@wop@infosec.pub avatar

wop

@wop@infosec.pub

Blog: ittavern.comFeedback is appreciated

This profile is from a federated server and may be incomplete. Browse more on the original instance.

wop,
@wop@infosec.pub avatar

So, let’s assume that you are in an international company and the first and only security person. What are your first steps and projects? It is like really vague, but I’d assume like a SIEM, inventory of the network and all devices, backup situation, maybe even honeypots?

What are your high-prio things that every company should have? Is there even a framework for it?

Feeling kinda lost and I hope you get some guidance in the right direction.

wop,
@wop@infosec.pub avatar

Testing a few CTF platforms to learn more about pentesting. It is interesting, but the learning curve is quite steep.

wop,
@wop@infosec.pub avatar

Currently using HedgeDoc for taking notes, but it is lacking some features, so I am trying to find and host some alternatives and compare them. And I hope I can find some time to play with my Flipper Zero…

wop,
@wop@infosec.pub avatar

I want to get into Ansible and I am building a testing env for it - home lab with various switches and routers, Fortinet, Palo, and a proxmox host server and some remote VPS. One of my goals for Q1 '24. Today I am going to prep the switches.

Besides that, I want to host my own NFTY server and I hope that I can get it online within this week.

wop,
@wop@infosec.pub avatar

I am currently transitioning into a Security role at work. One question would be: what are the must-have tools for every blue team?

  • Vuln-Scanner
  • Logging/ SIEM-Server
wop,
@wop@infosec.pub avatar

Learning things about Wireguard and implement it to secure my internet facing servers.

wop, (edited )
@wop@infosec.pub avatar

Thank you for the AMA.

Do you regularly feel overwhelmed? - Keeping up with the sec news and patch accordingly, firewall/ips and endpoint alarms, logs, meetings, and more. It shouldn’t be the case, but it seems that everything in security is prio 1.

EDIT: and being the party pooper and saying no to everything, bc people do not think about security.

wop,
@wop@infosec.pub avatar

Good points and thank you for your input. What kind of TaskManager do you use? Any system, or just simple list?

wop,
@wop@infosec.pub avatar

I am currently trying to organize my notes. The old ‘system’ is a pain, and getting everything centralized makes it easier to find things. Notes, snippets, bookmarks, and so on.

wop,
@wop@infosec.pub avatar

Haven’t found my perfect solution. The current goal is get everything together and see what I really need. Most likely a single .md file that I can encrypt and sync in my machines, but not sure yet.

wop,
@wop@infosec.pub avatar

Do you know logseq.com ? - I think it is considered an alternative to Obisidian. Had been using it for a while, was great, but it was almost too much work to organize everything.

wop,
@wop@infosec.pub avatar

Ping - Update 2

wop,
@wop@infosec.pub avatar

Ping - Update 2 Your numbers are are still missing since I havent had time to look into the pcaps yet. I hope I can get it done by the end of the week, but we are a little bit wiser.

wop,
@wop@infosec.pub avatar

Added the Update 2. Still some things to do, but we know a little bit more now. Feedback and questions are still welcome.

wop,
@wop@infosec.pub avatar

The ISPs are slow to answer if there is no active outage. Will take some time anyway.

Packets are dropped in bot directions. I am currently looking through the pcaps and will do another stress test later - got another window. MTU/MSS is the prio today.

wop,
@wop@infosec.pub avatar

Yeah, notifications are really unreliable here. I’ve got another window for more stress test today. Going to post update later, or tomorrow. Focus on MTU/MSS

wop, (edited )
@wop@infosec.pub avatar
wop,
@wop@infosec.pub avatar

Yeah, after more testing, we can say that the second IPStunnel was the issue. Re-worked the route over a single tunnel and the whole 100 Mbps are available again. Users are happy, I am happy. Even tho a little bit frustrating.

Thank you for your input!

wop,
@wop@infosec.pub avatar

Does fortigate not have a form of DMVPN like Cisco?

ADVPN (Auto-discovery VPN) seems to be the equivalent. docs.fortinet.com/document/fortimanager/…/advpn

Just curious why ISP/third party MPLS? Purely interest.

I guess it was easier at some point? - Taht was way before my time there. But we are going to replace the MPLS part with simple internet-breakout points on location and the the rest with SDWAN.

Also, did you find this purely from user complaining or have monitoring tool?

Purely from users complaining and other departments getting frustrated about why their stuff was not working (e.g. Citrix). The new FW had to be installed in a short time and ‘everything’ worked fine at first. Problems only occurred after some load was put on the network. We failed - as in network dep - by NOT doing a stress/limit test of the network and finding this problem immediately, and NOT implementing some kind of monitoring that would have notified us of all those lost packets and connections. We caught up, but we should have done it in the first place, because it is necessary.

I’m assuming using third party was supposed to offload the work/config from you?

Do you mean the ISP/MPLS provider? - If so, not really.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • kavyap
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • tacticalgear
  • cubers
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • osvaldo12
  • ngwrru68w68
  • GTA5RPClips
  • provamag3
  • InstantRegret
  • everett
  • Durango
  • cisconetworking
  • khanakhh
  • ethstaker
  • tester
  • anitta
  • Leos
  • normalnudes
  • modclub
  • megavids
  • lostlight
  • All magazines