DracoCyberSecurity
DracoCyberSecurity
  • 62
  • 118 947

วีดีโอ

Deploy FMCv 7 4 1 in KVM on Ubuntu 22 04
มุมมอง 1464 หลายเดือนก่อน
In this tutorial I will show you how to deploy the Firewall Management Center Virtual version 7.4.1 in KVM running on Ubuntu 22.04 in the cloud. We will be using the virt-manager to deploy the FMCv. You can follow the steps in my blog as well. dracocybersecurity.com/deploy-fmcv-7-4-1-in-kvm-ubuntu-22-04
How to create a SYSTEMD service for VNCServer to autostart at reboot
มุมมอง 715 หลายเดือนก่อน
In this tutorial I will show you: 1. How to configure a SystemD service 2. tweak the xstartup file. 3. Reload the SystemD daemon 4. Enable persistent SystemD service and start the service
How to create a SYSTEMD Timer to update ip address in ipset from Dynamic DNS
มุมมอง 846 หลายเดือนก่อน
In this tutorial I will show you how to. 1. Create a SYSTEMD Service to run a script 2. A simple script to update ipset set/list 3. A SYSTEMD timer to run the script every min.
How to create a cron job to update ipset with ip address from Dynamic Domain
มุมมอง 1777 หลายเดือนก่อน
In this tutorial I will show you how to. 1. Create a ipset 2. Create a script to get the ip address from a dynamic domain. 3. Update the ipset 4. Create a cron job 5. Basic validation 6. Adding ipset into a iptable rule.
How to configure ipset
มุมมอง 3738 หลายเดือนก่อน
In this tutorial I will show you some of the basic command to configure ipset.
Onboard FTDv 7.3.0 to Cloud Firewall Management Center (FMC) in Cisco Defense Orchestrator (CDO)
มุมมอง 6899 หลายเดือนก่อน
In this tutorial I will show you how to Onboard FTDv 7.3.0 to Cloud Firewall Management Center (FMC) in Cisco Defense Orchestrator (CDO)
Onboard FTDv 7.3.0 (FDM) to Cisco Defense Orchestrator (CDO)
มุมมอง 84510 หลายเดือนก่อน
In this tutorial I will show you how to Onboard FTDv 7.3.0 (FDM) to Cisco Defense Orchestrator (CDO).
Configure Site to Site VPN between 2 FTDv using FDM Running on KVM (Ubuntu 22.04)
มุมมอง 39311 หลายเดือนก่อน
In today's tutorial I will show you how to configure Site to Site VPN between 2 Firewall Threat Defense Virtual (FTDv) using Firewall Device Manager (FDM).
Configure Remote Access (RA) VPN using FDM - FTDv 7.3.0 Running on KVM (Ubuntu 22.04)
มุมมอง 2K11 หลายเดือนก่อน
In this tutorial I will show you how to configure Remote Access VPN using Cisco Firewall Device Manager (FDM) to configure Cisco Firewall Threat Defense Virtual (FTDv) 7.3.0. Running in KVM in Ubuntu 22.04 You can follow the step by step guide.
Configure HA using FDM 2x FTDv 7.3.0 Running on KVM (Ubuntu 22.04)
มุมมอง 200ปีที่แล้ว
In this tutorial I will show you how to configure HA for a pair of FTDv 7.3.0 using FDM. The FTDv is running on KVM in Ubuntu 22.04. You can go to my blog for step by step guide. dracocybersecurity.com/cisco-ftdv-7-3-0-using-fdm-to-configure-ha-for-ftdv-kvm-in-ubuntu/
Configure FTDv using FDM Port Forwarding to SSH Client Behind FTDv
มุมมอง 230ปีที่แล้ว
In this tutorial I am going to show you how to Port Forward custom SSH port 11222 to actual Kali SSH port 22. PAT/NAT
Configure FTDv using FDM Port Forwarding to RDP Client Behind the FTDv
มุมมอง 157ปีที่แล้ว
In this tutorial I will show you how to configure Port forwarding (PAT/NAT) to a RDP Client behind the FTDv using FDM.
