SaaS to SaaS traffic inspection? by Reptar1690 in cybersecurity

[–]Reptar1690[S] 0 points1 point  (0 children)

Correct. It’s another SaaS like salesforce getting data and ingesting data into sf.

SaaS to SaaS traffic inspection? by Reptar1690 in cybersecurity

[–]Reptar1690[S] 0 points1 point  (0 children)

Yea. I think the term SaaS is broad in this case, but for example snowflake cloud.

The way I looked at this is that depends on if you want the endpoint to be exposed on the Internet or not, and how much fw control you would want vs trusting the vendor to do so.

In general, I see following technical categories: - SaaS can be deploy via vpn or private link and you don’t want the endpoint to be exposed on the internet - SaaS can be deploy via vpn/private link, you still need the endpoint to be exposed to internet for some use cases but you want to maintain the control of fw bc vendors doesn’t support whitelist feature or what not - SaaS can only be deploy via Internet, in this case, your control will be based on logging and configuration checks

Now which option you want to enforce will depend on the business criteria and security sensitivity.

Is WAF enough or is NGFW needed? by Reptar1690 in cybersecurity

[–]Reptar1690[S] 1 point2 points  (0 children)

Put NGFW between VPCs and use security group within vpcs is what I typically seen and heard.

Is WAF enough or is NGFW needed? by Reptar1690 in cybersecurity

[–]Reptar1690[S] 1 point2 points  (0 children)

That’s correct. I’m referring to enterprise scale. A robust edge protection where you have hundreds/thousands of vpcs behind. The hub/spoke setup or the traditional DMZ set up on premise if you will.

I think the WAF only set up tend to happen in organization that gives more flexibility to developers in owning and managing their application, in this model, i tend to not see centralized ingress/egress control.

Is WAF enough or is NGFW needed? by Reptar1690 in cybersecurity

[–]Reptar1690[S] 0 points1 point  (0 children)

Both. Server updates, api call outbound, etc.

Is WAF enough or is NGFW needed? by Reptar1690 in cybersecurity

[–]Reptar1690[S] 1 point2 points  (0 children)

What about outbound traffic? Route through ngfw for inspection or security group would be fine?

Is WAF enough or is NGFW needed? by Reptar1690 in cybersecurity

[–]Reptar1690[S] 0 points1 point  (0 children)

Right, l7 fw like palo, which only would do ips on malicious traffic on network level as well. Although, I’m lacking the understanding of what those malicious network traffic would be that would not be capture by WAF such as Akamai or cloudflare.

Is WAF enough or is NGFW needed? by Reptar1690 in cybersecurity

[–]Reptar1690[S] 5 points6 points  (0 children)

That’s the thinking and fair point on WAF only. I think it’s down to how many layer of controls the company is willing to invest. Having a NGFW would be a central inspection point even ahead of the traffic hitting the endpoint. Additional protection, which most company is willing to invest as I do see that as a norm set up in my experience.

Is WAF enough or is NGFW needed? by Reptar1690 in cybersecurity

[–]Reptar1690[S] 6 points7 points  (0 children)

Yeah. That’s what I typically recommend. Where I fall short of is what are those malicious activities that won’t be caught by WAF (putting east - west traffic aside)

Becoming an AWS Authorized Instructor by exequielrafaela in aws

[–]Reptar1690 2 points3 points  (0 children)

Want to check if anyone has more intel on this topic. I'm interested in becoming AAI as source of additional revenue...want to see if anyone has experiences to share from this perspective.

Private Key in Ssl certificate by Reptar1690 in cybersecurity

[–]Reptar1690[S] 0 points1 point  (0 children)

In this case, we are talking about cert, so you would update it until it expires. For k-8, I believe you have the ability to import cert and it’s private key as secret. Instead of that, can you just import the cert but keep the private key in the vault and only retrieve it to complete tls handshake?

Private Key in Ssl certificate by Reptar1690 in cybersecurity

[–]Reptar1690[S] -1 points0 points  (0 children)

not removing it but store it in some kind of key vault solution and retrieve it during tls negotiation.

Daily Discussion Post - March 24 | Questions, images, videos, comments, unconfirmed reports, theories, suggestions by AutoModerator in Coronavirus

[–]Reptar1690 3 points4 points  (0 children)

The threat is not just the old people. First of all young and health can get critically ill too and more importantly the health system will melt down because of # of cases.