this post was submitted on 22 Oct 2023
148 points (97.4% liked)

Memes

45533 readers
918 users here now

Rules:

  1. Be civil and nice.
  2. Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.

founded 5 years ago
MODERATORS
 

Warp nACLs (network access control lists)

top 13 comments
sorted by: hot top controversial new old
[–] [email protected] 23 points 1 year ago* (last edited 1 year ago) (1 children)

Kirk: We need more packets!

Scotty: I canna divert more packets. She’s gonna blow.

Spock: Perhaps we could divert the packets via a patch cable.

Scotty: Ya gotta be kiddin’ me. That’s a horrible plan.

Kirk: Do it.

Enterprise Computer: We’ve been trying to reach you about your ships extended warp bubble

Scotty: Bloody idiots, the lot of ya

[–] [email protected] 14 points 1 year ago (1 children)

Cap'n, they're DDoSing the reactor!

[–] [email protected] 4 points 1 year ago

Computer: Magnetic containment fa…..

[–] [email protected] 5 points 1 year ago

I like star trek, so i give this an upvote even when i dont understand it.

[–] [email protected] 4 points 1 year ago (1 children)
[–] [email protected] 2 points 1 year ago

thanks, now i get it...

[–] [email protected] 3 points 1 year ago

Warp "Nackles" is how I read it.

[–] [email protected] 3 points 1 year ago (2 children)

Ouf. Please close port 80. And if this is not a web server, close any ports for inbound traffic and implement a spi capable firewall.

[–] [email protected] 4 points 1 year ago (2 children)

It looks like these are examples from some documentation and not someone actual config

[–] [email protected] 6 points 1 year ago (1 children)

This, I just grabbed a random example. I shudder to think of actually posting the ACLs from any production environment

[–] [email protected] 1 points 1 year ago

I think the file upload size limit could become a problem in my case, at least in terms of posting the complete ACLs.

We've recently managed to come down to only ~1.4k VLANs though, and the network firewall pair for our server networks now only handles ~600 SPB services.

[–] [email protected] 0 points 1 year ago

Yea, I guess. But this should only be an example for how not to ACL

[–] [email protected] 3 points 1 year ago

Port 80 is open so you can redirect to https, it's not actually serving over http