Existing anti-phishing tech, together with training, is not getting the job done when it comes to Phishing. It is almost inevitable that someone will click a bad link leading to compromised credentials. A new approach is needed, and it is called isolation. No human firewalls are required! When a user clicks on a link in an email, it is opened in a remote cloud container, and the site’s content is streamed to the end user. Any phishing malware is blocked from getting to the machine and the site can be rendered in “read-only” mode to prevent users from handing over their credentials. This solution is available today as a component of our NetCloud SASE Solution. Peter Silva lights up how to protect users and devices from malicious links.
Showing posts with label lightboard. Show all posts
Showing posts with label lightboard. Show all posts
Thursday, September 26, 2024
Friday, November 6, 2020
Cloud Interconnection with F5 & Equinix
Learn how the simplified Interconnection Oriented Architecture (IOA) from #F5 and #Equinix helps IT departments solve the need for mobile and dispersed user access to their cloud infrastructure(s) in a multi-cloud environment.
Learn more: https://www.f5.com/services/resources/use-cases/a-secure-equinix-gateway-to-the-cloud
This architecture allows for services to be deployed at the edge of, or next to the cloud resulting in Fewer hops, Dramatically lower latency, Fault-proof security & Lower Network transport costs - as much as 80% lower.
This ‘edge’ architecture provides a natural point for traffic control by having centralized policy control and Security policy enforcement, access control and other services like DDoS protection, AAA and WAF.
Sunday, April 5, 2020
Remote Desktop Protocol (RDP) using an SSL VPN
Returning to the F5 DevCentral Lightboard, I explain why its a bad idea to expose RDP to the internet and how using a SSL VPN like BIG-IP APM is a much safer and better idea.
ps
ps
Labels:
3389,
apm,
devcentral,
f5,
lightboard,
rdp,
remote access,
silva,
sslvpn,
vpn
Tuesday, June 19, 2018
The DevCentral Chronicles June Edition 1(6)
Heading into the summer months is always a nice time of year – school is out,
warmer weather, BBQs, beaches, baseball and maybe some vacation time. And
hopefully all the Dads had a nice Father’s Day as we dive into our
6th installment of the DC Chronicles. The Chronicles are intended to
keep you updated on DevCentral happenings and highlight some of the cool content
you may have missed since the last issue and you can always catch up with the
links at the bottom. Welcome!
We had 20 new articles published since Volume 1, Issue 5, including 5 new Lightboard Lessons! We really enjoy making these and you, the audience, certainly express your enjoyment in watching. John Wagnon lit some cool security related topics like, Explaining TLS 1.3, What Are AEAD Ciphers? and The TLS 1.3 Handshake while Jason Rahm drew up the F5 software lifecycle and BIG-IP Cloud Edition Overview. Since we’re on Cloud, Chris Zhang also wrote up how to Achieve firewall high-availability in Azure with F5.
We also published a bunch of materials about our new BIG-IP Cloud Edition. BIG-IP Cloud Edition is designed to enable easy to use and fast self-serve deployments of application services in private and public clouds and is composed of BIG-IP Per-App VEs and BIG-IQ CM 6.0. To get the scoop, you can check out the BIG-IP Cloud Edition FAQ, Building Applications For The Rest Of Us With BIG-IQ 6 and Skies Never Looked So Good With BIG-IP Cloud Edition. DevCentral’s Chase Abbott lays out the details.
Moving from Cloud to Security, several vulnerability mitigations from our SIRT team dropped recently. You got coverage for Remote Code Execution with Spring OAuth Extension (CVE-2018-1260), a New BIG-IP ASM v13 Drupal v8 Ready Template, and a New BIG-IP ASM v13 WordPress v4.9 Ready Template. Also filed under Security, Steve Lyons showed how to Configure Smart Card Authentication to BIG-IP Management Interface.
Other highlights include Lori MacVittie’s Three HTTP Routing Patterns You Should Know with Eric Chen’s follow on, SNI Routing with BIG-IP. Chen also gives us Clone Pool Across L3 explaining how you can use the “clone pool” feature to copy traffic to an IDS and/or network monitoring device. Jason continues his Getting started with the Python SDK series covering Working with Statistics and Working with Request Parameters and finally, Jie Gao was DevCentral's Featured Member for June.
As always, You can stay engaged with @DevCentral by following us on Twitter, joining our LinkedIn Group or subscribing to our YouTube Channel. Look forward to hearing about your BIG-IP adventures.
The Chronicles:
We had 20 new articles published since Volume 1, Issue 5, including 5 new Lightboard Lessons! We really enjoy making these and you, the audience, certainly express your enjoyment in watching. John Wagnon lit some cool security related topics like, Explaining TLS 1.3, What Are AEAD Ciphers? and The TLS 1.3 Handshake while Jason Rahm drew up the F5 software lifecycle and BIG-IP Cloud Edition Overview. Since we’re on Cloud, Chris Zhang also wrote up how to Achieve firewall high-availability in Azure with F5.
