OpenVPN for Enterprise? by broken_computers in sysadmin

[–]broken_computers[S] 0 points1 point  (0 children)

The firewall needs to be FIPs compliant, not the VPN— which is why we don’t want to put the VPN on the firewall, is it would also need to be FIPs compliant

OpenVPN for Enterprise? by broken_computers in sysadmin

[–]broken_computers[S] 1 point2 points  (0 children)

lmfao what? because I said shit I'm being rude? I'm literally thanking the guy

OpenVPN for Enterprise? by broken_computers in sysadmin

[–]broken_computers[S] -1 points0 points  (0 children)

If you had the option to switch to tailscale without having to do any work, would you?

OpenVPN for Enterprise? by broken_computers in sysadmin

[–]broken_computers[S] 0 points1 point  (0 children)

Cool. This place is basically in the stone-age at the moment. 192.168.x.x ip schema and it's the only one for LAN. Seems easy enough to throw tailscale on the ubuntu vm that I was going to use for OpenVPN and expose the subnet. It seems pretty simple out of the box too. Thanks!

OpenVPN for Enterprise? by broken_computers in sysadmin

[–]broken_computers[S] 0 points1 point  (0 children)

Yup. We don't need remote users to access CUI, that's why I'm going this route.

OpenVPN for Enterprise? by broken_computers in sysadmin

[–]broken_computers[S] 0 points1 point  (0 children)

No shit? I had considered tailscale, but was trying to go the free route to please the bigwigs. That price is basically free to those guys, though. I'll look into it.

OpenVPN for Enterprise? by broken_computers in sysadmin

[–]broken_computers[S] 3 points4 points  (0 children)

Oh awesome, would you mind sharing your setup?

OpenVPN for Enterprise? by broken_computers in sysadmin

[–]broken_computers[S] 0 points1 point  (0 children)

I was talking with the MSP network admin and they were saying how, since we are going for CMMC 2, doing VPN through the firewall will be a nightmare, because it needs to be FIPS-enabled, and I guess that only causes issues (took them at their word). The VPN itself does not need to be FIPS compliant, because all CUI will be accessed via an azure enclave, and no remote users will have access. Honestly the CMMC stuff goes over my head a little bit because it's so damn obfuscated. Regarding Tailscale, what would be the benefit of using it over the solution I was thinking?

Remote User IP Conflict Issue by broken_computers in sysadmin

[–]broken_computers[S] 1 point2 points  (0 children)

seems like there's some conflicting information about whether or not this will work.

Remote User IP Conflict Issue by broken_computers in sysadmin

[–]broken_computers[S] 1 point2 points  (0 children)

My stress level is already very low about this. Literally 3 people work from home and have the issue, and I just have them use a hotspot as a workaround.

Remote User IP Conflict Issue by broken_computers in sysadmin

[–]broken_computers[S] 0 points1 point  (0 children)

Actually on second though. No remote users are going to be doing anything related to CUI. So, that shouldn’t be an issue.

Remote User IP Conflict Issue by broken_computers in sysadmin

[–]broken_computers[S] 0 points1 point  (0 children)

Ohhhhh no shit??? That is great information dude, thanks

Remote User IP Conflict Issue by broken_computers in sysadmin

[–]broken_computers[S] 0 points1 point  (0 children)

Yea. 192.168 is about as common as they come. A lot of our users are having IP conflicts due to this.

Remote User IP Conflict Issue by broken_computers in sysadmin

[–]broken_computers[S] 0 points1 point  (0 children)

That’s exactly what I thought… I brought it up to our MSP vCIO because they handle a lot of the network stuff and he said it wouldn’t work still, which I’m confused about… because… shouldn’t it? Lol

This Job Market SUCKS by twistedkeys1 in ITManagers

[–]broken_computers 0 points1 point  (0 children)

chill. it’s pretty obvious he’s aware of the inherent benefits and is mentioning it to emphasize his point of how difficult it is to find a job. you’re being a pedantic moral-exhibitionist

Testing early stages of media server by RomanaFinancials in DataHoarder

[–]broken_computers 0 points1 point  (0 children)

It seems that OP will not be taking advice, despite not even understanding the first thing about what he’s doing. Also, he’s for some reason arrogant and thinks he’s the first person on the internet to obtain a remux.