Just out of curiosity, if Connect to Command Center is disabled and has been disabled on an install for months now, how is it that Threat History in the Command Center is populated with all the occasional attachments that have triggered Virus Blocker on that install?
Announcement
Collapse
No announcement yet.
Just out of curiosity, if Connect to Command Center....
Collapse
This topic is closed.
X
X
-
Originally posted by fasttech View PostJust out of curiosity, if Connect to Command Center is disabled and has been disabled on an install for months now, how is it that Threat History in the Command Center is populated with all the occasional attachments that have triggered Virus Blocker on that install?
-
-
I'm pretty sure it connects anyway, I'm just not sure exactly when. Possibly on admin login? I've seen the same behavior at times, but never took the time to look into it.Rob Sandling, BS:SWE, MCP, Microsoft Certified: Azure Administrator Associate
NexgenAppliances.com
Phone: 866-794-8879 x201
Email: [email protected]
Comment
-
-
-
Untangle's Command Center is hiding behind Cloudflare's Web Firewall, which has been dealing with Log4j far longer than anything else.
Not to mention its age, I'd be highly surprised if Untangle built it based on any JAVA at all to have Log4j involved. If they did, that was rather silly of them. But regardless, I'd assume such a platform is already updated to a version of Log4j that isn't hopeless?
As for the Command Center, as a matter of principle I also have that feature disabled on all of my units, my NFR is one exception. Why? Because the systems in question ARE NOT MINE! They each belong to someone else that I'm providing support for. It's not appropriate to have them all piled up in my Command Center, exposing them all to my technical risks as well as their own.
Secured Islands, it's a concept critical to defense in depth. You ask why would you turn that off, and I respond why did you turn it on?Rob Sandling, BS:SWE, MCP, Microsoft Certified: Azure Administrator Associate
NexgenAppliances.com
Phone: 866-794-8879 x201
Email: [email protected]
Comment
-
-
Originally posted by sky-knight View PostUntangle's Command Center is hiding behind Cloudflare's Web Firewall, which has been dealing with Log4j far longer than anything else.
Not to mention its age, I'd be highly surprised if Untangle built it based on any JAVA at all to have Log4j involved. If they did, that was rather silly of them. But regardless, I'd assume such a platform is already updated to a version of Log4j that isn't hopeless?
As for the Command Center, as a matter of principle I also have that feature disabled on all of my units, my NFR is one exception. Why? Because the systems in question ARE NOT MINE! They each belong to someone else that I'm providing support for. It's not appropriate to have them all piled up in my Command Center, exposing them all to my technical risks as well as their own.
Secured Islands, it's a concept critical to defense in depth. You ask why would you turn that off, and I respond why did you turn it on?
Comment
-
-
Originally posted by dashpuppy View PostI really hope Untangle works on some Proper 2FA stuff 2022. THis simple email 2FA code is not acceptable these days and should be resolved... It's one of the things i get questioned every day about Selling more Untangle appliances and stuff, do they have Proper 2FA yet ? When i say no people drop the conversation and say then we won't use the product then.
But without MFA on the LOCAL ADMIN LOGINS to all products in question, properly 2FA'ing the Command Center is largely moot.
And yes, this should have been in the product ages ago, we were PROMISED it to be in the product when they inserted OpenVPN to the phrase after the fact and let us all down. Not that we don't need that too... but still.Rob Sandling, BS:SWE, MCP, Microsoft Certified: Azure Administrator Associate
NexgenAppliances.com
Phone: 866-794-8879 x201
Email: [email protected]
Comment
-
-
Command Center is NOT vulnerable to log4j!
It was only ever brought up as an example... if not log4j today, what new vulnerability tomorrow? Ie: if you're not really using it because you only have one Untangle installation and have good VPN/remote access setup on your own, Command Center only represents increased attack surface.Five time Microsoft ASP.Net MVP managing a Lenovo RD330 / E5-2420 / 16GB with Untangle 16.5.2 to protect a 1Gbps fiber link for ~450 residential college students and associated staff and faculty
Comment
-
-
Exactly due to the nature of NGFW, and Microedge, the Command Center is always additional attack surface.
The question is, does the additional attack surface do something for you that makes it worth the risk? That's something everyone has to answer on their own.
But no, I do not believe Command Center uses Java code, which means no Log4j at all to be vulnerable in this case. But again EVEN IF IT DID, it'd still be mitigated because the command center is 100% behind CloudFlare's amazing proxy service. And Cloudflare was very much out in front on the log4j situation just as they are everything else.
Untangle is paying the right people to secure access to Command Center, it's gold star, doesn't get any better. Untangle has Untangle'd Command Center. You don't have to functionally worry about it.
The product is missing features, but it's deployed very well.Rob Sandling, BS:SWE, MCP, Microsoft Certified: Azure Administrator Associate
NexgenAppliances.com
Phone: 866-794-8879 x201
Email: [email protected]
Comment
-
-
Originally posted by sky-knight View PostExactly due to the nature of NGFW, and Microedge, the Command Center is always additional attack surface.
The question is, does the additional attack surface do something for you that makes it worth the risk? That's something everyone has to answer on their own.
But no, I do not believe Command Center uses Java code, which means no Log4j at all to be vulnerable in this case. But again EVEN IF IT DID, it'd still be mitigated because the command center is 100% behind CloudFlare's amazing proxy service. And Cloudflare was very much out in front on the log4j situation just as they are everything else.
Untangle is paying the right people to secure access to Command Center, it's gold star, doesn't get any better. Untangle has Untangle'd Command Center. You don't have to functionally worry about it.
The product is missing features, but it's deployed very well.DAMN i can wish hard on this !
Comment
-
-
Originally posted by dashpuppy View PostNow they just need to setup proper 2fa instead of email 2fa codesDAMN i can wish hard on this !
Rob Sandling, BS:SWE, MCP, Microsoft Certified: Azure Administrator Associate
NexgenAppliances.com
Phone: 866-794-8879 x201
Email: [email protected]
Comment
-
Comment