We also published a bunch of materials about our new BIG-IP Cloud Edition. BIG-IP Cloud Edition is designed to enable easy to use and fast self-serve deployments of application services in private and public clouds and is composed of BIG-IP Per-App VEs and BIG-IQ CM 6.0. To get the scoop, you can check out the BIG-IP Cloud Edition FAQ, Building Applications For The Rest Of Us With BIG-IQ 6 and Skies Never Looked So Good With BIG-IP Cloud Edition. DevCentral’s Chase Abbott lays out the details.
Moving from Cloud to Security, several vulnerability mitigations from our SIRT team dropped recently. You got coverage for Remote Code Execution with Spring OAuth Extension (CVE-2018-1260), a New BIG-IP ASM v13 Drupal v8 Ready Template, and a New BIG-IP ASM v13 WordPress v4.9 Ready Template. Also filed under Security, Steve Lyons showed how to Configure Smart Card Authentication to BIG-IP Management Interface.
Other highlights include Lori MacVittie’s Three HTTP Routing Patterns You Should Know with Eric Chen’s follow on, SNI Routing with BIG-IP. Chen also gives us Clone Pool Across L3 explaining how you can use the “clone pool” feature to copy traffic to an IDS and/or network monitoring device. Jason continues his Getting started with the Python SDK series covering Working with Statistics and Working with Request Parameters and finally, Jie Gao was DevCentral's Featured Member for June.
As always, You can stay engaged with @DevCentral by following us on Twitter, joining our LinkedIn Group or subscribing to our YouTube Channel. Look forward to hearing about your BIG-IP adventures.
The Chronicles:
Wednesday, April 11, 2018
The DevCentral Chronicles Volume 1, Issue 4
If you missed our initial issues of the DC Chronicles, you can catch up with the links at the bottom. The Chronicles are intended to keep you updated on DevCentral happenings and highlight some of the cool content you may have missed since the last issue. Welcome!
Like last month, we’re digging the OWASP Top 10 #Lightboard series from @JohnWagnon. He wrapped it up this month with numbers 9 & 10 - Using Components With Known Vulnerabilities and Insufficient Logging and Monitoring. To give you a sense of how these have been received, YouTube viewer Sanket Kamath says, ‘Thank you for the excellent overview for all of the OWASP Top 10 2017! John made it really easy to understand each of the 10 attacks with his explanation!’ Check out the entire playlist!
Speaking of LightBoard Lessons, we had a few fantastic ones this past month. John took on lighting up the GitHub DDoS Attack and Explaining the Spectre and Meltdown Vulnerabilities while Jason gave us the OSI and TCP/IP Models and What Are Containers? I added SAML IdP and SP on One BIG-IP to round out our videos.
On the Security front, we had a bunch of great articles covering a mess, and I mean a mess of stuff. The mess was some new vulnerabilities and our Security Researchers had the mitigations for many including Spring Framework Spring-Messaging Remote Code Execution (CVE-2018-1270), Drupal Core SA-CORE-2018-002 Remote Code Execution Vulnerability and Jackson-Databind - A Story of Blacklisting Java Deserialization Gadgets.
We also learned how to Protect your AWS API Gateway with F5 BIG-IP WAF, how to configure F5 BIG-IP as an Explicit Forward Web Proxy Using Secure Web Gateway (SWG) and how to set up ADFS Proxy Replacement on F5 BIG-IP.
The Cloud folks will love Lori’s Three Types of Load Balancing You Meet in the Cloud, DNS Admins will dig Eric’s Unbreaking the Internet and Converting Protocols and Coders will enjoy Jason’s Debugging API calls with the python sdk and Satoshi’s iControl REST Fine-Grained Role Based Access Control.
And, we couldn’t let this Chronicle pass without mentioning an awesome @haveibeenpwned #Pwned Passwords Check #CodeShare from MVP Niels van Sluis. This snippet makes it possible to use @troyhunt ‘Pwned Passwords’ API to check if the password has been exposed. See it here: http://bit.ly/2GOhi1y
And wrapping up, a wonderful contributor Daniel Varela is DevCentral's Featured Member for April and F5 Agility is coming to Boston, MA this August!
As always, You can stay engaged with @DevCentral by following us on Twitter, joining our LinkedIn Group or subscribing to our YouTube Channel. Look forward to hearing about your BIG-IP adventures.
ps
Previous
Thursday, March 22, 2018
Post of the Week: SAML IdP and SP on One BIG-IP
In this Lightboard Post of the Week, I answer a question about being able to do SAML IdP and SP on a single BIG-IP VE. Thanks to DevCentral Members hpr and Daniel Varela for the question and answer. +25 DC points for ya!
