Coming to me in the form of Sonicwall's Cloud Secure Edge (at a monthly, per-user cost), I understand the basics of what they say it's going to do, but I also have been doing this long enough to understand when someone's using a lot of buzzwords and scare tactics to hype a much simpler concept that I feel I am not as much up on. I would welcome any and all comments from those of you with any experience in implementing/utilizing/understanding SSE. Thanks in advance!
27 Comments
Brkdncr@lemmy.world · 6 pts · 201d
It’s a hosted vpn.
TheOneAndOnly@lemmy.world · 2 pts · 201d
Right...but is it somehow "more secure" than just a simple SSL VPN client? Granted, I have to put in a password, so anyone who compromises that password now can setup the same, so a password-less solution is inherently "more secure" in that regard...but aside from that...?
Brkdncr@lemmy.world · 4 pts · 201d
It’s probably IPsec, not ssl.
Enterprise grade firewalls should be cert, MFA or SAML. I wouldn’t expect a simple username/password in use today.
It’s not more or less secure than the same setup on an in-house firewall.
Passerby6497@lemmy.world · 2 pts · 201d
Don't use sonic walls, and also I don't have any configured, so I can't help you with any specifics other than other vendors.
Just guessing, they might be doing some kind of network level exploit detection along with the VPN. My network team has that setup on our firewall (multi-zone, including VPN), and I've been called in on more than a few security calls triggered by network EDR. If they have people you can use in that kind of a scenario, it would probably be worth it (my CISO is always trying to get customers to buy into the service BEFORE we have to get on a call rather than after).
TheOneAndOnly@lemmy.world · 1 pts · 201d
I appreciate the response. That makes sense, but I think I still have a lot of homework to do!
False@lemmy.world · 5 pts · 201d
Hadn't heard of it, reading up on it I think my employer (a very large company) has already implemented a form of it effectively. For us it's taken the form of a trusted auth service for all of our internal websites/services with everything now being directly Internet facing. This means that you can access (almost) everything without a VPN from anywhere, and it removes the idea of "internal" traffic being trustworthy. It's mostly been pretty nice from a user perspective.
It also sounds like a buzzword that a lot of companies are trying to use to sell you bundles of saas products.
TheOneAndOnly@lemmy.world · 3 pts · 201d
Thank you! The whole thing feels like another "the cloud", or "AI" push, and I instantly distrust anything that leverages fear as a sales tool. From what I'm seeing, it feels like there's potential for improving the user experience, so I'm glad to hear that aligns with your perspective!
possiblylinux127@lemmy.zip · 4 pts · 201d
Avoid Sonicwall
TheOneAndOnly@lemmy.world · 2 pts · 201d
Yeah? Is that experience talking?
thermal_shock@lemmy.world · 1 pts · 199d
Yes. Even setting DHCP scopes and opening/forwarding ports is a pain in the ass compared to others like meraki. Should just be a click, not 14 steps.
TheOneAndOnly@lemmy.world · 1 pts · 198d
I haven't used a Meraki in about 4 years, but the last one I had to administer was kind of a pain in the ass. Maybe it's just experience?
MehBlah@lemmy.world · 3 pts · 200d
Dell product and dell is currently circling the drain.
TheOneAndOnly@lemmy.world · 1 pts · 200d
Dell dropped SonicWall in 2016. SonicWall is owned by private equity now.
MehBlah@lemmy.world · 2 pts · 199d
Didn't know that. I haven't had to support it all since 2018.
thermal_shock@lemmy.world · 0 pts · 199d
Yeah, we switched all our clients to meraki and some on ubiquiti, depending on their budget and user counts. I personally use ubiquiti gateways/switches/waps at home and love it.
MehBlah@lemmy.world · 1 pts · 199d
I use ubiquity AP's at the house but I run pfsense for my router. The unifi gateways I've dealt with were buggy. Of course its been at least five years since I've touched one of those and they may be more stable now.
thermal_shock@lemmy.world · 1 pts · 199d
Mines a little old, ran into a few bugs, but nothing detrimental. I don't know much about the new ones like the wall mounted ones. Mine are all rack mount.
MehBlah@lemmy.world · 1 pts · 199d
Like I said the problems I had have probably been addressed. Ubiquity has always been pretty diligent about keeping their products working as advertised.
I have the pfsense plus routers at work and one thing I like about them is the selection of tunnel options and the really great filter. Unifi controllers have though been increasingly require their gateways to function in full. That kind of forced integration is a strike in my book.
thermal_shock@lemmy.world · 1 pts · 199d
I used pfsense before, I got ubiquiti to familiarize myself more with it since clients use it.
I hate the app too, I have it setup on a small micro PC setup as my pihole and DNS.
slazer2au@lemmy.world · 3 pts · 201d
Much like Zero Trust it looks like a framework on providing access to privileged information based on policies. Looks to integrate zero trust with a cloud firewall and session broker.
TheOneAndOnly@lemmy.world · 2 pts · 201d
Where I'm trying to get is, zero-trust being a good framework, does it make sense to go with SW's proposal, or can I do it myself for less/no cost with other solutions out there? It seems like MS has an offering under "Global Secure Access" that might be bundled in with Office365 premium, so I've started focusing there...
mech@feddit.org · 4 pts · 201d
As a rule of thumb IMO the fewer features you implement with M365 the better.
TheOneAndOnly@lemmy.world · 1 pts · 201d
Yeah, I get that. The disruption to everyone's workday switching to FOSS services would be immediate and (figuratively) violent...but I've had some conversations down that road...
mech@feddit.org · 3 pts · 201d
I'm not talking about FOSS. It's just M365 really sucks to administrate and when I see how you're supposed to configure it and what the defaults are, I'm regularly like

TheOneAndOnly@lemmy.world · 2 pts · 201d
Hah! Oh... Very much agreed.
voracitude@lemmy.world · 2 pts · 201d
False@lemmy.world · 2 pts · 201d
My employer is not using Sonicwalls solution, but a home grown proprietary solution.
But please don't take that as evidence in favor of doing it yourself - their capability in this area is atypical.
TheOneAndOnly@lemmy.world · 2 pts · 201d
My customer is a mid-large size environment with not a lot of tech-savvy folk who are always frustrated with additional security, so anything that would decrease the number of MFA pushes passwords they have to remember would be a win. For that matter, decreasing the number of hours spent admin-ing those things is also desireable. Currently, we're just using simple SSL VPN to access on-prem file/print services.