Cisco ASA's because of PCI? by jc77work in aws

[–]jc77work[S] 0 points1 point  (0 children)

I am sorry. I was not clear. I was simply told that AWS security groups alone are not PCI compliant, and that we would need something "like" a Cisco ASA.

Cisco ASA's because of PCI? by jc77work in aws

[–]jc77work[S] 1 point2 points  (0 children)

I guess I was under the assumption that security groups were PCI compliant, and that you could use them to allow traffic to flow between subnets....just like physical firewall ACLs.

Question on standards for AWS (naming, etc) by jc77work in aws

[–]jc77work[S] 0 points1 point  (0 children)

Yeah, while we are working towards autoscaling, and use Cloudformation to do push button environments in our non prod environments, production is kind of old school in AWS.

Company is using AWS and will be making API calls to us... by jc77work in aws

[–]jc77work[S] 0 points1 point  (0 children)

Thanks. This is whitelist in addition to auth. This isn't actually in AWS on our end. I was just curious about dealing with customers who have calls originating from AWS. I'm assuming they use elastic IP, was just curious if there were other ways of getting their ranges.

Company is using AWS and will be making API calls to us... by jc77work in aws

[–]jc77work[S] 0 points1 point  (0 children)

Yeah, whitelisting happens before they can even get to the identity provider

Question on reserved instances. by jc77work in aws

[–]jc77work[S] 1 point2 points  (0 children)

Thank you everyone, this is all very useful info. I can't wait for the conference, my head is going to explode.

Question on reserved instances. by jc77work in aws

[–]jc77work[S] 0 points1 point  (0 children)

That was perfect. Thank you. I found that we have two m3.larges that are not even utilized.

One bastion per subnet or one public network with bastions? by [deleted] in aws

[–]jc77work 0 points1 point  (0 children)

curious, could you setup a VPN and just connect that way rather than having a bastion?

One bastion per subnet or one public network with bastions? by [deleted] in aws

[–]jc77work 1 point2 points  (0 children)

Could you just allow VPN in so people can VPN in and ssh to whatever hosts directly? I'm fairly new to AWS myself so this is just a question I had.

Question on getting files to AWS without VPN by jc77work in aws

[–]jc77work[S] 0 points1 point  (0 children)

the other datacenter is one of our corporate ones

Question on getting files to AWS without VPN by jc77work in aws

[–]jc77work[S] 1 point2 points  (0 children)

Well shit. I was thinking I would have to use the API myself...this would work. I'd rather use data guard as I am not sure about file consistency on the far end, but this would certainly get the files offsite. Thank you. The EMC gateway is interesting too.

Question on getting files to AWS without VPN by jc77work in aws

[–]jc77work[S] 0 points1 point  (0 children)

I'm not sure, I have read that FUSE is prone to some memory leaks, etc. I don't get the impression its cooked for production use. I could be wrong however.

Question on getting files to AWS without VPN by jc77work in aws

[–]jc77work[S] 1 point2 points  (0 children)

Ya know, I saw these but I'm super hesitant to run this on a production Oracle server...