while(true){💩};

  • 0 Posts
  • 26 Comments
Joined 2 years ago
cake
Cake day: June 11th, 2023

help-circle














  • Semperverus@lemmy.worldtoTechnology@lemmy.worldFireWall as a Service?
    link
    fedilink
    English
    arrow-up
    6
    ·
    edit-2
    4 months ago

    We use one of these at work! There are a couple of companies offering these solutions such as PaloAlto, Zscaler, etc. and they are typically of the “Next-Gen Firewall” variety (I.e. they scan the content of the packets rather than just routes and ports and such).

    The way they work is basically that you establish VPN connections to their endpoints, and they scan the traffic as it passes through. Like a VPN, you get a new IP address that is shared with other customers, but there is a way to pin your original IP in the packet headers if you need.

    These connections can be handled via one of a few ways:

    1. Software on the workstation (best option as it allows deeper traffic routing and control, as long as your workstations are locked down)

    2. IPSec tunnels configured on the building’s router service’s endpoints/datacenters

    3. GRE tunnels configured on the building’s router to the service’s endpoints/datacenters

    4. A physical firewall box that sits in front of your other hardware that does any of the above OR something bespoke

    Note that unless you have option 4, none of these replace traditional “dumb” firewalls. If you’re still using IPv4, you still need a NAT firewall.






  • Semperverus@lemmy.worldtoAsk Lemmy@lemmy.world*Permanently Deleted*
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    6 months ago

    Ahh yes, the old classic: being in the neutral position between the two extremes.

    I have the same problem in real life, but with the left/right crowd. I’ll get called one or the other until people clock me for what I am and then make fun of me by calling me an “enlightened centerist.”

    It’s always weird when you trigger a .ml user in particular though, because they become very aggressive or very “principaled” very quickly. A .world user is usually a little more metered, and just regular internet-brand angry, on average.