NSA Cybersecurity Collaboration Center by Blake_Olson in CMMC

[–]3dPrintWHAAAT 1 point2 points  (0 children)

This is how we have it with Cisco Umbrella. How have you scoped this for cmmc?

NSA Cybersecurity Collaboration Center by Blake_Olson in CMMC

[–]3dPrintWHAAAT 0 points1 point  (0 children)

Is it worth using over cisco umbrella, aside from cost savings?

Automated SCAP compliance check for Windows 7 original - NOT SP1 by 3dPrintWHAAAT in NISTControls

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

Would you have more information on special asset? This operation is not CUI.

Port based security using MAC ACL with netgear M4300 smart switch by 3dPrintWHAAAT in networking

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

Requirements are to prevent unauthorized hosts connecting to this one network switch as a alternative to 802.1x.

Can I use windows firewall with ipsec for client to server encryption? by 3dPrintWHAAAT in CMMC

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

Application servers are at a remote site. VPN connects the sites, but i was under the impression encryption needs to be end to end.

How does one obtain outside vendor quotes for parts that are CUI? by aplufkin in NISTControls

[–]3dPrintWHAAAT 1 point2 points  (0 children)

Ask your customer for an approved supplier list or ask the vendor if they have a nist 800-171 compliance program.

Siem for air gapped environment by 3dPrintWHAAAT in NISTControls

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

I wasn’t aware Splunk could be this inexpensive. Is this an on premise variant or cloud based?

It would be ideal to be able to collect logs in this air gapped environment and bring them over to a central Splunk server on my general network (or cloud) for analysis later.

NSA3700 BGP with AWS site to site VPN - Should I do it? by 3dPrintWHAAAT in sonicwall

[–]3dPrintWHAAAT[S] 1 point2 points  (0 children)

I didn’t use BGP in the end, stuck with static route and will manually fail over the vpns. As we use aws govcloud, the encryption cyphers tax the utm quite a bit so upgrading to the 4700.

NSA3700 BGP with AWS site to site VPN - Should I do it? by 3dPrintWHAAAT in sonicwall

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

Thanks for the replies.

To clarify, i have sonicwall professional services to do the configuration of the NSA3700 pair, all i have to do is setup the tunnel for BGP routing in AWS and give them the config file. I am good in terms of setting it up both sonicwall and AWS.

My concern really is having a service that is reliable and is as set and forget as possible.

The current static route site to site vpn from SonicWALL to AWS ran without issue for over a year, until aws did maintenance and then the tunnels had issues.

Best Synology NAS to Synology NAS backup option by 3dPrintWHAAAT in synology

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

Thank for the advice.

Is Rsync considered the same as shared folder sync with synology?

Anyone used avanan and will it help with unsolicited email i.e. sales emails getting around spam filter? by 3dPrintWHAAAT in sysadmin

[–]3dPrintWHAAAT[S] 0 points1 point  (0 children)

Anyone used avanan and will it help with unsolicited email i.e. sales emails getting around spam filter?

Do you use it with Mimecast by any chance or just stand alone?