Cloverleaf and Cisco Secure Workload

Clovertech Forums Cloverleaf Cloverleaf and Cisco Secure Workload

Tagged: 

  • Creator
    Topic
  • #120359
    Keith McLeod
    Participant

      Looking for the impacts of using Cisco Secure Workload on a Cloverleaf Server.  We are using Redhat Linux and Cloverleaf 19.1.1.  Any issues derived from this? Recommendations?  I did not find anything on the Concierge site in either direction on this product.  It is essentially a host based firewall.  I expect if I don’t have control access that I will need to seek another group for every ip and port change while trying to get the job done.  Also, will probably require more troubleshooting unless we have the visibility.  Anyone have any insight before I go down this path?

      • This topic was modified 1 year, 9 months ago by Keith McLeod.
    Viewing 1 reply thread
    • Author
      Replies
      • #120361
        John Mercogliano
        Participant

          Zero trust sucks when building interfaces for sure.  We just finished implemented this just two weeks ago.  They have two modes.  Catch and allow, then catch and deny.  We kept it in catch and allow till we discovered all ports we used, then they switched to catch and deny.  We are running on Azure RedHat and cloverleaf 20.1.

          You are right, you will need to request every new port to be allowed when building new interfaces.  This will also affect major releases of cloverleaf.  I’m in the process of looking at 2209 release on my dev systems and it is a pain since it’s a new workflow for our lan team.

          Good luck

           

          John Mercogliano
          Sentara Healthcare
          Hampton Roads, VA

        • #120363
          John Mercogliano
          Participant

            And they do have a dashboard that they can give you access to if your team in charge will allow it.  This will let you see what ports have been blocked recently.

            John Mercogliano
            Sentara Healthcare
            Hampton Roads, VA

        Viewing 1 reply thread
        • You must be logged in to reply to this topic.