- Видео 62
- Просмотров 129 616
DracoCyberSecurity
Сингапур
Добавлен 22 апр 2020
Видео
Deploy FMCv 7 4 1 in KVM on Ubuntu 22 04
Просмотров 3569 месяцев назад
In this tutorial I will show you how to deploy the Firewall Management Center Virtual version 7.4.1 in KVM running on Ubuntu 22.04 in the cloud. We will be using the virt-manager to deploy the FMCv. You can follow the steps in my blog as well. dracocybersecurity.com/deploy-fmcv-7-4-1-in-kvm-ubuntu-22-04
How to create a SYSTEMD service for VNCServer to autostart at reboot
Просмотров 15011 месяцев назад
In this tutorial I will show you: 1. How to configure a SystemD service 2. tweak the xstartup file. 3. Reload the SystemD daemon 4. Enable persistent SystemD service and start the service
How to create a SYSTEMD Timer to update ip address in ipset from Dynamic DNS
Просмотров 103Год назад
In this tutorial I will show you how to. 1. Create a SYSTEMD Service to run a script 2. A simple script to update ipset set/list 3. A SYSTEMD timer to run the script every min.
How to create a cron job to update ipset with ip address from Dynamic Domain
Просмотров 245Год назад
In this tutorial I will show you how to. 1. Create a ipset 2. Create a script to get the ip address from a dynamic domain. 3. Update the ipset 4. Create a cron job 5. Basic validation 6. Adding ipset into a iptable rule.
How to configure ipset
Просмотров 610Год назад
In this tutorial I will show you some of the basic command to configure ipset.
Onboard FTDv 7.3.0 to Cloud Firewall Management Center (FMC) in Cisco Defense Orchestrator (CDO)
Просмотров 1 тыс.Год назад
In this tutorial I will show you how to Onboard FTDv 7.3.0 to Cloud Firewall Management Center (FMC) in Cisco Defense Orchestrator (CDO)
Onboard FTDv 7.3.0 (FDM) to Cisco Defense Orchestrator (CDO)
Просмотров 1,1 тыс.Год назад
In this tutorial I will show you how to Onboard FTDv 7.3.0 (FDM) to Cisco Defense Orchestrator (CDO).
Configure Site to Site VPN between 2 FTDv using FDM Running on KVM (Ubuntu 22.04)
Просмотров 678Год назад
In today's tutorial I will show you how to configure Site to Site VPN between 2 Firewall Threat Defense Virtual (FTDv) using Firewall Device Manager (FDM).
Configure Remote Access (RA) VPN using FDM - FTDv 7.3.0 Running on KVM (Ubuntu 22.04)
Просмотров 3,3 тыс.Год назад
In this tutorial I will show you how to configure Remote Access VPN using Cisco Firewall Device Manager (FDM) to configure Cisco Firewall Threat Defense Virtual (FTDv) 7.3.0. Running in KVM in Ubuntu 22.04 You can follow the step by step guide.
Configure HA using FDM 2x FTDv 7.3.0 Running on KVM (Ubuntu 22.04)
Просмотров 253Год назад
In this tutorial I will show you how to configure HA for a pair of FTDv 7.3.0 using FDM. The FTDv is running on KVM in Ubuntu 22.04. You can go to my blog for step by step guide. dracocybersecurity.com/cisco-ftdv-7-3-0-using-fdm-to-configure-ha-for-ftdv-kvm-in-ubuntu/
Configure FTDv using FDM Port Forwarding to SSH Client Behind FTDv
Просмотров 420Год назад
In this tutorial I am going to show you how to Port Forward custom SSH port 11222 to actual Kali SSH port 22. PAT/NAT
Configure FTDv using FDM Port Forwarding to RDP Client Behind the FTDv
Просмотров 255Год назад
In this tutorial I will show you how to configure Port forwarding (PAT/NAT) to a RDP Client behind the FTDv using FDM.
Configure FTDv Using FDM to allow Management from Internet to the Inside Management Interface
Просмотров 224Год назад
In this tutorial I will show you how to configure FTDv using FDM to allow management from the Internet through Port Address Translation to the Inside Management Interface. Mapping port 8443 from the internet to port 443 of the internal management interface.