Configure FTDv Using FDM to allow Management from Internet to the Inside Management Interface
มุมมอง 145ปีที่แล้ว
In this tutorial I will show you how to configure FTDv using FDM to allow management from the Internet through Port Address Translation to the Inside Management Interface. Mapping port 8443 from the internet to port 443 of the internal management interface.
Configure FTDv using FDM to allow Management from the Internet/Outside
มุมมอง 604ปีที่แล้ว
In this setup I will show you how to quickly configure the FTDv using FDM to allow management to the outside interface from the internet. And we will also look at the allowed ip address and a some nuance if you are running 2 Tier Firewall. You can check out my blog for the step by step guide as well if you do not want to go through the whole video. dracocybersecurity.com/configure-ftdv-using-fm...
Deploy FTDv10 in KVM (Ubuntu 22.04) using Virt-Manager
มุมมอง 812ปีที่แล้ว
Deploy FTDv10 in KVM (Ubuntu 22.04) using Virt-Manager
Configure ASAv Inside and Ouside Interface as well as Dynamic PAT for Internet Access
มุมมอง 877ปีที่แล้ว
Configure ASAv Inside and Ouside Interface as well as Dynamic PAT for Internet Access
Deploy ASAv in KVM Ubuntu
มุมมอง 1.2Kปีที่แล้ว
Deploy ASAv in KVM Ubuntu
How to Configure ASAv Management IP address and ASDM Management
มุมมอง 1.7Kปีที่แล้ว
How to Configure ASAv Management IP address and ASDM Management
install ASAv in VMWARE ESXi
มุมมอง 2.9Kปีที่แล้ว
install ASAv in VMWARE ESXi
Python3.9.2 - File and Exception - SSH Brute Force Source IP Address
มุมมอง 2.7K2 ปีที่แล้ว
Python3.9.2 - File and Exception - SSH Brute Force Source IP Address
SASE - Configuring Meraki vMX (AWS) Site to Site VPN with MX67W - SDWAN
มุมมอง 6K2 ปีที่แล้ว
SASE - Configuring Meraki vMX (AWS) Site to Site VPN with MX67W - SDWAN
Python 3.9.2 Taking input from Command Line - Using sys module
มุมมอง 1.5K2 ปีที่แล้ว
Python 3.9.2 Taking input from Command Line - Using sys module
Configure RSYSLOG to LOG IPTABLES Rules with --LOG-PREFIX to multiple log files in Ubuntu 20.04
มุมมอง 2K2 ปีที่แล้ว
Configure RSYSLOG to LOG IPTABLES Rules with LOG-PREFIX to multiple log files in Ubuntu 20.04
Changing Bash Prompt - Ubuntu 20.04
มุมมอง 1.5K2 ปีที่แล้ว
Changing Bash Prompt - Ubuntu 20.04
Install Windows Server 2022 in a nested KVM environment on Ubuntu 20.04 with standard NAT.
มุมมอง 3.7K2 ปีที่แล้ว
Install Windows Server 2022 in a nested KVM environment on Ubuntu 20.04 with standard NAT.
Install Nested KVM on Ubuntu 20 04 - Hosted VPS - With Ubuntu Client VM
มุมมอง 1.9K2 ปีที่แล้ว
Install Nested KVM on Ubuntu 20 04 - Hosted VPS - With Ubuntu Client VM
Grep and Cut by Example - Potential Brute force on your SSH Server - Debian 11
มุมมอง 1.2K2 ปีที่แล้ว
Grep and Cut by Example - Potential Brute force on your SSH Server - Debian 11
Elastic Cloud - Auditd - Dashboard Visualization of Attack on SSH Server - Debian11
มุมมอง 1.2K2 ปีที่แล้ว
Elastic Cloud - Auditd - Dashboard Visualization of Attack on SSH Server - Debian11
SSH Tunneling - Remote port forwarding
มุมมอง 3.4K2 ปีที่แล้ว
SSH Tunneling - Remote port forwarding

ความคิดเห็น

  • @hoggrobinson
    @hoggrobinson 2 หลายเดือนก่อน

    Very informative

  • @AndresDiaz-et5mc
    @AndresDiaz-et5mc 4 หลายเดือนก่อน

    thanks a lot really men Noww the question is how i deploy this webpart in my sharepoint page prod?

