ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    ZeroTier: is this a good time to use...

    IT Discussion
    zerotier rds rdp vpn
    8
    91
    26.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller @Dashrender
      last edited by

      @Dashrender said:

      @scottalanmiller said:

      @Dashrender said:

      I was talking a bit more generically for my DHCP server on my LAN - if a laptop stays off beyond my 8 lease, that IP will be assigned to something else.

      What's the use case for doing that, though?

      What do you mean? This is the default way windows DHCP works. After the IP lease expires, it simply goes back into the pool.

      The question is... why would you be using it in a ZT scenario? Why have DHCP for ZT addresses at all? What's the end goal?

      DashrenderD 1 Reply Last reply Reply Quote 0
      • DashrenderD
        Dashrender @dafyre
        last edited by

        @dafyre said:

        @scottalanmiller said:

        @Dashrender said:

        I was talking a bit more generically for my DHCP server on my LAN - if a laptop stays off beyond my 8 lease, that IP will be assigned to something else.

        What's the use case for doing that, though?

        He's talking about generic DHCP on a LAN.

        Correct - I am talking about my LAN. I'm not assigning IPs to the ZT network adapters.

        scottalanmillerS 1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller @Dashrender
          last edited by

          @Dashrender said:

          @dafyre said:

          @scottalanmiller said:

          @Dashrender said:

          I was talking a bit more generically for my DHCP server on my LAN - if a laptop stays off beyond my 8 lease, that IP will be assigned to something else.

          What's the use case for doing that, though?

          He's talking about generic DHCP on a LAN.

          Correct - I am talking about my LAN. I'm not assigning IPs to the ZT network adapters.

          Oh, I guess I missed something then.

          DashrenderD 1 Reply Last reply Reply Quote 0
          • DashrenderD
            Dashrender @scottalanmiller
            last edited by

            @scottalanmiller said:

            @Dashrender said:

            @scottalanmiller said:

            @Dashrender said:

            I was talking a bit more generically for my DHCP server on my LAN - if a laptop stays off beyond my 8 lease, that IP will be assigned to something else.

            What's the use case for doing that, though?

            What do you mean? This is the default way windows DHCP works. After the IP lease expires, it simply goes back into the pool.

            The question is... why would you be using it in a ZT scenario? Why have DHCP for ZT addresses at all? What's the end goal?

            Yeah I don't, never said I did.

            1 Reply Last reply Reply Quote 0
            • DashrenderD
              Dashrender @scottalanmiller
              last edited by

              @scottalanmiller said:

              @Dashrender said:

              @dafyre said:

              @scottalanmiller said:

              @Dashrender said:

              I was talking a bit more generically for my DHCP server on my LAN - if a laptop stays off beyond my 8 lease, that IP will be assigned to something else.

              What's the use case for doing that, though?

              He's talking about generic DHCP on a LAN.

              Correct - I am talking about my LAN. I'm not assigning IPs to the ZT network adapters.

              Oh, I guess I missed something then.

              I was giving @dafyre an example of when IP's change - my LAN based DHCP will give out the same IP to another device after a leas expires.

              What we don't know - does the ZT DHCP follow normal protocols and hand out an IP after a lease expires? or does it assign it for life?

              scottalanmillerS 1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller @Dashrender
                last edited by

                @Dashrender said:

                What we don't know - does the ZT DHCP follow normal protocols and hand out an IP after a lease expires? or does it assign it for life?

                There is no ZT DHCP. That's where the confusion came from. ZT does not use DHCP, so there is no connection to DHCP-like behaviour. Pertino does not either.

                A 1 Reply Last reply Reply Quote 0
                • A
                  Alex Sage @scottalanmiller
                  last edited by

                  @scottalanmiller said:

                  There is no ZT DHCP.

                  What? Then how do addresses get assigned?

                  scottalanmillerS 1 Reply Last reply Reply Quote 1
                  • scottalanmillerS
                    scottalanmiller @Alex Sage
                    last edited by

                    @anonymous said:

                    What? Then how do addresses get assigned?

                    Via the client. Remember that the client talks to the server. No need for something like DHCP.

                    dafyreD 1 Reply Last reply Reply Quote 2
                    • dafyreD
                      dafyre @scottalanmiller
                      last edited by

                      @scottalanmiller said:

                      @anonymous said:

                      What? Then how do addresses get assigned?

                      Via the client. Remember that the client talks to the server. No need for something like DHCP.

                      Scott is correct here. If you check a Windows system with ZT installed, and look at the ipv4 properties of the adapter, you will see that by default the IP address & DNS boxes are set to "static" but they are blank.