Configure FTDv using FDM to allow Management from the Internet/Outside
Просмотров 917Год назад
In this setup I will show you how to quickly configure the FTDv using FDM to allow management to the outside interface from the internet. And we will also look at the allowed ip address and a some nuance if you are running 2 Tier Firewall. You can check out my blog for the step by step guide as well if you do not want to go through the whole video. dracocybersecurity.com/configure-ftdv-using-fm...
Deploy FTDv10 in KVM (Ubuntu 22.04) using Virt-Manager
Просмотров 934Год назад
Deploy FTDv10 in KVM (Ubuntu 22.04) using Virt-Manager
Configure ASAv Inside and Ouside Interface as well as Dynamic PAT for Internet Access
Просмотров 938Год назад
Configure ASAv Inside and Ouside Interface as well as Dynamic PAT for Internet Access
How to Configure ASAv Management IP address and ASDM Management
Просмотров 2 тыс.Год назад
How to Configure ASAv Management IP address and ASDM Management
Python3.9.2 - File and Exception - SSH Brute Force Source IP Address
Просмотров 2,7 тыс.2 года назад
Python3.9.2 - File and Exception - SSH Brute Force Source IP Address
SASE - Configuring Meraki vMX (AWS) Site to Site VPN with MX67W - SDWAN
Просмотров 6 тыс.2 года назад
SASE - Configuring Meraki vMX (AWS) Site to Site VPN with MX67W - SDWAN
Python 3.9.2 Taking input from Command Line - Using sys module
Просмотров 1,5 тыс.2 года назад
Python 3.9.2 Taking input from Command Line - Using sys module
Configure RSYSLOG to LOG IPTABLES Rules with --LOG-PREFIX to multiple log files in Ubuntu 20.04
Просмотров 2,1 тыс.2 года назад
Configure RSYSLOG to LOG IPTABLES Rules with LOG-PREFIX to multiple log files in Ubuntu 20.04
Changing Bash Prompt - Ubuntu 20.04
Просмотров 1,6 тыс.2 года назад
Changing Bash Prompt - Ubuntu 20.04
Install Windows Server 2022 in a nested KVM environment on Ubuntu 20.04 with standard NAT.
Просмотров 4 тыс.2 года назад
Install Windows Server 2022 in a nested KVM environment on Ubuntu 20.04 with standard NAT.
Install Nested KVM on Ubuntu 20 04 - Hosted VPS - With Ubuntu Client VM
Просмотров 2 тыс.2 года назад
Install Nested KVM on Ubuntu 20 04 - Hosted VPS - With Ubuntu Client VM
Grep and Cut by Example - Potential Brute force on your SSH Server - Debian 11
Просмотров 1,2 тыс.2 года назад
Grep and Cut by Example - Potential Brute force on your SSH Server - Debian 11
Elastic Cloud - Auditd - Dashboard Visualization of Attack on SSH Server - Debian11
Просмотров 1,2 тыс.2 года назад
Elastic Cloud - Auditd - Dashboard Visualization of Attack on SSH Server - Debian11
SSH Tunneling - Remote port forwarding
Просмотров 3,6 тыс.2 года назад
SSH Tunneling - Remote port forwarding
Ty
Thank you!
thanksthank you for a very helpful guide. for example i have network site A: 200.200.0.0/16 vs site B: 10.0.0.0/16, 192.168.0.0/16 then what will be the configuration of vpn vs nat exempt
How can I reach the browser please ?
I followed the tutorial and was able to connect to the vncserver but when I try to open up terminal or run an application, nothing happens. I can run "vncserver" in putty and connect to "192.168.x.x:1" and everything works like it's supposed to there, it's just when I try connecting to "192.168.x.x:5990" that I have issues.
Very informative
thanks a lot really men Noww the question is how i deploy this webpart in my sharepoint page prod?
haven’t had a chance to do a video for that. Will find time in the coming month do update that part
walau that accent strong leh ;-D
but a great video! ;-)
haha sorry no slang, but glad it’s useful
You save my life man!! Thank you!!
Glad to hear it!
@@dracocybersecurity can you do one video of how to do netflow on fdm?
Quick question: If my Firepower has an config already, the CDO will delete the config on the process of adding it? Just like FMC a mean!