    • @dracocybersecurity
      @dracocybersecurity 3 หลายเดือนก่อน

      haven’t had a chance to do a video for that. Will find time in the coming month do update that part

  • @GerryCrooked
    @GerryCrooked 5 หลายเดือนก่อน

    walau that accent strong leh ;-D

    • @GerryCrooked
      @GerryCrooked 5 หลายเดือนก่อน

      but a great video! ;-)

    • @dracocybersecurity
      @dracocybersecurity 5 หลายเดือนก่อน

      haha sorry no slang, but glad it’s useful

  • @arturit0_
    @arturit0_ 5 หลายเดือนก่อน

    You save my life man!! Thank you!!

    • @dracocybersecurity
      @dracocybersecurity 5 หลายเดือนก่อน

      Glad to hear it!

    • @arturit0_
      @arturit0_ 5 หลายเดือนก่อน

      @@dracocybersecurity can you do one video of how to do netflow on fdm?

  • @arturit0_
    @arturit0_ 6 หลายเดือนก่อน

    Quick question: If my Firepower has an config already, the CDO will delete the config on the process of adding it? Just like FMC a mean!

    • @dracocybersecurity
      @dracocybersecurity 6 หลายเดือนก่อน

      As of right now CDO will delete the config on the process of adding it. FMC is the option if you only have a single FTD. If you have a HA pair. You can onboard one of the FTD and migrate the policy to CDO/CloudFMC. docs.defenseorchestrator.com/#!c-migrating-fdm-devices-managed-by-cisco-defense-orchestrator.html

  • @Tom1st
    @Tom1st 8 หลายเดือนก่อน

    Sorry for bothering you, how do I activate the CDO license? I don't see anywhere to do that. My client purchased a CDO license, but his tenant is still on trial

    • @dracocybersecurity
      @dracocybersecurity 8 หลายเดือนก่อน

      docs.defenseorchestrator.com/#!about-licenses.html If after adding the Firewall license and you still cannot get it to work. Do contact the local team or open a TAC case.

  • @237311
    @237311 9 หลายเดือนก่อน

    12:10 Completely lose on the port forwarding. How can I do that if using Windows OS?

    • @dracocybersecurity
      @dracocybersecurity 9 หลายเดือนก่อน

      You are looking at NAT using IPTables/Firewall to forward the incoming traffic to the Windows OS? If you are looking at just internet access from the Windows Server than using the NAT feature on the KVM should be fine. If you are looking at forwarding internet traffic to your window OS. Check out the following it is an example to forward RDP traffic to the Server in the KVM but you will need to change the network type . dracocybersecurity.com/configure-iptables-port-forwarding-to-nested-guest-vm-in-kvm-default-nat-virtual-bridge-ubuntu-20-04/

  • @aliakbarakbari3802
    @aliakbarakbari3802 9 หลายเดือนก่อน

    Good work!!!!

  • @aliakbarakbari3802
    @aliakbarakbari3802 9 หลายเดือนก่อน

    Great work!!!!!!

  • @Tom1st
    @Tom1st 10 หลายเดือนก่อน

    i don't have FMD options, may i miss something

    • @dracocybersecurity
      @dracocybersecurity 9 หลายเดือนก่อน

      You might want open a tac case with Cisco. I have seen newer CDO instances that do not have that options.

  • @Tom1st
    @Tom1st 10 หลายเดือนก่อน

    What is different between FTD and FDM onboard

    • @dracocybersecurity
      @dracocybersecurity 10 หลายเดือนก่อน

      FTD Firewall Threat Defense is the software that runs on the Firewall and FDM Firewall Device Management is the management Software for managing a single device that runs on the firewall. if you onboard using FDM it has less feature and capabilities.

