Dec 29, 2024

Review: SASE Architecture for dummies

Linked in showed some weeks ago the following posting:
So i downloaded the PDF provided by https://www.netskope.com and here my review on this book, which contains an introduction and 5 chapters on 74 pages, which is really more than the typical booklets i reviewed on this blog in the last years. 
The introduction starts with a nice remark: "But security can’t inhibit people’s ability to do their work." - that means, there are new demands from business for apps, services, etc. which does not fit in the traditional castle security approach, because cloud is an environment, which does not fit to the old data center security. The proposal of this book is:
The architecture called secure access service edge (SASE; pronounced
“sassy”) is the proven way forward.  

Chapter one focuses on the vision, how SASE can secure an enterprise. One assumption here is, no enterprise can avoid SaaS apps/services, if you want to be competitive, but old security mechanisms can cope with that challenges. In this chapter the starting building blocks for SASE are enumerated:

  • SWGs (Secure web gateways)
  • CASBs (Cloud access security brokers)
  • ZTNA (Zero trust network access)
  • DLP (Data loss prevention)

and then some others are added like FWaaS and RBI (Remote browser isolation). All these tools are summarized under "Security Service Edge" (SSE). The end of the section focuses on the discussion if SSE and SDWAN has to be delivered from one vendor or if a dual vendor approach will work as well. 

The title of chapter 2 is "Bringing SASE to Life with SSE and SDWAN": and the proposal here is, that security and network performance will enhance each other within SASE. The chapter is divided in to parts: looking into the SSE part and the into the networking part. For the SSE part the identity is key and the integration of all the different building blocks (s. enumeration above) with advanced thread protection (ATP). The SDWAN part is from my perspective somehow an advertising of netskope.

Chapter 3 is named "Empowering People through SASE". A summary of this section can be given with the following quote:

But security is also about shielding your staff from themselves —
guarding against the mistakes, temptations, negligence, and errors
of judgment that can do irreparable harm. This is critical in a land-
scape where more than 85 percent to 95 percent of cybersecurity
incidents are attributable to human error, according to research
from Tessian and IBM --- SASE is a powerful tool for navigating these
waters, removing restrictions on your people while empowering
them to work safely in new ways.

Key for empowering SASE is context - every action is examined and based on user behavior activities can be taken to prevent attacks, etc..

"Protecting data and applications" is the fourth chapter of the book. The promise of SASE is, that traffic is not simply blocked or allowed - there a context aware policies possible and there are less tools, which have to be configured and integrated.

Chapter 5 is a 10-step guide, how to implement SASE in your enterprise. These steps vary from "gain awareness" to "optimize network performance". From my perspective a good checklist to start from.

Overall i liked the clear structure of this book. Every section starts with 5 key phrases, what you can learn in that section. There are many comparisons drawn with castles, modern homes or airport security or .... That is really a good idea and makes it much more understandable. Maybe the following snippets shows, why this book was sponsored by netskope:

But that does not matter - if you want to start into SASE: Read this book!
 

 

Feb 3, 2024

Flashing Tasmota onto a Wifi sensor controller (MHCOZY TH1CH-B1RF)

Today i got a MHCOZY TH1CH-B1RF and installed tasmota:

MHCOZY TH1CH-B1RF is a Wifi temperature and humidity controller:
Product details say:

Users can add the device to the APP eWeLink in order to remotely control connected home appliances or devices. In self-locking mode, customers can remotely turn on/off connected devices immediately. When in inching mode, customers can have two wiring ways to select: * Turn on 1s and then auto-off,* Turn off 1s and then auto-on.

Of course you can stay with the original software, but then you have to integrate EWELINK to you enviroment (which uses port 5353 with some strange multicast mechanism). I want to get the values via HTTP. So the questions is: Can this hardware run tasmota?

If you open this device, you see, that the chip is a PSF-Bxx:

(picture is a screenshot from here: https://templates.blakadder.com/PSF-B.html)

With knowing that, Tasmota can be flashed onto this device:
(all the connects are a little bit tricky, because there are no plugs and you have to constantly touch the contacts with the pins)

  1. Connect GPIO0 with ground (you can use the shielding of the USB connector on the board) 
  2. Insert power via the USB connector
  3. after 5 seconds remove the connection from GPIO0 to ground
  4. connect your serial programmer TX --> chip RX
  5. connect your serial programmer RX --> chip TX
    (i always start with TX --> TX and RX --> RX, which is wrong 🤐 ) 
  6. open tasmotizer.py
    (for installation look here - i chose option 2)
  7. if you choose "backup - save original firmware", then you have to start after the backup with step 1 again.
  8. choose "release" and "tasmota.bin"

  9. click "Tasmotize!"

After a reboot change to the new Wifi "tasmota....XXXX" and enter your Wifi credentials there on 192.168.4.1. And after a reboot you can open the web GUI like this here:

 

(the DHT11 sensor has to be selected for GPIO14)

Now i can get the values via

curl 'http://192.168.178.107/cm?cmnd=status%2010&user=admin&password=XXXX'

"StatusSNS":{"Time":"2024-02-03T19:19:29","DHT11":{"Temperature":24.3,"Humidity":50.0,"DewPoint":13.2},"TempUnit":"C"}}

Jan 10, 2024

Review@amazon: AWS for Solutions Architects

 Beginning of 2024 i read the book "AWS for Solutions Architects: The definitive guide to AWS Solutions Architecture for migrating to, building, scaling, and succeeding in the cloud":


The book has 627 pages and consists of 16 chapters.

Due to the number of topics, the author wants to cover (and has to!) the book cannot really go into detail about all the services - but in my opinion that is not necessary. I really liked the network sketches in Chapter 4 and the 6 Pillars in chapter 9. But the rest also fits - there are various keywords or links for each area that provide a good introduction.  

For anyone who knows other hyperscalers and is moving to AWS or is having their first contact with the cloud with AWS, this book should be a must-read. I really liked chapters 9, 14, 15, 16 because they deal with the general topics. Here the author cares more about the reader's knowledge base than about the specific implementation in AWS (and he doesn't leave this out). Absolute reading recommendation!

For more details please read my review at amazon (this time in german only) :)

(But maybe copilot or any other ChatGPT/OpenAI can translate that.

Jan 6, 2024

1 million visitors reached!

After 17 years (!) this blog reached 1.000.000 visitors.

 

Some more numbers: 591 articles written, 2.200 comments which where spam, 360 published comments, nearly 200 posts about Linux, 180 posts about Oracle, nearly 50 reviews on books...


Let's see if the 2mio will be reached in 2040 (omg).