Posted Question on DevCentral: https://devcentral.f5.com/questions/apm-ltm-121-saml-idp-and-sp-possible-in-one-ve-58114
If you got an answer you'd like lit up on the Lightboard, let us know in the comments!
ps
Posted Question on DevCentral: https://devcentral.f5.com/questions/apm-ltm-121-saml-idp-and-sp-possible-in-one-ve-58114
If you got an answer you'd like lit up on the Lightboard, let us know in the comments!
ps
Labels:
authentication,
big-ip,
devcentral,
f5,
lightboard,
saml
Friday, January 26, 2018
Post of the Week: Two-Factor Auth and SSO with BIG-IP
In this Lightboard Post of the Week, I answer a question about 2FA and SSO with AD/RSA on BIG-IP by creating a SSO Credential Mapping policy agent in the Visual Policy Editor, that takes the username and password from the logon page, and maps them to variables to be used for SSO services. Special thanks to senthil147 for the question and a new 2018 MVP, MrPlastic (Lee Sutcliffe, which I flubbed) for the great answer.
Posted Question on DevCentral: https://devcentral.f5.com/questions/2fa-authentication-with-sso-on-apm-57581
ps
Posted Question on DevCentral: https://devcentral.f5.com/questions/2fa-authentication-with-sso-on-apm-57581
ps
Labels:
2fa,
authentication,
big-ip,
devcentral,
f5,
lightboard,
sso
Friday, December 22, 2017
Post of the Week: SSL on a Virtual Server
In this Lightboard Post of the Week, I answer a few questions about SSL/https on Virtual Servers. BIG-IP being a default deny, full proxy device, it's important to configure specific ports, like 443, to accept https traffic along with client and server side profiles and include your SSL certificates. We cover things like SAN/SNI certificates but I failed to mention that self-signed certificates are bad anywhere except for testing or on the server side of the connection.
Thanks to DevCentral members, testimony, Only1masterblaster, Faruk AYDIN, MrPlastic, Tyler G, Prince, and dward for their Q/A engagement.
Posted Questions on DevCentral:
ps
Thanks to DevCentral members, testimony, Only1masterblaster, Faruk AYDIN, MrPlastic, Tyler G, Prince, and dward for their Q/A engagement.
Posted Questions on DevCentral:
ps
Labels:
big-ip,
certificates,
devcentral,
f5,
https,
lightboard,
potw,
ssl,
video
Friday, November 17, 2017
Post of the Week: BIG-IP APM Policy Sync
In this Lightboard Post of the Week, I light up the answer to a question about BIG-IP APM Policy Sync. Posted Question on DevCentral: https://devcentral.f5.com/questions/apm-policy-sync-56330
Thanks to DevCentral user Murali (@MuraliGopalaRao) for the question and special thanks to Leonardo Souza for the answer!
ps
Related:
Thanks to DevCentral user Murali (@MuraliGopalaRao) for the question and special thanks to Leonardo Souza for the answer!
ps
Related:
Labels:
big-ip,
devcentral,
f5,
lightboard,
policy sync,
potw,
video
Wednesday, November 1, 2017
Lightboard Lessons: What is DDoS?
Over the last quarter, there were approximately 500 DDoS attacks daily around the world with some lasting as long as 300 hours. In this Lightboard Lesson I light up some #basics about DoS and DDoS attacks.
ps
Related:
ps
Related:
Labels:
basics,
botnets,
ddos,
devcentral,
f5,
lbl,
lightboard,
malware,
security
Wednesday, October 18, 2017
Lightboard Lessons: What are Bots?
In this Lightboard Lesson, I light up some #basics about internet bots and botnets. Humans account for less than 50% of internet traffic and the rest is spread between the good bots and bad ones.
ps
Related:
ps
Related:
Labels:
basics,
botnets,
bots,
devcentral,
f5,
lightboard,
lightboard lesson,
malware
Wednesday, October 4, 2017
Lightboard Lessons: Connecting Cars with BIG-IP
Labels:
connected car,
devcentral,
f5,
iot,
lbl,
lightboard,
mqtt,
solace,
video
Wednesday, September 20, 2017
Lightboard Lessons: What is HTTP?
In this Lightboard Lesson, I light up some #basics about HTTP. HTTP defines the structure of messages between web components such as browser or command line clients, servers like Apache or Nginx, and proxies like the BIG-IP.
ps
Related:
ps
Related:
Wednesday, August 23, 2017
Lightboard Lessons: BIG-IP ASM Layered Policies
In this Lightboard Lesson, I light up some use cases for BIG-IP ASM Layered Policies available in BIG-IP v13.