  • @aliakbarakbari3802
    @aliakbarakbari3802 10 หลายเดือนก่อน

    Great work!!!!! Many thanks

  • @aalien7293
    @aalien7293 ปีที่แล้ว

    Very helpful and informativw

  • @jblyon2
    @jblyon2 ปีที่แล้ว

    Just a fair warning, DO NOT attempt to use Duo's Linux documentation for Ubuntu. You WILL end up with a BRICKED system. Duo has been utterly useless when attempting to obtain accurate documentation.

    • @dracocybersecurity
      @dracocybersecurity 10 หลายเดือนก่อน

      Always important to test out the capabilities in a test or staging environment or get professional service before implementing in critical system

  • @jaymarcotte494
    @jaymarcotte494 ปีที่แล้ว

    Great video this helped me setup the environment for basic traffic, my question is how do you configure the Environment to have ALL traffic passthrough the Meraki? Inbound and outbound. I would like the Meraki to manage inbound firewall filtering if possible. Or is this Meraki only for VPN management?

    • @dracocybersecurity
      @dracocybersecurity ปีที่แล้ว

      Thanks, Meraki vMX in the cloud only function as a One-Arm VPN Concentrator. If you need VPN and Firewall capabilities in AWS. You can check out the Cisco Firewall that is available in the Cloud Market place. For your on-prem Meraki MX it is both a firewall as well as a VPN Server.

  • @ankitmagan
    @ankitmagan ปีที่แล้ว

    Great Video!! One question here. Would we be able to configure /16 (10.111.0.0/16) as the local subnet on the vMX instead of 10.111.10/24? This is because you would want your entire AWS network reachable from the remote sites.

    • @dracocybersecurity
      @dracocybersecurity ปีที่แล้ว

      It is possible to expand the subnet to /16. You do have to determine how the existing AWS routing works as well. But if it is simple inclusion on the subnet in a single LAN then it should be fine.

    • @ankitmagan
      @ankitmagan ปีที่แล้ว

      Will really appreciate if you can make a video spinning two virtual MX in AWS depicting High Availability

  • @movingpictures2378
    @movingpictures2378 ปีที่แล้ว

    This is a great video. Thank you very much!!!!

  • @germanglopez
    @germanglopez ปีที่แล้ว

    Thank you for your detailed presentation. Issue I am having is SSH from AWS SSH server cannot connect to SSH server at client side via VPN. It times out.

    • @dracocybersecurity
      @dracocybersecurity ปีที่แล้ว

      For a start I will check if the SSH Server is routing the traffic through the VPN Tunnel.

  • @mcorona09
    @mcorona09 ปีที่แล้ว

    Very helpful video! Helped me when i got stuck in a rut. Appreciate your work!

  • @archersterling4044
    @archersterling4044 ปีที่แล้ว

    Can I make windows server have a public ip? that is reachable over internet?

    • @dracocybersecurity
      @dracocybersecurity ปีที่แล้ว

      Yes it is possible. you just need to know that it exposes your window server directly to the internet which is not advisable. For testing you can get additional public ip address from the service provider and assign the public ip address to the windows server. In my test environment I use the bridge function to bridge the public ip to my device that I want to assign the public ip. which is usually the firewall, but u can do it for Windows or Linux as well.

  • @alphannguyen9387
    @alphannguyen9387 ปีที่แล้ว

    I successfully installed win2022 on KVM, the machine works well. Could you share how to configure the network between ubuntu and the virtual machine? I used CyberPanel on Ubuntu for hosting sites The KVM used the same IP address. But I can't set-up the IIS to recognize that public IP. It always connects to Cyberpanel first. How could I run websites on IIS? Do I need another public IP? Thanks

    • @dracocybersecurity
      @dracocybersecurity ปีที่แล้ว

      For exposing your IIS to the public internet having a public IP address to bridge to IIS server might be the easiest way to do it or you can use iptables to do port forwarding. however you will need to understand how the various bridge function or DNAT and maybe SNAT depending on your setup to expose the web service. I have not done cyberpanel or even cockpit configuration. I usually do it through the command line for iptables configuration and virt-manager for bridge config.

