This article is within the scope of WikiProject Computing, a collaborative effort to improve the coverage of computers, computing, and information technology on Wikipedia. If you would like to participate, please visit the project page, where you can join the discussion and see a list of open tasks.ComputingWikipedia:WikiProject ComputingTemplate:WikiProject ComputingComputing
Latest comment: 4 years ago7 comments2 people in discussion
@peaceray
Hello. Subnetting is not a standard security practice. It is a way to manage IP space. It does not add security, or prevent a machine from being secure. The first bullet point here says that a jump server is made more secure by part of a smaller subnet. That isn't true in anyway, shape, or form. In many cases, creating small subnets hurts more than it helps, or is suboptimal (see ipv6)
Can you explain why you re added that smaller subnets assist with securing jump servers?
You also added that ACLs can be used to choose who enters a network. But an ACL uses network signals only, and does not know who is sending them. This is another piece of misinformation you added.
Now that I have provided a half dozen+ sources for why subnetting / segmenting is a standard cybersecurity practice, would you please kindly list your sources why it is not? Perhaps you can find something approaching the About 98,600,000 result that Google claims for "segmenting a network for security". Peaceray (talk) 05:54, 28 January 2022 (UTC)Reply
Subnetting isn't a part of "jump hosts", it is part of networking in general. It misleading to claim that because subnetting is used to secure networks, jump hosts should be members of more subnets. That is your claim that you added. That is original research. You will find out, adding more networks to a hardended host makes it HARDER to secure. For modern ip protocols, you can't even adjust the subnet size if you'd like to, by standard.
There is your source for ipv6. Can you tell me which of your sources makes the claim in the prose you added, specifically, "it is safer to have smaller and more subnets attached to jump servers". I can't think of anyone who would recommend adding more complexity to a hardened box.
looking deeper, looks like all of your sources are actually unrelated to the topic of jump servers completely. Can you please provide a source for your claims about the best practices of configuring jump servers? Else, can we agree that this is original research and faulty. At best, it's someone's vague recollection of 1990s networking, at worst, it was someone trolling with misinfo. — Preceding unsigned comment added by 2600:1700:12B0:3000:85A4:3E9A:69B1:D576 (talk) 06:24, 28 January 2022 (UTC)Reply
Those sources specifically address your claim from your first edit summary Removed a list of misinformation. I. E. Smaller networks are not more secure.
Since my last comment here, I have provided citations for each Jump server#Security risks bullet item that is specific to that item's application to jump servers. You may discuss any problems you have with individual citations here. I am sure we can find other reliable sources with a little more research. Peaceray (talk) 06:36, 28 January 2022 (UTC)Reply
I think you moved the references incorrectly, because there is a reference about subnetting in the "strong logging" and "Keeping the OS" up to date bullets. But even if those were references about regular updates, that isn't specific to jump hosts. It is just general and vague advice. What is strong logging? Verbose logging can be an attack vector. The reference does not use this phrase. Maybe it would be easier to link to [Hardening_(computing)] in the prose instead of attempting to summarize that article here in the form of a list — Preceding unsigned comment added by 2600:1700:12B0:3000:85A4:3E9A:69B1:D576 (talk) 06:58, 28 January 2022 (UTC)Reply
The citations that I added each mention jump server & are specific to the particular security practice, either in application to or with jump servers.
The bulleted items are neither false nor misinformation. All of them are standard cybersecurity practices.
The citations I added discuss those security practices that buttress jump servers and their inclusion as part of a layered approach to cybersecurity. Yes, many of them are good security practices in themselves, but they are all necessary to the robust implementation of a jump server. I think that we would be wholly remiss to omit them. Peaceray (talk) 07:30, 28 January 2022 (UTC)Reply
Informasi ini disarikan dari Wikipedia dan disajikan kembali untuk tujuan edukasi. Konten tersedia di bawah lisensi CC BY-SA 3.0. Kami tidak bertanggung jawab atas ketidakakuratan data yang bersumber dari kontribusi publik tersebut.
The information displayed on this website is sourced in part or in whole from Wikipedia and has been adapted for the purpose of restating it. We strive to provide accurate and relevant information, however:
There is no guarantee of absolute accuracy. Wikipedia is an open, collaborative project that can be edited by anyone, so information is subject to change.
It is not intended to constitute professional advice. The content displayed is for informational and educational purposes only. For important decisions (e.g., medical, legal, or financial), please consult a professional.
Content copyright. Wikipedia is licensed under the Creative Commons Attribution-ShareAlike License (CC BY-SA). This means that content may be reused with appropriate attribution and shared under a similar license.
Responsible use. Any risk arising from the use of information from this website is entirely the responsibility of the user.