As of right now CDO will delete the config on the process of adding it. FMC is the option if you only have a single FTD. If you have a HA pair. You can onboard one of the FTD and migrate the policy to CDO/CloudFMC. docs.defenseorchestrator.com/#!c-migrating-fdm-devices-managed-by-cisco-defense-orchestrator.html
Sorry for bothering you, how do I activate the CDO license? I don't see anywhere to do that. My client purchased a CDO license, but his tenant is still on trial
docs.defenseorchestrator.com/#!about-licenses.html If after adding the Firewall license and you still cannot get it to work. Do contact the local team or open a TAC case.
12:10 Completely lose on the port forwarding. How can I do that if using Windows OS?
You are looking at NAT using IPTables/Firewall to forward the incoming traffic to the Windows OS? If you are looking at just internet access from the Windows Server than using the NAT feature on the KVM should be fine. If you are looking at forwarding internet traffic to your window OS. Check out the following it is an example to forward RDP traffic to the Server in the KVM but you will need to change the network type . dracocybersecurity.com/configure-iptables-port-forwarding-to-nested-guest-vm-in-kvm-default-nat-virtual-bridge-ubuntu-20-04/
Good work!!!!
Thank you! Cheers!
Great work!!!!!!
Thank you! Cheers!
i don't have FMD options, may i miss something
You might want open a tac case with Cisco. I have seen newer CDO instances that do not have that options.
What is different between FTD and FDM onboard
FTD Firewall Threat Defense is the software that runs on the Firewall and FDM Firewall Device Management is the management Software for managing a single device that runs on the firewall. if you onboard using FDM it has less feature and capabilities.
Great work!!!!! Many thanks
Many thanks!
Very helpful and informativw
Glad it was helpful!
Just a fair warning, DO NOT attempt to use Duo's Linux documentation for Ubuntu. You WILL end up with a BRICKED system. Duo has been utterly useless when attempting to obtain accurate documentation.
Always important to test out the capabilities in a test or staging environment or get professional service before implementing in critical system
Great video this helped me setup the environment for basic traffic, my question is how do you configure the Environment to have ALL traffic passthrough the Meraki? Inbound and outbound. I would like the Meraki to manage inbound firewall filtering if possible. Or is this Meraki only for VPN management?
Thanks, Meraki vMX in the cloud only function as a One-Arm VPN Concentrator. If you need VPN and Firewall capabilities in AWS. You can check out the Cisco Firewall that is available in the Cloud Market place. For your on-prem Meraki MX it is both a firewall as well as a VPN Server.
Great Video!! One question here. Would we be able to configure /16 (10.111.0.0/16) as the local subnet on the vMX instead of 10.111.10/24? This is because you would want your entire AWS network reachable from the remote sites.
It is possible to expand the subnet to /16. You do have to determine how the existing AWS routing works as well. But if it is simple inclusion on the subnet in a single LAN then it should be fine.
Will really appreciate if you can make a video spinning two virtual MX in AWS depicting High Availability
This is a great video. Thank you very much!!!!
Glad that you enjoy it. :)
Thank you for your detailed presentation. Issue I am having is SSH from AWS SSH server cannot connect to SSH server at client side via VPN. It times out.
For a start I will check if the SSH Server is routing the traffic through the VPN Tunnel.
Very helpful video! Helped me when i got stuck in a rut. Appreciate your work!
Glad that it is useful :)
Can I make windows server have a public ip? that is reachable over internet?
Yes it is possible. you just need to know that it exposes your window server directly to the internet which is not advisable. For testing you can get additional public ip address from the service provider and assign the public ip address to the windows server. In my test environment I use the bridge function to bridge the public ip to my device that I want to assign the public ip. which is usually the firewall, but u can do it for Windows or Linux as well.
I successfully installed win2022 on KVM, the machine works well. Could you share how to configure the network between ubuntu and the virtual machine? I used CyberPanel on Ubuntu for hosting sites The KVM used the same IP address. But I can't set-up the IIS to recognize that public IP. It always connects to Cyberpanel first. How could I run websites on IIS? Do I need another public IP? Thanks
For exposing your IIS to the public internet having a public IP address to bridge to IIS server might be the easiest way to do it or you can use iptables to do port forwarding. however you will need to understand how the various bridge function or DNAT and maybe SNAT depending on your setup to expose the web service. I have not done cyberpanel or even cockpit configuration. I usually do it through the command line for iptables configuration and virt-manager for bridge config.
