- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- Re: MUH with VMSS to protect AVD (VDI in Azure)
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
MUH with VMSS to protect AVD (VDI in Azure)
this post will show a use case for my past post about ID-Sharing.
Customer with VDI solution uses our MUH agent to identify users behind the same machine and apply rules based on their identity, this is great and uses the agent to communicate with a GW that stores the identity and ports used by a specific user, the issue is when we are in the Cloud and a VMSS, the agent can communicate only to one GW so VMSS environments are an issue, so we can use the ID Sharing mechanism to connect the MUH agent to one GW that only will serve as Collector and Share the learned Identities from this one to the VMSS members, this can be automated with a simple script that I shared in the past (past post).
Here a simple diagram from my demo.
and a video showing all the stuffs
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@ChristianCastil You bring great architecture and ideas here!
Wonderful
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Awesome!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
wouldn't it be better to have simple gateway deployed in same backend subnet as VMSS and use it ? instead of going back to on-prem via vpn/express route.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
meanwhile there is connectivity the place of the collector/sharing GW is not relevant, in this scenario I place on-prem to avoid the use of rented compute in the cloud, since will be static and no benefit from any cloud feature, also because normally the customer will have some on-prem devices, in case this is not true or they are allowed to pay for a collector machine in the cloud, they can place it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Nice work, on a related note I know many have been waiting for the Identity Awareness APIs coming in R81.20.
For MUH on Windows 10 please see sk177024
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Nice Document!!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Nice!
Unfortunately the Word document is protected by Capsule Docs!