ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Mesh Central

    IT Discussion
    4
    28
    2.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      AdamF
      last edited by

      I finally spun up a MC server VPS. How is everyone securing this? Besides the fact that I can setup 2FA for this, if I don't want to put this behind any proxy, what is the best approach to secure the web UI?

      S 2 Replies Last reply Reply Quote 1
      • S
        scottalanmiller @AdamF
        last edited by

        @AdamF Usernames, passwords, SSL/TLS and 2FA are the lockdowns you'd use anywhere. It's secure by default. If you can, do IP locking. But it is rare that you can do that.

        A 1 Reply Last reply Reply Quote 0
        • A
          AdamF @scottalanmiller
          last edited by

          @scottalanmiller said in Mesh Central:

          @AdamF Usernames, passwords, SSL/TLS and 2FA are the lockdowns you'd use anywhere. It's secure by default. If you can, do IP locking. But it is rare that you can do that.

          Excellent, just wanted to verify with someone else as well. Thanks Scott.

          1 Reply Last reply Reply Quote 0
          • S
            scottalanmiller @AdamF
            last edited by

            @AdamF said in Mesh Central:

            if I don't want to put this behind any proxy

            That doesn't do much anyway. There's really very little to do. It's a web page, so basically think of it link a bank website.

            A 1 Reply Last reply Reply Quote 1
            • A
              AdamF @scottalanmiller
              last edited by

              @scottalanmiller Hopefully getting those Pi's connected this weekend. (from the other thread)

              A 1 Reply Last reply Reply Quote 1
              • A
                AdamF @AdamF
                last edited by

                @scottalanmiller I am missing the 2FA option in the my account settings. I am missing something I suppose?

                S 1 Reply Last reply Reply Quote 0
                • S
                  scottalanmiller @AdamF
                  last edited by

                  @AdamF said in Mesh Central:

                  @scottalanmiller I am missing the 2FA option in the my account settings. I am missing something I suppose?

                  Because the name is dumb?

                  My Account >> Manage Authenticator App

                  A 1 Reply Last reply Reply Quote 1
                  • S
                    syko24
                    last edited by

                    They also added CrowdSec recently. @Ylian the developer also releases YouTube videos covering a lot of these topics and how to implement.

                    Youtube Video

                    S 1 Reply Last reply Reply Quote 0
                    • A
                      AdamF @scottalanmiller
                      last edited by

                      @scottalanmiller said in Mesh Central:

                      @AdamF said in Mesh Central:

                      @scottalanmiller I am missing the 2FA option in the my account settings. I am missing something I suppose?

                      Because the name is dumb?

                      My Account >> Manage Authenticator App

                      Nope. I just didn't RTFM. By default, it is in WAN and LAN mode. You have to switch it to WAN mode and give it a valid DNS name. Then that option shows up.

                      S 1 Reply Last reply Reply Quote 0
                      • S
                        scottalanmiller @AdamF
                        last edited by

                        @AdamF said in Mesh Central:

                        @scottalanmiller said in Mesh Central:

                        @AdamF said in Mesh Central:

                        @scottalanmiller I am missing the 2FA option in the my account settings. I am missing something I suppose?

                        Because the name is dumb?

                        My Account >> Manage Authenticator App

                        Nope. I just didn't RTFM. By default, it is in WAN and LAN mode. You have to switch it to WAN mode and give it a valid DNS name. Then that option shows up.

                        Oh right, been a long time since I did a new install. Forgot that they default to LAN. Why I wonder?

                        1 Reply Last reply Reply Quote 0
                        • S
                          scottalanmiller @syko24
                          last edited by

                          @syko24 said in Mesh Central:

                          They also added CrowdSec recently. @Ylian the developer also releases YouTube videos covering a lot of these topics and how to implement.

                          Youtube Video

                          Says unavailable. I think because it is a channel and not a video but ML thinks it is a video link.

                          S 1 Reply Last reply Reply Quote 0
                          • S
                            syko24 @scottalanmiller
                            last edited by

                            @scottalanmiller said in Mesh Central:

                            @syko24 said in Mesh Central:

                            They also added CrowdSec recently. @Ylian the developer also releases YouTube videos covering a lot of these topics and how to implement.

                            Youtube Video

                            Says unavailable. I think because it is a channel and not a video but ML thinks it is a video link.

                            Yeah that was supposed to be to the channel. Here is the CrowdSec video. Lots great videos on his channel for setting things up.