  • @mopikozz
    @mopikozz ปีที่แล้ว

    Thanks for the Guide! Detailed & precise Any idea if it works by not using AutoVPN but standard non-meraki ipsec across to AWS? Reason being, both our branch Mx and vMx belongs to diff organization account...can't do autoVPN

    • @dracocybersecurity
      @dracocybersecurity ปีที่แล้ว

      It should work with the standard IPSec config. as long as the crypto and protocol is supported have not done with AWS but did a standard IPsec with oracle cloud before. the tricky part is getting the protocol to match and then the routing. let us know if u manage to get it working with AWS.

    • @trininox
      @trininox ปีที่แล้ว

      You may want to get an Elastic IP to use with the vMX for its Public IP so it doesn't ever change and break your IPsec tunnel.

    • @davidtq8723
      @davidtq8723 ปีที่แล้ว

      It's not going to work for what you need. IPSEC tunnels on regular site to site can only recognize and pass traffic for one subnet to AWS from Meraki. I think this has something to do w/Meraki being policy based instead of route based site to site. You'd be much better off merging sites into the same org. Contact support for help.

  • @mikeurbizo4210
    @mikeurbizo4210 ปีที่แล้ว

    This is a very special use case, and actually one that I am now needing. How do I expose the ports to the windows ADD that is running inside an Ubuntu KVM? I have tried Socat and this didn't work, the public address on the Linux machine is working fine, I have a QOS to the Ubuntu server, but cannot get the Windows machine inside to be reached from the outside. Any help will be greatly appreciated.

    • @dracocybersecurity
      @dracocybersecurity ปีที่แล้ว

      For my lab environment I use iptables. using dnat to forward port 3389 to the internal windows ip address. there are a few configurations you need to do if you know iptables then it is easy. be mindful of opening up RDP directly to the internet as it opens up the server to direct attacks.

    • @dracocybersecurity
      @dracocybersecurity ปีที่แล้ว

      You can also check out my post on what the 2 rules might look like. dracocybersecurity.com/how-to-configure-iptables-to-port-forward-rdp-3389-to-windows-machine-in-kvm/ I use the -I XXXX 1 to insert the rule in front to the top of the nat table, but can you just use -A add depending on our config. Do not the rules in IPTABLES are executed top down.

  • @tracyngu6698
    @tracyngu6698 ปีที่แล้ว

    Do you think it’s possible to create a webpart like highlighted content but code it to play videos inline and also be able to like, add hashtags and comment on videos directly?

    • @dracocybersecurity
      @dracocybersecurity ปีที่แล้ว

      You will probably need to use the video webpart for inline video. support.microsoft.com/en-us/office/using-videos-on-sharepoint-pages-5a0eb37c-81a8-45b7-875e-ff0515dd2e5f You can also check out microsoft stream or do some custom development for adding hashtags and comments. Have not seen out of the box capabilities for hashtags and comments for inline video.

  • @aleeessio
    @aleeessio ปีที่แล้ว

    7:36 How is it possible? You have opened only port 22

    • @dracocybersecurity
      @dracocybersecurity ปีที่แล้ว

      This is leveraging on ssh protocol (port 22) to tunnel the rest of the traffic across. It is actually a very old school way of creating a tunnel for traffic that you do not want to open additional ports. These days vpn tunnels are the more common use as it is easier to manage for mutliple clients or site to site tunnels.

  • @kofi-tawiahagyeman
    @kofi-tawiahagyeman ปีที่แล้ว

    Hello Geek, Can you be my mentor?

    • @dracocybersecurity
      @dracocybersecurity ปีที่แล้ว

      Thanks for the confidence, but I have not been doing any advance stuffs with Sharepoint :)

  • @alexazizi3642
    @alexazizi3642 ปีที่แล้ว

    im receiving this message after log in " oh,no something went wrong ! " what can i do with this ?

