Husband, Father, IT Pro, military service.

Don’t assume, ask. Don’t assume questions are statements or accusations.

I’d rather talk about difficult and nuanced topics in personal one on one situations over espresso or beer. Such discussion is very difficult in Internet written form.

I believe everyone should be treated with dignity and respect, but that doesn’t mean I agree with everything or everyone.

I have conservative and progressive views. I believe people can be both.

  • 6 Posts
  • 189 Comments
Joined 1 year ago
cake
Cake day: February 11th, 2024

help-circle
  • Knowledge primarily, since I’m not running a business.

    At this point, like they say in Chips, TLS inspection is standard…

    If your enterprise isn’t doing TLS inspection on everything other than banks, medical, gov, they’re doing it wrong.

    Some times people think the hard part is getting the CA trust setup, but I find it’s far more tedious to deal with certain sites and mobile apps especially that do certificate pinning.


  • RedFox@infosec.pubOPtoSelfhosted@lemmy.worldSophos XG Firewall Home Use
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    2
    ·
    1 month ago

    I like OPN also. I’ve always appreciated the stability of the BSDs.

    My only personal complaint with OPN/PF was the TLS inspection.

    I’ve read about adding the modules to *Sense, but I haven’t figured out the configuration pieces.

    It just works with Sophos UTM and XG firewall, and the configuration was super easy.

    You always use what you like though.


  • RedFox@infosec.pubOPtoSelfhosted@lemmy.worldSophos XG Firewall Home Use
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    1 month ago

    This is true, the 6 GB RAM limit and four cores.

    I run a pretty enterprise home lab, and I haven’t ever seen the devices hit the resource limit.

    I have around 3k IPS rules and TLS inspection for most categories of sites except the normal stuff like streaming, banking, etc that you’d not want or need to inspect.

    For anyone it might help, I use these as inline proxies rather than as the gateway at the moment. So they have more than just internet traffic going through them, they also have segments of my LANs getting evaluated. Performance has been great so far.














  • contract “options” are indeed normal. You could also lump in government contracts into the category your thinking about. I’ve never heard of a scenario where the vendor broke contract by not honoring the options. I also have never dealt with a vendor getting bought out and then not honoring existing contracts. Super fun to watch the corporate drama. I personally don’t care for the private equity style business that seems to be an even bigger problem than the investor first/profit centric model that I thought was the worst thing.





  • It’s pretty plain to see IBM afraid of loosing vendor lock-in, but running a software solution designed for an open or distributed platform shouldn’t be that big of a threat, right?

    All their selling points for z series are the insane hardware performance, redundancy, and tuning.

    Isn’t it unlikely you’re going to get that on some virtual or abstracted mainframe platform?

    If I was one of the businesses that’s been paying the fortune keeping IBM mainframe alive, I’d stay on it. They measure profits in the billions and saving some money going away from IBM and risking loosing countless dollars per minute seems like a risk…

    Oh wait, I forgot, all American Corps are currently (since the 80s-ish), worthless greedy fucks solely focused on short term profit and stock price regardless of long term consequences. Maybe they should save some money on one of the things that’s helps make them billions…I bet that golden goose tastes amazing 😄