Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • About Bonfire
Kevin Beaumont
@GossiTheDog@cyberplace.social  ·  activity timestamp 4 hours ago

IMHO - you shouldn't use BIG-IP F5 directly internet facing in 2025 if it's critical infrastructure, have it behind a cloud WAF and have the origin firewalled off to just the WAF service.

  • Copy link
  • Flag this post
  • Block
❄️☃️Merry Jerry🎄🌲
@jerry@infosec.exchange replied  ·  activity timestamp 4 hours ago

@GossiTheDog Also, your sonicwall, fortinet, and palo altos firewalls should be behind a firewall and not exposed to the internet

  • Copy link
  • Flag this comment
  • Block
Risotto Bias
@risottobias@toot.risottobias.org replied  ·  activity timestamp 3 hours ago

@jerry @GossiTheDog what firewall do you recommend your firewall be behind?

  • Copy link
  • Flag this comment
  • Block
Fishd
@Fishd@infosec.exchange replied  ·  activity timestamp 3 hours ago

@jerry @GossiTheDog

Your browser does not support the video tag.
GIF
GIF
Dean Winchester Reaction GIF
Dean Winchester Reaction GIF
  • Copy link
  • Flag this comment
  • Block
Jernej Simončič �
@jernej__s@infosec.exchange replied  ·  activity timestamp 3 hours ago

@jerry @GossiTheDog I replaced a client's Asa with pfSense on Monday. About 3 minutes of downtime, that's how long I needed to ssh in and run arping to announce the new MAC to their upstream.

  • Copy link
  • Flag this comment
  • Block
ocdtrekkie
@ocdtrekkie@mastodon.social replied  ·  activity timestamp 4 hours ago

@jerry @GossiTheDog This is a wild take. What firewall *would* you expose to the Internet?

  • Copy link
  • Flag this comment
  • Block
Kevin Beaumont
@GossiTheDog@cyberplace.social replied  ·  activity timestamp 4 hours ago

@ocdtrekkie @jerry I suspect they mean the management interface

  • Copy link
  • Flag this comment
  • Block
ineedsleeps
@ineedsleeps@infosec.exchange replied  ·  activity timestamp 4 hours ago

@jerry @GossiTheDog

use your firewall stack to protect your firewall stack

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this comment
  • Block
❄️☃️Merry Jerry🎄🌲
@jerry@infosec.exchange replied  ·  activity timestamp 4 hours ago

@ineedsleeps @GossiTheDog it's the only way to be sure

  • Copy link
  • Flag this comment
  • Block
Santa Caws
@cR0w@infosec.exchange replied  ·  activity timestamp 4 hours ago

@jerry @GossiTheDog

Ivanti has entered the chat like

Kool Aid Man busting through a wall in an old commercial.
Kool Aid Man busting through a wall in an old commercial.
Kool Aid Man busting through a wall in an old commercial.
  • Copy link
  • Flag this comment
  • Block
❄️☃️Merry Jerry🎄🌲
@jerry@infosec.exchange replied  ·  activity timestamp 4 hours ago

@cR0w @GossiTheDog I keep forgetting that there are still people who like to play with matches at the gas station

  • Copy link
  • Flag this comment
  • Block
RootWyrm 🇺🇦:progress:
@rootwyrm@weird.autos replied  ·  activity timestamp 3 hours ago

@jerry @cR0w @GossiTheDog Ivanti likes to play with cutting torches and live natural gas lines.

  • Copy link
  • Flag this comment
  • Block
Santa Caws
@cR0w@infosec.exchange replied  ·  activity timestamp 4 hours ago

@jerry @GossiTheDog

nods in USG

  • Copy link
  • Flag this comment
  • Block
Log in

Bonfire community

This is a bonfire demo instance for testing purposes

btfree.social: About · Code of conduct · Privacy ·
Bonfire community · 1.0.0 no JS en
Automatic federation enabled
  • Explore
  • About
  • Public Groups
  • Code of Conduct
Home
Login