    • @dracocybersecurity
      @dracocybersecurity ปีที่แล้ว

      You can check these out to see if it is the issue that you are facing. lists.debian.org/debian-backports/) you can download xrdp 0.9.15-1 and xorgxrdp 1:0.2.15-1 via snapshot.debian.org/ Those package versions were still compatible with libc6 from bullseye. sudo apt install ./xorgxrdp_0.2.15-1_amd64.deb sudo apt install ./xrdp_0.9.15-1_amd64.deb

  • @alexkeen6840
    @alexkeen6840 ปีที่แล้ว

    Total lifesaver - thank you!!

  • @no-hope-in-the-pope
    @no-hope-in-the-pope ปีที่แล้ว

    Thanks! this video solved my issue...I was installing on ubuntu 20.04 and the missing /lib/security folder was missing along with setting up a user in Duo! I feel dumb...Thanks again!

    • @dracocybersecurity
      @dracocybersecurity ปีที่แล้ว

      Glad it helps. And these things happens all the time :)

  • @HustleBigNetwork
    @HustleBigNetwork ปีที่แล้ว

    I get a black screen with just a cursor? how do I fix it?

    • @dracocybersecurity
      @dracocybersecurity ปีที่แล้ว

      There are multiple reason that you are getting just a cursor. The 2 common problem might be the Graphical Desktop Environment that you installed might be causing the problem. or could be a permission issue preventing the GDE from loading properly. You might want to take a look at the xrdp logs to see if there is anything mentioned there. github.com/neutrinolabs/xrdp/issues/2064. You can check out this post to see if it solves your problem.

  • @lqyj
    @lqyj ปีที่แล้ว

    Can use in remote desktop connection?

    • @dracocybersecurity
      @dracocybersecurity ปีที่แล้ว

      Yes it can support RDP, just need to make sure that the firewall allows that. For my lab setup I utilized this windows server as a AD and only allow RDP through local vpn.

  • @iainhmunro
    @iainhmunro ปีที่แล้ว

    Thanks for the video - was looking for the second and subsequent videos in this series, but couldn't find any.

    • @dracocybersecurity
      @dracocybersecurity ปีที่แล้ว

      I haven't had time to do the second video for this yet. Stay tune for more

  • @weewam2530
    @weewam2530 2 ปีที่แล้ว

    Explained in great detail! Thank you so much!!

  • @masterminder05
    @masterminder05 2 ปีที่แล้ว

    Hi Draco , Thank you so much for this Great!!! tutorial, Had a question - 1) if i have to upgrade from Azure vmx-100 to vmx-M, do i have to re-deploy vmx-M on Azure again even though my license has 1 more month left to expire, can i just not transfer the license from vmx-100 to vmx-M ? and 2) we have multiple Site-to-Site locations , can i redploy vmx-M with peering 1 site at a time or do i have to deploy all the multiple Sites in one time all in one day? The reason im asking is because our cutomer is only OFF on Sundays and they work 18 hours daily :)

    • @dracocybersecurity
      @dracocybersecurity 2 ปีที่แล้ว

      community.meraki.com/t5/Security-SD-WAN/Azure-vMX100-transition-to-vMX-M/m-p/109509 you can check out this link seems that you have to recreate a vMX-M instance if you are on vMX 100. I would recommend to get in touch with your local Meraki team or raise a case to discuss your need.

    • @masterminder05
      @masterminder05 2 ปีที่แล้ว

      @@dracocybersecurity Thank you so much!

  • @eschete5
    @eschete5 2 ปีที่แล้ว

    Thanks for making this video. Any guidance on setting up the virtual network ? I can ping the vmx from my local network. I am having issues after I create a virtual machine and having that see the VMX and also my local network

    • @dracocybersecurity
      @dracocybersecurity 2 ปีที่แล้ว

      Did you create the Virtual Machine in the existing subnet that you have configured during the provisioning? If you have follow closely from 14min to 23min of the video it will work. However any deviation from the standard steps then you will need to tweak the routing and route table of Azure this becomes complex for me as I am not an expert in Azure Networking, unlike Linux/AWS the Azure Routing is not easy to troubleshoot. I had issue during the video creation when I create the Subnet after the vMX creation and also creating the Virtual Machines in another subnet. I am assuming that if you are doing ping you have allowed ping on the Windows virtual machine and if you have not done any changes to the RDP of your Windows VM you have tried to RDP from your local network machine to the Windows Virtual Machine and the basic interesting traffic are not in conflict. Do let me know if you manage to get it to work :) with the basic steps. If you let me know without sharing sensitive information on how your setup looks like I can try to see if I can check out in my setup what you can do to get it to work. Or talk to your local Meraki expert. Do note that in my view Meraki is really great for its simplicity and scalability but any complex setup you will need to do your feasibility assessment base on your needs.

