ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    CloudatCost OpenDNS Issue

    IT Discussion
    dns cloudatcost
    15
    184
    67.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • thanksajdotcomT
      thanksajdotcom
      last edited by

      It's a DC. It's my failover. What do I need to change?

      scottalanmillerS ? 2 Replies Last reply Reply Quote -1
      • scottalanmillerS
        scottalanmiller @thanksajdotcom
        last edited by

        @thanksajdotcom said:

        It's a DC. It's my failover. What do I need to change?

        OH! He publicly exposed a Domain Controller!!!

        You have it wide open, like it is sitting on a LAN. You have DNS, DHCP, AD, etc. open to the world because your "LAN" is the Internet!!

        1 Reply Last reply Reply Quote 0
        • ?
          A Former User @thanksajdotcom
          last edited by

          @thanksajdotcom said:

          It's a DC. It's my failover. What do I need to change?

          Change the Zone's the ports are allowed on. Only allow it on the VPN Zone. Aka Not Public.

          thanksajdotcomT 1 Reply Last reply Reply Quote 1
          • thanksajdotcomT
            thanksajdotcom
            last edited by

            Just lock down DNS to internal only or what?

            1 Reply Last reply Reply Quote -1
            • ?
              A Former User
              last edited by

              I would never trust that DC again. Time to rebuild.

              thanksajdotcomT 1 Reply Last reply Reply Quote 1
              • thanksajdotcomT
                thanksajdotcom @A Former User
                last edited by thanksajdotcom

                @Aaron-Studer said:

                I would never trust that DC again. Time to rebuild.

                It's secured with Webroot. Also, there's been no indication of an attack. I'm not decomming it without a good reason.

                scottalanmillerS 1 Reply Last reply Reply Quote -1
                • thanksajdotcomT
                  thanksajdotcom @A Former User
                  last edited by

                  @thecreativeone91 said:

                  @thanksajdotcom said:

                  It's a DC. It's my failover. What do I need to change?

                  Change the Zone's the ports are allowed on. Only allow it on the VPN Zone. Aka Not Public.

                  Ok, so in Windows Firewall?

                  1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller @thanksajdotcom
                    last edited by

                    @thanksajdotcom said:

                    @Aaron-Studer said:

                    I would never trust that DC again. Time to rebuild.

                    It's secured with Webroot. Also, there's been no indication of an attack. I'm not decomming it without a good reason.

                    It's not like he'll have it for long anyway. He doesn't have a datacenter license for every CPU in the cloud so he can't run anything but a demo license that expires in 90 days there.

                    ? thanksajdotcomT 2 Replies Last reply Reply Quote 0
                    • ?
                      A Former User
                      last edited by

                      At least you don't have any open SMB shares.

                      ? thanksajdotcomT 2 Replies Last reply Reply Quote 0
                      • ?
                        A Former User @A Former User
                        last edited by A Former User

                        @thecreativeone91 How do you know this? I bet he did it is a domain controller after all.

                        scottalanmillerS 1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller @A Former User
                          last edited by

                          @Aaron-Studer said:

                          @thecreativeone91 How do you know this?

                          You can just attempt to connect 🙂

                          1 Reply Last reply Reply Quote 1
                          • ?
                            A Former User
                            last edited by

                            I am using AJ as my DNS server now! THANKSAJ! =P

                            1 Reply Last reply Reply Quote 2
                            • ?
                              A Former User @scottalanmiller
                              last edited by

                              @scottalanmiller said:

                              @thanksajdotcom said:

                              @Aaron-Studer said:

                              I would never trust that DC again. Time to rebuild.

                              It's secured with Webroot. Also, there's been no indication of an attack. I'm not decomming it without a good reason.

                              It's not like he'll have it for long anyway. He doesn't have a datacenter license for every CPU in the cloud so he can't run anything but a demo license that expires in 90 days there.

                              Why don't you just run the Standard version. Granted Cloud@Cloud not having a infrastructure based firewall option is not really the place for something like a DC.

                              scottalanmillerS 1 Reply Last reply Reply Quote 0
                              • ?
                                A Former User
                                last edited by

                                DNS is working great for me.

                                ? 1 Reply Last reply Reply Quote 1
                                • ?
                                  A Former User @A Former User
                                  last edited by

                                  @thecreativeone91 Me too. Super Fast! So much better then OpenDNS!

                                  1 Reply Last reply Reply Quote 0
                                  • ?
                                    A Former User
                                    last edited by

                                    Your firewall should be blocking everything on your public connection except RDP.

                                    ? 1 Reply Last reply Reply Quote 0
                                    • scottalanmillerS
                                      scottalanmiller @A Former User
                                      last edited by

                                      @thecreativeone91 said:

                                      Why don't you just run the Standard version. Granted Cloud@Cloud not having a infrastructure based firewall option is not really the place for something like a DC.

                                      Standard isn't valid on a cloud. Because the VM moves around regularly and he can't lock it down, standard is not an option. Only DC is a valid option and only if he maintains a license for every CPU in the cloud. It's hundreds of millions of dollars to license Windows this way. While technical feasible, you can't actually run Windows on a cloud using your own licenses. You can in certain non-cloud VPS types, but not in this cloud-based VPS type. MS has special licenses that come from the provider to make this possible so that Amazon, for example, can offer it.

                                      ? ? 2 Replies Last reply Reply Quote 0
                                      • ?
                                        A Former User @scottalanmiller
                                        last edited by

                                        @scottalanmiller said:

                                        Standard isn't valid on a cloud. Because the VM moves around regularly and he can't lock it down, standard is not an option. Only DC is a valid option and only if he maintains a license for every CPU in the cloud. It's hundreds of millions of dollars to license Windows this way. While technical feasible, you can't actually run Windows on a cloud using your own licenses. You can in certain non-cloud VPS types, but not in this cloud-based VPS type. MS has special licenses that come from the provider to make this possible so that Amazon, for example, can offer it.

                                        Vultr offers Windows 2012 R2 for just $15 a month.

                                        scottalanmillerS 1 Reply Last reply Reply Quote 0
                                        • scottalanmillerS
                                          scottalanmiller @A Former User
                                          last edited by

                                          @Aaron-Studer said:

                                          Vultr offers Windows 2012 R2 for just $15 a month.

                                          Yes, everyone offers Windows except CloudatCost. They do "bring your own licensing" and leave it up to you to figure out that Microsoft doesn't offer any licenses that fit that scenario.

                                          1 Reply Last reply Reply Quote 0
                                          • ?
                                            A Former User @scottalanmiller
                                            last edited by A Former User

                                            @scottalanmiller said:

                                            @thecreativeone91 said:

                                            Why don't you just run the Standard version. Granted Cloud@Cloud not having a infrastructure based firewall option is not really the place for something like a DC.

                                            Standard isn't valid on a cloud. Because the VM moves around regularly and he can't lock it down, standard is not an option. Only DC is a valid option and only if he maintains a license for every CPU in the cloud. It's hundreds of millions of dollars to license Windows this way. While technical feasible, you can't actually run Windows on a cloud using your own licenses. You can in certain non-cloud VPS types, but not in this cloud-based VPS type. MS has special licenses that come from the provider to make this possible so that Amazon, for example, can offer it.

                                            Yeah But isn't Cloud@Cloud Technically a VPS that doesn't move around unless re-imaged. Odd thing is you can apply for license mobility to run every MS Server application in the cloud using SA. But you can't with windows server itself.

                                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 9
                                            • 10
                                            • 1 / 10
                                            • First post
                                              Last post