ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Napkin design...let's go LAN'less

    IT Discussion
    lanless nu skewl
    8
    40
    9.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DashrenderD
      Dashrender
      last edited by

      @scottalanmiller said:

      ics many mechanisms in a VPN but is not a VPN. A VPN extends a LAN, a Jump Box proxies to it. Proxying with user

      As for the Jump boxes, Why make administration something that can be done from anywhere? Sure, those managed boxes might provide other services to the internet at large, like web service, but why open port 22 to the internet at large? Instead you can put all those port 22's behind the jump box allowing logon only from the jump box. Hopefully this provides better security.

      coliverC 1 Reply Last reply Reply Quote 0
      • coliverC
        coliver @Dashrender
        last edited by

        @Dashrender said:

        @scottalanmiller said:

        ics many mechanisms in a VPN but is not a VPN. A VPN extends a LAN, a Jump Box proxies to it. Proxying with user

        As for the Jump boxes, Why make administration something that can be done from anywhere? Sure, those managed boxes might provide other services to the internet at large, like web service, but why open port 22 to the internet at large? Instead you can put all those port 22's behind the jump box allowing logon only from the jump box. Hopefully this provides better security.

        I thought that was kind of the point. Proxy the management through a jump box.

        scottalanmillerS 1 Reply Last reply Reply Quote 2
        • scottalanmillerS
          scottalanmiller @coliver
          last edited by

          @coliver said:

          @Dashrender said:

          @scottalanmiller said:

          ics many mechanisms in a VPN but is not a VPN. A VPN extends a LAN, a Jump Box proxies to it. Proxying with user

          As for the Jump boxes, Why make administration something that can be done from anywhere? Sure, those managed boxes might provide other services to the internet at large, like web service, but why open port 22 to the internet at large? Instead you can put all those port 22's behind the jump box allowing logon only from the jump box. Hopefully this provides better security.

          I thought that was kind of the point. Proxy the management through a jump box.

          Exactly.

          DashrenderD 1 Reply Last reply Reply Quote 1
          • DashrenderD
            Dashrender @scottalanmiller
            last edited by

            @scottalanmiller said:

            @coliver said:

            @Dashrender said:

            @scottalanmiller said:

            ics many mechanisms in a VPN but is not a VPN. A VPN extends a LAN, a Jump Box proxies to it. Proxying with user

            As for the Jump boxes, Why make administration something that can be done from anywhere? Sure, those managed boxes might provide other services to the internet at large, like web service, but why open port 22 to the internet at large? Instead you can put all those port 22's behind the jump box allowing logon only from the jump box. Hopefully this provides better security.

            I thought that was kind of the point. Proxy the management through a jump box.

            Exactly.

            Yup, that's where I was going with that. It has nothing to do with being LANless, and as Scott already said, everything to do with security.

            1 Reply Last reply Reply Quote 0
            • travisdh1T
              travisdh1
              last edited by

              LAN'less napkin design, something like this?

              FATeknollogeeF 1 Reply Last reply Reply Quote 0
              • FATeknollogeeF
                FATeknollogee @travisdh1
                last edited by

                @travisdh1 Who/what is in charge of "controlling" all those users & their access?

                scottalanmillerS 1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @FATeknollogee
                  last edited by

                  @FATeknollogee said:

                  @travisdh1 Who/what is in charge of "controlling" all those users & their access?

                  ownCloud.

                  dafyreD FATeknollogeeF 2 Replies Last reply Reply Quote 0
                  • dafyreD
                    dafyre @scottalanmiller
                    last edited by dafyre

                    @scottalanmiller said:

                    @FATeknollogee said:

                    @travisdh1 Who/what is in charge of "controlling" all those users & their access?

                    ownCloud.

                    Or the System Admin who manages that server.

                    Edit: Ideally the oC Server would be integrated into some form of central authentication -- AD, AzureAD, or something.

                    scottalanmillerS travisdh1T 2 Replies Last reply Reply Quote 1
                    • FATeknollogeeF
                      FATeknollogee @scottalanmiller
                      last edited by

                      @scottalanmiller said:

                      @FATeknollogee said:

                      @travisdh1 Who/what is in charge of "controlling" all those users & their access?

                      ownCloud.

                      I assumed the users will access more than oC even though the drawing doesn't show that?

                      scottalanmillerS 1 Reply Last reply Reply Quote 1
                      • scottalanmillerS
                        scottalanmiller @dafyre
                        last edited by

                        @dafyre said:

                        @scottalanmiller said:

                        @FATeknollogee said:

                        @travisdh1 Who/what is in charge of "controlling" all those users & their access?

                        ownCloud.

                        Or the System Admin who manages that server.

                        Edit: Ideally the oC Server would be integrated into some form of central authentication -- AD, AzureAD, or something.

                        Maybe not ideally. If that is the only service, use it as the authentication authority.

                        1 Reply Last reply Reply Quote 2
                        • scottalanmillerS
                          scottalanmiller @FATeknollogee
                          last edited by

                          @FATeknollogee said:

                          @scottalanmiller said:

                          @FATeknollogee said:

                          @travisdh1 Who/what is in charge of "controlling" all those users & their access?

                          ownCloud.

                          I assumed the users will access more than oC even though the drawing doesn't show that?

                          Ah, well that's different then.

                          travisdh1T 1 Reply Last reply Reply Quote 0
                          • travisdh1T
                            travisdh1 @dafyre
                            last edited by

                            @dafyre said:

                            @scottalanmiller said:

                            @FATeknollogee said:

                            @travisdh1 Who/what is in charge of "controlling" all those users & their access?

                            ownCloud.

                            Or the System Admin who manages that server.

                            Edit: Ideally the oC Server would be integrated into some form of central authentication -- AD, AzureAD, or something.

                            Right. If you have more than a single server and/or service it'd be easier to manage with LDAP/AD/AzureAD.

                            1 Reply Last reply Reply Quote 0
                            • travisdh1T
                              travisdh1 @scottalanmiller
                              last edited by

                              @scottalanmiller said:

                              @FATeknollogee said:

                              @scottalanmiller said:

                              @FATeknollogee said:

                              @travisdh1 Who/what is in charge of "controlling" all those users & their access?

                              ownCloud.

                              I assumed the users will access more than oC even though the drawing doesn't show that?

                              Ah, well that's different then.

                              I should've just labeled the server as "Services" instead of "OwnCloud"

                              1 Reply Last reply Reply Quote 2
                              • 1
                              • 2
                              • 2 / 2
                              • First post
                                Last post