Thanks for the Guide! Detailed & precise Any idea if it works by not using AutoVPN but standard non-meraki ipsec across to AWS? Reason being, both our branch Mx and vMx belongs to diff organization account...can't do autoVPN
It should work with the standard IPSec config. as long as the crypto and protocol is supported have not done with AWS but did a standard IPsec with oracle cloud before. the tricky part is getting the protocol to match and then the routing. let us know if u manage to get it working with AWS.
You may want to get an Elastic IP to use with the vMX for its Public IP so it doesn't ever change and break your IPsec tunnel.
It's not going to work for what you need. IPSEC tunnels on regular site to site can only recognize and pass traffic for one subnet to AWS from Meraki. I think this has something to do w/Meraki being policy based instead of route based site to site. You'd be much better off merging sites into the same org. Contact support for help.
This is a very special use case, and actually one that I am now needing. How do I expose the ports to the windows ADD that is running inside an Ubuntu KVM? I have tried Socat and this didn't work, the public address on the Linux machine is working fine, I have a QOS to the Ubuntu server, but cannot get the Windows machine inside to be reached from the outside. Any help will be greatly appreciated.
For my lab environment I use iptables. using dnat to forward port 3389 to the internal windows ip address. there are a few configurations you need to do if you know iptables then it is easy. be mindful of opening up RDP directly to the internet as it opens up the server to direct attacks.
You can also check out my post on what the 2 rules might look like. dracocybersecurity.com/how-to-configure-iptables-to-port-forward-rdp-3389-to-windows-machine-in-kvm/ I use the -I XXXX 1 to insert the rule in front to the top of the nat table, but can you just use -A add depending on our config. Do not the rules in IPTABLES are executed top down.
Do you think it’s possible to create a webpart like highlighted content but code it to play videos inline and also be able to like, add hashtags and comment on videos directly?
You will probably need to use the video webpart for inline video. support.microsoft.com/en-us/office/using-videos-on-sharepoint-pages-5a0eb37c-81a8-45b7-875e-ff0515dd2e5f You can also check out microsoft stream or do some custom development for adding hashtags and comments. Have not seen out of the box capabilities for hashtags and comments for inline video.
7:36 How is it possible? You have opened only port 22
This is leveraging on ssh protocol (port 22) to tunnel the rest of the traffic across. It is actually a very old school way of creating a tunnel for traffic that you do not want to open additional ports. These days vpn tunnels are the more common use as it is easier to manage for mutliple clients or site to site tunnels.
Hello Geek, Can you be my mentor?
Thanks for the confidence, but I have not been doing any advance stuffs with Sharepoint :)
im receiving this message after log in " oh,no something went wrong ! " what can i do with this ?
You can check these out to see if it is the issue that you are facing. lists.debian.org/debian-backports/) you can download xrdp 0.9.15-1 and xorgxrdp 1:0.2.15-1 via snapshot.debian.org/ Those package versions were still compatible with libc6 from bullseye. sudo apt install ./xorgxrdp_0.2.15-1_amd64.deb sudo apt install ./xrdp_0.9.15-1_amd64.deb
Total lifesaver - thank you!!
Glad it helped!
Thanks! this video solved my issue...I was installing on ubuntu 20.04 and the missing /lib/security folder was missing along with setting up a user in Duo! I feel dumb...Thanks again!
Glad it helps. And these things happens all the time :)
I get a black screen with just a cursor? how do I fix it?
There are multiple reason that you are getting just a cursor. The 2 common problem might be the Graphical Desktop Environment that you installed might be causing the problem. or could be a permission issue preventing the GDE from loading properly. You might want to take a look at the xrdp logs to see if there is anything mentioned there. github.com/neutrinolabs/xrdp/issues/2064. You can check out this post to see if it solves your problem.
Can use in remote desktop connection?
Yes it can support RDP, just need to make sure that the firewall allows that. For my lab setup I utilized this windows server as a AD and only allow RDP through local vpn.
Thanks for the video - was looking for the second and subsequent videos in this series, but couldn't find any.
I haven't had time to do the second video for this yet. Stay tune for more
Explained in great detail! Thank you so much!!
Glad it was helpful!