                            Youtube Video

                            1 Reply Last reply Reply Quote 0
                            • A
                              AdamF
                              last edited by

                              Well, this tool is amazing and just works. Nice job @Ylian !

                              S 1 Reply Last reply Reply Quote 3
                              • S
                                scottalanmiller @AdamF
                                last edited by

                                @AdamF said in Mesh Central:

                                Well, this tool is amazing and just works. Nice job @Ylian !

                                Yeah, it's definitely the best tool for this on the market. It's blown past everyone else. We are doing the AMT integration now and rolling out vPro anywhere that we can. It's just amazing.

                                A 1 Reply Last reply Reply Quote 0
                                • A
                                  AdamF @scottalanmiller
                                  last edited by

                                  @scottalanmiller said in Mesh Central:

                                  @AdamF said in Mesh Central:

                                  Well, this tool is amazing and just works. Nice job @Ylian !

                                  Yeah, it's definitely the best tool for this on the market. It's blown past everyone else. We are doing the AMT integration now and rolling out vPro anywhere that we can. It's just amazing.

                                  I know you use it for remote agents that are always installed (or at least I assume so), but are you also able to use it for "one off" remote sessions? For example, sometimes I will open a screen connect session for a quick support session. Then when finished, close the session, the end. Can we do that as well with MC?

                                  S 1 Reply Last reply Reply Quote 0
                                  • S
                                    scottalanmiller @AdamF
                                    last edited by

                                    @AdamF said in Mesh Central:

                                    @scottalanmiller said in Mesh Central:

                                    @AdamF said in Mesh Central:

                                    Well, this tool is amazing and just works. Nice job @Ylian !

                                    Yeah, it's definitely the best tool for this on the market. It's blown past everyone else. We are doing the AMT integration now and rolling out vPro anywhere that we can. It's just amazing.

                                    I know you use it for remote agents that are always installed (or at least I assume so), but are you also able to use it for "one off" remote sessions? For example, sometimes I will open a screen connect session for a quick support session. Then when finished, close the session, the end. Can we do that as well with MC?

                                    Yes, works fine for that. The end user just chooses "Run" instead of "install" and it works that way.

                                    1 Reply Last reply Reply Quote 1
                                    • A
                                      AdamF
                                      last edited by

                                      I have the agent running on 2 Pi's The 4 GB version of the Pi. The screen lag is incredibly SLOW. (running Raspian)
                                      Installing an agent on my windows laptop (8GB ram) is incredibly responsive and quick. Are there some tweaks to run on the Pis to improve the screen lag for remote viewing?

                                      A S 2 Replies Last reply Reply Quote 0
                                      • A
                                        AdamF @AdamF
                                        last edited by

                                        @AdamF said in Mesh Central:

                                        I have the agent running on 2 Pi's The 4 GB version of the Pi. The screen lag is incredibly SLOW. (running Raspian)
                                        Installing an agent on my windows laptop (8GB ram) is incredibly responsive and quick. Are there some tweaks to run on the Pis to improve the screen lag for remote viewing?

                                        It was 100% Pi related as suspected. Here's what I did to speed things up. (found on https://forums.raspberrypi.com/viewtopic.php?p=1983061&sid=eaf6504ffd4e15374cbd86907d954c67#p1983061)

                                        in /boot/config.txt
                                        uncomment this line:
                                        hdmi_force_hotplug=1

                                        commented out these lines:
                                        #dtoverlay=vc4-kms-v3d
                                        #max_framebuffers=2

                                        Then the resolution was really low despite the VNC resolution set in raspi-config, so after setting the above and rebooting I then set the 'display options' resolution in raspi-config to be the same as the VNC resolution.

                                        In my case I'm using 1920x1080, so that modified my config.txt to have these lines:

                                        hdmi_group=2
                                        hdmi_mode=82

                                        1 Reply Last reply Reply Quote 0
                                        • S
                                          scottalanmiller @AdamF
                                          last edited by

                                          @AdamF said in Mesh Central:

                                          I have the agent running on 2 Pi's The 4 GB version of the Pi. The screen lag is incredibly SLOW. (running Raspian)
                                          Installing an agent on my windows laptop (8GB ram) is incredibly responsive and quick. Are there some tweaks to run on the Pis to improve the screen lag for remote viewing?

                                          RP is pretty slow on that. The screen rendering on Linux for remoting isn't as robust.

                                          4GB 32bit is the fastest option.

                                          1 Reply Last reply Reply Quote 0
                                          • S
                                            scottalanmiller
                                            last edited by

                                            Make sure to update firmware.

                                            A 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post