• 0 Posts
  • 31 Comments
Joined 2 years ago
cake
Cake day: June 24th, 2024

help-circle





  • Zabbix is extremly nice.

    Why?

    • API Monitoring for Proxmox and Docker/Podman. Aka "you don’t need to setup monitoring for every container/LxC/VM. Do it once for the host,then everything gets autodiscovered.

    • Active and passive agents as well as SNMP, IPMI,etc. can be combined as you like. Also does Website/service/application/database monitoring, SSG/Telnet checks and nowadys can even do Prometheus and MQTT/Modbus

    • The proxy is really really worth it. It collects data from nodes you do not want exposed and relays them to the server. This includes all kind of inputs and is really easy to setup.

    • Due to it being around for two decades there are a shitton of templares for devices - and it’s fairly easy to do your own.

    • Unlike other systems (cough checkmk cough Grafana) there are no features that are only available to paying customers.

    The most major downsides are the fact that it’s moderately to fairly ressource intensive to run in a small setup(but does consume less than others in large Setups) and it’s far less flashy dashboards. (Which are still powerful,though)



  • Not a fan. Absolutely not.

    They had multiple security incidents which they kept under the rugs for a long time, they have the tendency to EOL devices without warning (which then means you need to replace your sometimes 9month old device or your whole enviroment can’t be updated), their lock-in into their ecosystem is much more complete as they can’t be used properly without their enviroment.(e.g. Omada devices can work without the Omada stuff, with Unifi you will always need a controller for some functions).

    So if you realy need SDN features like Unifi look at Omada,otherwise Mikrotik is a solid alternative. (And OPNsense for firewall)



  • Ungefähr jede KRITIS Infrastruktur in DE die überhaupt soweit geht einen zweiten Kanal zu haben nutzt die…selbst wenn es Alternativen gäbe.

    Dabei ist das Zeug netzseitig extrem wacklig aufgebaut und ein Ausfall jetzt nicht so unwahrscheinlich - insbesondere wenn im Schadensfall die Zellen alle gleichzeitig ausgelastet sind. Und leider ist das nun nicht so unwahrscheinlich.

    …richtig mies dabei: Es gibt eine einsatzbereite europäische Lösung: OneWeb ist zwar nicht billig(die Terminals liegen eher so in der 5k Range) und das System ist bauartbedingt etwas langsamer was Latenz (70ms) und Throughput angeht, dafür aber eben europäisch, deutl. weniger störanfällig und sind netzseitig extrem gut auf KRITIS und Business eingestellt - weil das der geplante Markt ist.

    Aber nein, deutsche Behörden schließen betteln stattdessen tlw. Starlink an bitte 10 Jahres Verträge zu kriegen. (Was StarLink nicht gerne macht). Obwohl sie wissen,dass IRIS2 in den Startlöchern steht das primär für sie gemacht ist.

    Arghhhhhh!





  • My company is a part of critical infrastructure and we provide consulting in disasters (e.g. how to get a hospital back up and running). So we fall under European legislation to have certain precautions. And as I colocate in my companys rack…it’s easier. As the rack is in a room I rent to my company. (We are small and I am the founder,that makes it easier)

    But yeah, we put a bit of thought in it. Waiting for Iris2 finally materialise so I can get rid of LTE finally.






  • I have a LTE Backhaul,but admittedly if the firewall itself craps out I would also be offline - but I can at least reboot it via a plain old GSM power plug. That thing does not directly reboot the firewall,though, but brings up a old raspberry (usb boot,I don’t trust sdcards) which then checks if outside connectivity is still available (so if the GSM power plug gets compromised it’s not an issue) and if not tries a shutdown or,if that is unsucessful, a powercut of the firewall. If that also doesn’t work it triggers a dry contact in the GSM plug which leads to the plug sending out a SMS so I know I am fucked and need to get someone with a key to the rack.