Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
LazarusG
Contributor
Contributor

mgmt and stealth rule for on-prem gateway and maas?

Hi 

Hope this is the right location for this post(?)

Potentially dumb question: what is best practice for a mgmt and stealth rule on an on-prem policy if the manager is cloud/maas?

If mgmt is through the maas tunnel, (which is reliant on fqdn resolution on the gw?) would this instruction be valid still?

Best Practices for Access Control Rules

Thanks!

0 Kudos
3 Replies
the_rock
Legend
Legend

Thats totally valid question @LazarusG . Personally, I would say same would technically apply. Thats at least what TAC told me about this 2 years ago.

Andy

0 Kudos
PhoneBoy
Admin
Admin

When using Smart-1 Cloud, all connectivity between management and gateway is via a single HTTPS connection initiated from the gateway. 
No specific rules should be necessary unless you've disabled the Implied Rule that allows Outbound traffic from the Gateway.

0 Kudos
LazarusG
Contributor
Contributor

Thanks - the reasons for asking is that the policy has  no stealth rule at the moment but we are trying to prevent external access to the https cert - I have looked at many SKs but in my lab building on-prem environment incrementally the stealth rule if the first thing that deterministically stops the access. However this is an on-prem lab not maas.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events