                      1 Reply Last reply Reply Quote 4
                      • DashrenderD
                        Dashrender
                        last edited by

                        Cool - OK then you can effectively say that the IP assigned on the ZT will never change 🙂

                        1 Reply Last reply Reply Quote 1
                        • wrx7mW
                          wrx7m
                          last edited by

                          In terms of the gateway feature, is it Linux connector + bridged mode?

                          dafyreD 1 Reply Last reply Reply Quote 0
                          • dafyreD
                            dafyre @wrx7m
                            last edited by dafyre

                            @wrx7m said:

                            In terms of the gateway feature, is it Linux connector + bridged mode?

                            That is supposed to be the way it works, but I haven't been able to get it to work like that. 😞

                            If I want it as a "gateway", I just set it up as a router, and add static routes on the physical routers on each site.

                            DashrenderD 1 Reply Last reply Reply Quote 2
                            • DashrenderD
                              Dashrender @dafyre
                              last edited by

                              @dafyre said:

                              @wrx7m said:

                              In terms of the gateway feature, is it Linux connector + bridged mode?

                              That is supposed to be the way it works, but I haven't been able to get it to work like that. 😞

                              If I want it as a "gateway", I just set it up as a router, and add static routes on the physical routers on each site.

                              that doesn't allow for ethernet level access - definitely not the same thing at all.

                              dafyreD 1 Reply Last reply Reply Quote 0
                              • dafyreD
                                dafyre @Dashrender
                                last edited by

                                @Dashrender said:

                                @dafyre said:

                                @wrx7m said:

                                In terms of the gateway feature, is it Linux connector + bridged mode?

                                That is supposed to be the way it works, but I haven't been able to get it to work like that. 😞

                                If I want it as a "gateway", I just set it up as a router, and add static routes on the physical routers on each site.

                                that doesn't allow for ethernet level access - definitely not the same thing at all.

                                Sadly, you are very much correct.

                                1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller
                                  last edited by

                                  That's why ZT refers to it as a bridge, not a router. It's true bridging functionality that is needed to make it work as intended.

                                  DashrenderD 1 Reply Last reply Reply Quote 1
                                  • DashrenderD
                                    Dashrender @scottalanmiller
                                    last edited by

                                    @scottalanmiller said:

                                    That's why ZT refers to it as a bridge, not a router. It's true bridging functionality that is needed to make it work as intended.

                                    That's what I thought, but @dafyre is saying he's been unable to get it to work.

                                    dafyreD 1 Reply Last reply Reply Quote 0
                                    • J
                                      Jason Banned @FATeknollogee
                                      last edited by

                                      @FATeknollogee said:

                                      Type 3: Users (are contractors), they connect via VPN from overseas

                                      Seems like a bad idea. Usually employees are given VPN access from company owned devices. a VPN is too much exposure for non-company owned devices and for people who aren't full employees. I would look into some other form of access, RD Gateway with RDS or Ctirix etc for these people.

                                      FATeknollogeeF 1 Reply Last reply Reply Quote 1
                                      • dafyreD
                                        dafyre @Dashrender
                                        last edited by

                                        @Dashrender said:

                                        @scottalanmiller said:

                                        That's why ZT refers to it as a bridge, not a router. It's true bridging functionality that is needed to make it work as intended.

                                        That's what I thought, but @dafyre is saying he's been unable to get it to work.

                                        I have not been able to get it to work. I got a post out on their community, but haven't heard anything back yet, lol.

                                        1 Reply Last reply Reply Quote 0
                                        • FATeknollogeeF
                                          FATeknollogee @Jason
                                          last edited by

                                          @Jason said:

                                          @FATeknollogee said:

                                          Type 3: Users (are contractors), they connect via VPN from overseas

                                          Seems like a bad idea. Usually employees are given VPN access from company owned devices. a VPN is too much exposure for non-company owned devices and for people who aren't full employees. I would look into some other form of access, RD Gateway with RDS or Ctirix etc for these people.

                                          Are you saying access via ZT is not a good idea?

                                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                                          • scottalanmillerS
                                            scottalanmiller @FATeknollogee
                                            last edited by

                                            @FATeknollogee said:

                                            @Jason said:

                                            @FATeknollogee said:

                                            Type 3: Users (are contractors), they connect via VPN from overseas

                                            Seems like a bad idea. Usually employees are given VPN access from company owned devices. a VPN is too much exposure for non-company owned devices and for people who aren't full employees. I would look into some other form of access, RD Gateway with RDS or Ctirix etc for these people.

                                            Are you saying access via ZT is not a good idea?

                                            Correct. ZT is a VPN. VPNs from arbitrary devices is normally a bad idea. The only exception to this is when you would have happily exposed the LAN to the Internet and this is purely a handy control of IP addresses. If security is your goal, you are bypassing security using a VPN in this role. VPNs are very dangerous because they are about exposure.

                                            DashrenderD 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 4 / 5
                                            • First post
                                              Last post