    • @eschete5
      @eschete5 2 ปีที่แล้ว

      @@dracocybersecurity After configuring for a week now. I finally figured it out with your comment above. The drop down menu had cached old Virtual Networks and the new ones that I had created were not showing up. I opened a different browser and in the drop down my new virtual network with the correct subnet showed up. Everything works correctly. Thanks for the video. Only recomendation would be to setup a new virtual network in the video and show how it was done if anyone is new to working in azure

    • @dracocybersecurity
      @dracocybersecurity 2 ปีที่แล้ว

      Great that you manage to get it to work. cache on the browsers have their way of tripping us :). thanks for the feedback on showing the creating the new virtual network. That can be daunting for people new to Azure. I am still learning subnetting and the network gateway in Azure as well. wish that there is more consistency in network deployment in the cloud providers :) I am starting to like the simplicity of Oracle Cloud in their way of networking not much advance stuffs but the basic routing and VPN are a lot easier. wondering when vMX will be extended to them. when I get time I will do a video on vMX in AWS. that is a lot easier since more Linux style VPS. if you have a chance try out the whole setup for vMX on Azure and AWS and a few locations of hardware boxes. It is amazing for simple development need and management. but cost can be a concern for testing.

    • @eschete5
      @eschete5 2 ปีที่แล้ว

      @@dracocybersecurity thanks for your help and making the video. I will check out AWS

    • @majorblazer9055
      @majorblazer9055 2 ปีที่แล้ว

      @@dracocybersecurity Hey mate waiting for video for AWS Vmx, I need to deploy this for work.

  • @tricormetals8199
    @tricormetals8199 2 ปีที่แล้ว

    Great Video. It answered a few questions I had about this project.

  • @anthonypark9158
    @anthonypark9158 2 ปีที่แล้ว

    Hi this is really helpful for use case at work. This is pretty uncommon setup so I never thought I would find a video on this. Thank you very much!!

  • @karmanyadadhich1043
    @karmanyadadhich1043 2 ปีที่แล้ว

    thanks, it helped!

  • @Jon_Again
    @Jon_Again 2 ปีที่แล้ว

    Thanks for the walkthrough, worked perfectly.

  • @jamesjoyce7020
    @jamesjoyce7020 2 ปีที่แล้ว

    Not sure what I did wrong, but I configured the DUO client to my RADIUS server. The connectivity tool in DUO says “There are no configuration problems” the MX device is configure successfully to the RADIUS server, however when I connect to the VPN I am able to successfully connect without 2FA? Any ideas where to look?

    • @dracocybersecurity
      @dracocybersecurity 2 ปีที่แล้ว

      Hard to say but did you configure the Duo Authentication Proxy, to proxy the authentication? Seems that your vpn client is authenticating directly to the Radius instead of through the Duo Authentication proxy. The DAP configuration should be similar to how it is configure in this video, but do check what are the parameters that you need to change.

    • @graciesager
      @graciesager ปีที่แล้ว

      Have you figured this out James? I am having the same problem. Thanks

  • @vonglorwanchue8969
    @vonglorwanchue8969 2 ปีที่แล้ว

    can you download Firepower NGFW ovf file to google driver sir ? because i can't download

    • @dracocybersecurity
      @dracocybersecurity 2 ปีที่แล้ว

      You need to have a valid Cisco Partner or Customer account to download the ovf. Do reach out to your country authorized distributor or partner to request for that.

  • @johndorian4078
    @johndorian4078 2 ปีที่แล้ว

    Are there any other options for MFA for meraki that you've used.