With Parent and Child policies, you can:
ps
With Parent and Child policies, you can:
- Impose mandatory policy elements on multiple policies;
- Create multiple policies with baseline protection settings; and
- Rapidly push changes to multiple policies.
ps
Labels:
asm,
big-ip,
f5,
layered policies,
lightboard,
security,
video,
waf
Wednesday, July 26, 2017
Lightboard Lessons: What is BIG-IP APM?
In this Lightboard, I light up some lessons on BIG-IP Access Policy Manager. BIG-IP APM provides granular access controls to discreet applications and networks supporting 2FA and federated identity management. You can also check out Chase's written article What is BIG-IP APM?
ps
ps
Wednesday, March 29, 2017
Lightboard Lessons: Service Consolidation on BIG-IP
The Consolidation of point devices and services in your datacenter or cloud can help with cost, complexity, efficiency, management, provisioning and troubleshooting your infrastructure and systems.
In this Lightboard Lesson, I light up many of the services you can consolidate on BIG-IP.
ps
In this Lightboard Lesson, I light up many of the services you can consolidate on BIG-IP.
ps
Wednesday, March 15, 2017
Lightboard Lessons: What is a Proxy?
The term ‘Proxy’ is a contraction that comes from the middle English word procuracy, a legal term meaning to act on behalf of another.
In networking and web traffic, a proxy is a device or server that acts on behalf of other devices. It sits between two entities and performs a service. Proxies are hardware or software solutions that sit between the client and the server and do something to requests and sometimes responses.
In this Lightboard Lesson, I light up the various types of proxies.
ps
Related:
In networking and web traffic, a proxy is a device or server that acts on behalf of other devices. It sits between two entities and performs a service. Proxies are hardware or software solutions that sit between the client and the server and do something to requests and sometimes responses.
In this Lightboard Lesson, I light up the various types of proxies.
ps
Related:
- Encrypted malware vs. F5's full proxy architecture
- The Concise Guide to Proxies
- The Full-Proxy Data Center Architecture
- Three things your proxy can't do unless it's a full-proxy
- Back to Basics: The Many Modes of Proxies
Wednesday, February 8, 2017
Lightboard Lessons: IoT on BIG-IP
As more organizations deploy IoT applications in their data centers and clouds, they're going to need their ADC to understand the unique protocols these devices use to communicate.
In this Lightboard Lesson, I light up how IoT protocol MQTT (Message Queuing Telemetry Transport) works on BIG-IP v13. iRules allow you to do Topic based load balancing along with sensor authentication. And if you missed it, here is the #LBL on What is MQTT?
ps
Related:
In this Lightboard Lesson, I light up how IoT protocol MQTT (Message Queuing Telemetry Transport) works on BIG-IP v13. iRules allow you to do Topic based load balancing along with sensor authentication. And if you missed it, here is the #LBL on What is MQTT?
ps
Related:
Wednesday, January 11, 2017
Lightboard Lessons: What is MQTT?
The mad dash to connect virtually every noun to the internet or The Internet of Things, is creating a massive M2M network for all the devices, systems, sensors and actuators to connect & communicate on the Internet.
With that, they need a communications protocol to understand each other. One of those is Message Queue Telemetry Transport (MQTT). MQTT is a “subscribe and publish” messaging protocol designed for lightweight machine-to-machine (or IoT) communications.
In this episode of Lightboard Lessons, I light up how MQTT works.
ps
Related:
With that, they need a communications protocol to understand each other. One of those is Message Queue Telemetry Transport (MQTT). MQTT is a “subscribe and publish” messaging protocol designed for lightweight machine-to-machine (or IoT) communications.
In this episode of Lightboard Lessons, I light up how MQTT works.
ps
Related:
Labels:
big-ip,
devcentral,
f5,
iot,
lbl,
lightboard,
m2m,
mqtt,
silva,
video
Wednesday, December 14, 2016
Lightboard Lessons: SSO to Legacy Web Applications
IT organizations have a simple goal: make it easy for workers to access all
their work applications from any device. But that simple goal becomes
complicated when new apps and old, legacy applications do not authenticate in
the same way.
In this Lightboard Lesson, I draw out how VMware and F5 helps remove these complexities and enable productive, any-device app access. By enabling secure SSO to Kerberos constrained delegation (KCD) and header-based authentication apps, VMware Workspace ONE and F5 BIG-IP APM help workers securely access all the apps they need—mobile, cloud and legacy—on any device anywhere.
ps
Related:
In this Lightboard Lesson, I draw out how VMware and F5 helps remove these complexities and enable productive, any-device app access. By enabling secure SSO to Kerberos constrained delegation (KCD) and header-based authentication apps, VMware Workspace ONE and F5 BIG-IP APM help workers securely access all the apps they need—mobile, cloud and legacy—on any device anywhere.
ps
Related:
Labels:
authentication,
f5,
lbl,
lightboard,
saml,
sso,
video,
vmware
Subscribe to:
Posts (Atom)