Thanks for making this video. Any guidance on setting up the virtual network ? I can ping the vmx from my local network. I am having issues after I create a virtual machine and having that see the VMX and also my local network
Did you create the Virtual Machine in the existing subnet that you have configured during the provisioning? If you have follow closely from 14min to 23min of the video it will work. However any deviation from the standard steps then you will need to tweak the routing and route table of Azure this becomes complex for me as I am not an expert in Azure Networking, unlike Linux/AWS the Azure Routing is not easy to troubleshoot. I had issue during the video creation when I create the Subnet after the vMX creation and also creating the Virtual Machines in another subnet. I am assuming that if you are doing ping you have allowed ping on the Windows virtual machine and if you have not done any changes to the RDP of your Windows VM you have tried to RDP from your local network machine to the Windows Virtual Machine and the basic interesting traffic are not in conflict. Do let me know if you manage to get it to work :) with the basic steps. If you let me know without sharing sensitive information on how your setup looks like I can try to see if I can check out in my setup what you can do to get it to work. Or talk to your local Meraki expert. Do note that in my view Meraki is really great for its simplicity and scalability but any complex setup you will need to do your feasibility assessment base on your needs.
@@dracocybersecurity After configuring for a week now. I finally figured it out with your comment above. The drop down menu had cached old Virtual Networks and the new ones that I had created were not showing up. I opened a different browser and in the drop down my new virtual network with the correct subnet showed up. Everything works correctly. Thanks for the video. Only recomendation would be to setup a new virtual network in the video and show how it was done if anyone is new to working in azure
Great that you manage to get it to work. cache on the browsers have their way of tripping us :). thanks for the feedback on showing the creating the new virtual network. That can be daunting for people new to Azure. I am still learning subnetting and the network gateway in Azure as well. wish that there is more consistency in network deployment in the cloud providers :) I am starting to like the simplicity of Oracle Cloud in their way of networking not much advance stuffs but the basic routing and VPN are a lot easier. wondering when vMX will be extended to them. when I get time I will do a video on vMX in AWS. that is a lot easier since more Linux style VPS. if you have a chance try out the whole setup for vMX on Azure and AWS and a few locations of hardware boxes. It is amazing for simple development need and management. but cost can be a concern for testing.
@@dracocybersecurity thanks for your help and making the video. I will check out AWS
@@dracocybersecurity Hey mate waiting for video for AWS Vmx, I need to deploy this for work.
Great Video. It answered a few questions I had about this project.
Glad I could help!
Hi this is really helpful for use case at work. This is pretty uncommon setup so I never thought I would find a video on this. Thank you very much!!
Great to hear!
thanks, it helped!
Glad it helped!
Thanks for the walkthrough, worked perfectly.
Glad it helped
Not sure what I did wrong, but I configured the DUO client to my RADIUS server. The connectivity tool in DUO says “There are no configuration problems” the MX device is configure successfully to the RADIUS server, however when I connect to the VPN I am able to successfully connect without 2FA? Any ideas where to look?
Hard to say but did you configure the Duo Authentication Proxy, to proxy the authentication? Seems that your vpn client is authenticating directly to the Radius instead of through the Duo Authentication proxy. The DAP configuration should be similar to how it is configure in this video, but do check what are the parameters that you need to change.
Have you figured this out James? I am having the same problem. Thanks
can you download Firepower NGFW ovf file to google driver sir ? because i can't download
You need to have a valid Cisco Partner or Customer account to download the ovf. Do reach out to your country authorized distributor or partner to request for that.
Are there any other options for MFA for meraki that you've used.
I have not done any other integration with other MFA. But you should be able to integrate with other MFA.
Appreciate this video! Waiting for your next one.
More to come!
Great video! Very well done!!
Thank you! Cheers!
where are the remaining parts !!
Below are the balance 2 parts. These are basic videos to help those interested get started ruclips.net/video/f2T8ZhYyIco/видео.html Part 2/3 ruclips.net/video/RvtIhRX4Fv0/видео.html Part 3/3
sorry i am new to DUO and Meraki, i have understood your configuration but one thing I want to know is when you finally tested user for Client VPN how that push notification was sent to you? do we need to configure and link the AD user we are testing from under DUO portal so that notification is sent to us?
Check out this link. duo.com/docs/meraki-radius Duo they have a integration diagram that explain the flow much better than I do. What i have done is the older L2TP client. They now have the integration with AnyConnect. Which in my view is more secure. Of course L2TP is free with the system. AnyConnect I believe you need to pay for the license. Talk to your local Partner / Disti to get more support on the detail if you are interested in AnyConnect integration