    • @dracocybersecurity
      @dracocybersecurity 2 ปีที่แล้ว

      I have not done any other integration with other MFA. But you should be able to integrate with other MFA.

  • @soorajpmenon9835
    @soorajpmenon9835 2 ปีที่แล้ว

    Appreciate this video! Waiting for your next one.

  • @michaelpietrzak2067
    @michaelpietrzak2067 2 ปีที่แล้ว

    Great video! Very well done!!

  • @skyw3lker113
    @skyw3lker113 2 ปีที่แล้ว

    where are the remaining parts !!

    • @dracocybersecurity
      @dracocybersecurity 2 ปีที่แล้ว

      Below are the balance 2 parts. These are basic videos to help those interested get started th-cam.com/video/f2T8ZhYyIco/w-d-xo.html Part 2/3 th-cam.com/video/RvtIhRX4Fv0/w-d-xo.html Part 3/3

  • @mdabdulmoiz
    @mdabdulmoiz 3 ปีที่แล้ว

    sorry i am new to DUO and Meraki, i have understood your configuration but one thing I want to know is when you finally tested user for Client VPN how that push notification was sent to you? do we need to configure and link the AD user we are testing from under DUO portal so that notification is sent to us?

    • @dracocybersecurity
      @dracocybersecurity 3 ปีที่แล้ว

      Check out this link. duo.com/docs/meraki-radius Duo they have a integration diagram that explain the flow much better than I do. What i have done is the older L2TP client. They now have the integration with AnyConnect. Which in my view is more secure. Of course L2TP is free with the system. AnyConnect I believe you need to pay for the license. Talk to your local Partner / Disti to get more support on the detail if you are interested in AnyConnect integration

  • @mdabdulmoiz
    @mdabdulmoiz 3 ปีที่แล้ว

    can we have the vpn user use meraki cloud authentication (with local username pass created ) and then use the DUO? instead of AD credentials?

    • @dracocybersecurity
      @dracocybersecurity 3 ปีที่แล้ว

      From what I understand currently Duo is not integrated with the cloud authentication. You would need a Radius/AD/LDAP.

  • @visualmodo
    @visualmodo 3 ปีที่แล้ว

    Hotel WordPress Theme is the best hotel, hostel, resort, apartment presentation WordPress theme. With its beautiful design and high coding quality, this theme can showcase your unique accommodations to the world and attract more visitors to your website visualmodo.com/theme/hotel-wordpress-theme/ 🏨🛎️🛌⛵️🏖️

  • @pankaj8878
    @pankaj8878 3 ปีที่แล้ว

    Awesome Video... thank you.. one question though -- do we need to install RADIUS server in AD?

    • @dracocybersecurity
      @dracocybersecurity 3 ปีที่แล้ว

      In this particular setup, you don't need to install a separate radius server, the Duo Authentication Proxy will facilitate as a Radius Server. You can check out the official document that explain more on this. duo.com/docs/radius

    • @graciesager
      @graciesager ปีที่แล้ว

      @@dracocybersecurity Great video. Follow up question related to the question from the OP, since we're currently using meraki cloud authentication, once I have the proxy authentication server setup on the AD server, I could then change the authentication in Meraki to RADIUS using the proxy server's address? Thanks

    • @dracocybersecurity
      @dracocybersecurity ปีที่แล้ว

      Yes you should be able to do that. Just make sure the necessary firewall ports are open and the routing are done properly. I presume that the AD is internal so you need to take note of those nuances.

    • @graciesager
      @graciesager ปีที่แล้ว

      @@dracocybersecurity Thanks for your reply Draco. Unfortunately after following your video to the teeth, as soon as I connect my vpn and asked for my sign in, it just spins then receiving an error that "the remote connection was terminated because the remote computer did not respond in a timely matter" I already set timeout from 60 to 120 secs. It seems that it's not hitting the radius server at all. Any ideas? Thanks again

    • @wernerscholtz4048
      @wernerscholtz4048 9 หลายเดือนก่อน

      same problem here. everything tests fine but as soon as i hit connect on the vpn client, it gives the above error.@@graciesager