", fucks sake

Powerful Two-Hander fucked around with this message at 23:31 on Nov 6, 2017

AARP LARPer
Feb 19, 2005

THE DARK SIDE OF SCIENCE BREEDS A WEAPON OF WAR

Buglord
why is this guy melting down about firewalls

Proteus Jones
Feb 28, 2013



WAR DOGS OF SOCHI posted:

why is this guy melting down about firewalls

Welcome to SA, home of the loving strangest of hills to die on

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:


Proteus Jones posted:

Welcome to SA, home of the loving strangest of hills to die on

I like the "facebook and twitter are incestuous hitlerholes that need to be burned to the ground and salted ASAP and never ever replaced" hill myself, i'd die on that

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:


then again maybe i'm rather less alone on that hill nowadays than i was a couple years ago idk

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

WAR DOGS OF SOCHI posted:

why is this guy melting down about firewalls

lol if your brain is so broken that you interpret anything i posted as a meltdown

AARP LARPer
Feb 19, 2005

THE DARK SIDE OF SCIENCE BREEDS A WEAPON OF WAR

Buglord
totally not angry about firewalls, got it

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
gotta scream "MELTDOWN" from my clown car every time someone has a dissenting opinion on the funny computer forum because my brain is poisoned

30 TO 50 FERAL HOG
Mar 2, 2005



RISCy Business posted:

why the gently caress are you running firewalld

put an ASA or something in there instead

lmao never use ASAs

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

NEED MORE MILK posted:

lmao never use ASAs
why not

power botton
Nov 2, 2011

I dunno who posted about SMB v1 but a huge amount of Fortune 500 companies are now reaching out to vendors asking if our products will break if they disable v1 so get in quick (enterprise quick? like 2 years?) before they do it.

CrazyLittle
Sep 11, 2001





Clapping Larry
lol I'm just dying to hear how level3's internal fuckup is responsible for nearly all of comcast going offline

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug
10 bucks says the bgp boys are at it again

wolrah
May 8, 2006
what?

CrazyLittle posted:

lol I'm just dying to hear how level3's internal fuckup is responsible for nearly all of comcast going offline

What I saw from my perspective, coming from AS27364 (Armstrong Cable in Ohio and routed through their home base in Pittsburgh, PA), is that all my traffic destined for Comcast was routing through NTT New York, then NTT Ashburn, then to Level3 where it all went to hell before reaching the Comcast network. Didn't matter if it was destined for Pittsburgh, Chicago, or Houston it all seemed to have issues when it hit Level3 in DC. Others were reporting issues with Level3 in Chicago, but I didn't see that.

Since 14:30 US Eastern time when things were fixed the route has instead been jumping straight from NTT to Comcast at 111 8th Ave. in NYC.

SeaborneClink
Aug 27, 2010

MAWP... MAWP!

CrazyLittle posted:

lol I'm just dying to hear how level3's internal fuckup is responsible for nearly all of comcast going offline

I'll go with "be a backbone provider and push a bad bgp route for $100, Alex"

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
yeah level3 leaked more specific versions of prefixes belonging to comcast and got overwhelmed

30 TO 50 FERAL HOG
Mar 2, 2005



we literally had a Comcast rep in our office pitching Comcast fiber since we want a 10gig link for a new project when it happened lmao

Adbot
ADBOT LOVES YOU

minivanmegafun
Jul 27, 2004

can confirm I saw the problem in Chicago too

  • Locked thread