SAML Accounts on Vault
How would you onboard the any privileged account that is either protected using MFA and/Or using SAML SSO
How would you onboard the any privileged account that is either protected using MFA and/Or using SAML SSO
Have three regions all connected using vWAN solution . I have a requirement where each region will connect to one common site using IPSEc and target destination prefix is common. Its because each region can locally go via ipsec . Can I attach common remote address to ipsec vpn gw or it may not work ?
How does Azure ILB maintain symmetry in traffic flow when region 1 hub has NVA1 and region 1 hub has NVA2 . Each of NVA behind ILB . How each region ILB maintain flow symmetry
We have multiple HUB in different resigns. Whats the best way to handle routing between HUB when they are peered and traffic has to go through NVA.
Hey,
I have deployed active active FTD in Azure and will be setting up ipsec tunnel with remote sites. Whats the best way to handle active active ?
How would you deploy API Gateway in Datacenter/Cloud ? Do you really need to deploy API Gateway in DMZ then another one in Internal or you can only have internal API gateway ? I guess its also question where the api endpoints are hosted ?
I have recently deployed Cisco WLC in Azure Cloud but what I can not find what machine certificate used between WLC and access-point to establish DTLS tunnel . My understanding is that in VM there is no MIC certificate its only self-signed . If its self-signed how access-point trust ?
I would like to limit the usage of bandwidth from/to certain subnets which are placed behind the HUB . Panorama based SD-WAN plugin used . When branch send traffic to subnet that behind hub I would like to limit the usage to not go more then 20% of total bandwidth . What will be the best way to handle ?
Trying to use CyberArk Privilege Cloud TFE idsec module https://registry.terraform.io/providers/cyberark/idsec/latest/docs .During TFE apply I get 401 error but when I use same service user in direct API it works . I am not sure if I missing something in TFE provider configuration . Any idea would appreciate.
Whats the best way to secure service users? I am planning to use in Github pipeline. Whats the recommended practice?
I am building global protect configuration for laptops so build team can build the machine and its allow to connect to AD , PKI. But at the moment I am struggling to understand difference both options.
Also how user-logon will works in both cases.