wop

joined 1 year ago
MODERATOR OF
 

Set up new #FreshRSS instance for now. I want to read more and stay up to date on certain topics and I figured I could give RSS another chance. Stays invite-only for now, but feel free to hit me up if you want to have an account.

 
 

Focus on decoding unknown strings.

 

Not gonna lie, wasn't that fun. Learned a lot, but felt lost multiple times. Probably gets better over time.

 

Doing some rooms on TryHackMe. Decided to create a write up of one room. Have to work on the format, but it should be fine for now.

Feedback is welcome!

 

I think I've never share one of my favorite articles with you.

Creating this was great and it has been a great resource ever since. I use SSH tunnel a lot in troubleshooting sessions and security demonstrations.

 

I am pleased to announce the launch of: forum.ittavern.com

More information can be found in this thread, but in short I miss the forum culture and want to create an open-minded and sustainable community.

I welcome you and look forward to great discussions.

[–] [email protected] 3 points 9 months ago
 

I am happy to share with you the new design of my blog.

New logo, new thumbnails, lots of CSS changes and everything is now hosted in a German DC.

The goal was to create a clean design and reduce the loading time even further.

Feedback is welcome.

 

Sending files over the internet. Been a pain in the past and I finally decided to host my own instance. It should be 'production' ready, but let me know if you encounter any problems.

[–] [email protected] 2 points 9 months ago

Currently using HedgeDoc for taking notes, but it is lacking some features, so I am trying to find and host some alternatives and compare them. And I hope I can find some time to play with my Flipper Zero....

 

So, every network engineer knows it: everyone else will blame the network and you have to prove them wrong.

There are multiple reason:

  • lack of knowledge
  • ignorance
  • passing on responsibility
  • laziness
  • ... There are more.

I am interested in how you react to 'The network is causing the problems' requests.

  • do you request certain information?
  • need an explanation?
  • what are you first steps?
  • do you have a runbook or some policy in place?

Without getting into too much detail, I request some or all of the following information before I start looking:

  • what are they trying to do? What is the desired outcome?
  • what is the error message? *(pref a screenshot!) *+ timestamp (for logs)
  • has it ever worked before?
  • since when isn't it working?
  • can you resolve domains?
  • Source Host > Destination Host:Port
  • Results of Ping + Powershell Test-NetConnection on Windows and Netcat on Linux (to test general connection, assuming TCP connection)

What I ask for and in what order depends on the person I am talking to. By the way, monitoring is my friend. If it says everything is fine, it usually is.

Side note Describing the actual proof that it is not the network depends heavily on the infrastructure and the problem, so this may be a discussion for another thread.


What are your first steps?

 

A quick & dirty solution that is available on most Linux hosts.

[–] [email protected] 2 points 9 months ago (1 children)

Does fortigate not have a form of DMVPN like Cisco?

ADVPN (Auto-discovery VPN) seems to be the equivalent. https://docs.fortinet.com/document/fortimanager/7.2.0/single-datacenter-for-enterprise/282533/advpn

Just curious why ISP/third party MPLS? Purely interest.

I guess it was easier at some point? - Taht was way before my time there. But we are going to replace the MPLS part with simple internet-breakout points on location and the the rest with SDWAN.

Also, did you find this purely from user complaining or have monitoring tool?

Purely from users complaining and other departments getting frustrated about why their stuff was not working (e.g. Citrix). The new FW had to be installed in a short time and 'everything' worked fine at first. Problems only occurred after some load was put on the network. We failed - as in network dep - by NOT doing a stress/limit test of the network and finding this problem immediately, and NOT implementing some kind of monitoring that would have notified us of all those lost packets and connections. We caught up, but we should have done it in the first place, because it is necessary.

I’m assuming using third party was supposed to offload the work/config from you?

Do you mean the ISP/MPLS provider? - If so, not really.

[–] [email protected] 2 points 10 months ago

I want to get into Ansible and I am building a testing env for it - home lab with various switches and routers, Fortinet, Palo, and a proxmox host server and some remote VPS. One of my goals for Q1 '24. Today I am going to prep the switches.

Besides that, I want to host my own NFTY server and I hope that I can get it online within this week.

[–] [email protected] 5 points 10 months ago (3 children)

I am currently transitioning into a Security role at work. One question would be: what are the must-have tools for every blue team?

  • Vuln-Scanner
  • Logging/ SIEM-Server
  • ...
[–] [email protected] 2 points 1 year ago

public key authentication ... is king.

I agree that port knocking won't replace any other hardening method, but I thought I'd look into it since it gets recommended so often. Not a big fan either.

[–] [email protected] 3 points 1 year ago

Learning things about Wireguard and implement it to secure my internet facing servers.

[–] [email protected] 1 points 1 year ago (1 children)

Being using rsync and borg for backups, but rclone is a great alternative and has even more functions.

[–] [email protected] 2 points 1 year ago (1 children)

Yeah, after more testing, we can say that the second IPStunnel was the issue. Re-worked the route over a single tunnel and the whole 100 Mbps are available again. Users are happy, I am happy. Even tho a little bit frustrating.

Thank you for your input!

[–] [email protected] 1 points 1 year ago

I fully agree. Those tools are so useful! - But, not too familiar with s_client - will look it up.

Thank you for letting me know. It seems that adding a separate image removes the URL to the article. Interesting and might be a bug.

[–] [email protected] 2 points 1 year ago* (last edited 1 year ago) (3 children)
[–] [email protected] 2 points 1 year ago

Yeah, notifications are really unreliable here. I've got another window for more stress test today. Going to post update later, or tomorrow. Focus on MTU/MSS

view more: ‹ prev next ›