Thursday, 27 August 2020

AZ-500T00. Microsoft Azure Security Technologies

Microsoft Azure is a cloud platform on which you can deploy infrastructure solutions, databases, applications, services, and functions. It runs the well-known office cloud applications Office 365 and Microsoft 365. Here you can also store and process large amounts of data, use ready-made platform services in order to add additional functionality to custom applications. More than 260 services are running on Microsoft Azure . For convenience, they are divided into 22 areas, including DevOps, analytics, databases, security, blockchain, hybrid environments, artificial intelligence and machine learning, integration, IoT, mobile applications, multimedia, augmented reality, development tools and several others enterprise architect vs solutions architect.

Microsoft pays great attention to information security issues. The company annually invests $ 1 billion in this area. More than 3,000 security professionals work here to ensure data protection and user privacy. Microsoft considers Azure to be the most secure cloud in the world and can demonstrate more certifications to prove the platform's security than any other similar system. We add that Microsoft Azure also complies with the requirements of the European General Data Protection Regulation (GDPR).

The Microsoft Azure platform was built on the "security in mind" principle. All platform services have built-in protection and threat detection tools. Specialized tools have been developed such as the Azure Security Center. The cloud can protect identities, networks, data and other secrets from the most common types of attacks such as DDoS, spoofing, or cross-scripting. It should also be noted that the "human factor" remains the main threat to information security. Microsoft Azure and other cloud platforms declare a “shared responsibility model”. This means that the cloud provider is only responsible for the “low-level” security of the virtual infrastructure and the physical security of the data center. Customers and users are responsible for the security of networks, operating systems, applications, data.

Secure cloud storage of data, including “big data”, has a high level of functionality and scalability. Data protection from unauthorized access and loss is ensured through encryption and replication, while providing the ability to use your own secret keys. Especially sensitive data, passwords, keys, connection strings, and certificates can be stored using Azure Key Vaults.

When working with any cloud service, it is important to remember that invulnerable systems do not exist, especially if they were manually deployed. Microsoft Azure provides the highest level of information security in the industry, but this platform will not be able to protect completely from the problems associated with the "human factor". Most problems in technical systems are caused by humans. Therefore, the best way to ensure the stability and security of cloud services is to install and configure them automatically. Therefore, in Microsoft Azure, everything is automated to the maximum, it provides the opportunity to use managed services or Azure Resource Manager templates. There is no need to manually deploy and configure components, the platform can handle this easily and safely.

For security administrators and information security professionals, there are many features and conveniences. These include Azure AD functionality, a security center, VPN gateway builders, specialized DDoS protection, Azure Information Protection, Key Vault, and an Azure security analytics tool. Sentinel.

Microsoft Azure is a cloud platform. For her, both landline and mobile users are remote. This means that working with them is associated with increased risks. For account management, Microsoft Azure offers a range of services under the general name Azure AD. This one-stop identity management and security platform controls over 1.2 billion identities, performs over 8 billion daily authentications, and protects users from 99.9% of cyber attacks. For account security, Azure AD provides many tools, such as multi-factor authentication, Azure AD Identity Protection with automatic risk and threat analysis and detection.

For hybrid IT infrastructures that combine on-premises and cloud computing, we recommend using the fast private Azure Express Route. This will make it possible to transmit any, even encrypted corporate traffic exclusively through a separate private channel, and not the public Internet.

It is believed that IT and agriculture are the drivers of the Ukrainian economy. It is known that companies operating in these particular industries actively use Microsoft Azure in the IT infrastructure of their enterprises. If for IT companies this fact seems natural, then for large agricultural enterprises it is most likely indicative, demonstrating the advantages of clouds in practice.

Cloud services, including those based on Microsoft Azure, have become a daily routine for Internet users. Applications only for personal computers are becoming less popular, since now we spend 90% of our time at a computer in browsers. In the future, there will be no need for applications for computers at all; Internet access to applications deployed on a cloud architecture will suffice. An important point, in this case, the issues of information and network security become especially relevant.

Tuesday, 25 August 2020

Summer 10% discount on courses at the training center "Network Technologies"

We spend the summer with benefit in the training center "Network Technologies"! We give a 10% discount on IT courses and business trainings for everyone who does not want to waste time in vain. Study IT all summer long at competitive prices aws solutions architect salary.

If you have been postponing training all the time, a new attractive price is a wonderful reason to improve your skills and gain relevant knowledge.

The discount will be valid from June 01 to August 31, 2020.

Send your applications for training today!

Didn't find the course you're interested in? Write to us and we will find the right course or develop an individual training program, taking into account the needs and budget of your company.

Monday, 24 August 2020

15% Off VMware vSphere Course

TC "Network Technologies" invites you to the NT-VMware vSphere course "Deployment and management of VMware vSphere infrastructure" and provide a 15% discount to all students. Hurry up to take the opportunity are architects in demand!

Start date of the course: 08/10/2020.

The course will cover the most pressing issues:

Introduction to Virtualization and Cloud Technologies

ESXi hypervisor installation and basic configuration

Creating a virtual machine

Installing vCenter with vCenter Server Appliance (VCSA)

Hierarchy of vCenter infrastructure objects. Rights and roles

VCenter Server Maintenance

Configuring and managing virtual networks

Configuring and managing virtual storage

Virtual machine management

Backing up and restoring virtual machines

Resource allocation management

Increased Availability with vSphere HA and vSphere Fault Tolerance

vSphere Distributed Resource Scheduler (DRS)

vSphere Update Manager (VUM)

AutoDeploy

Troubleshooting Overview

The course will be useful for system administrators and engineers who have experience with Windows or Linux operating systems.

Saturday, 22 August 2020

Why a public cloud is safer than private ones

You think that a public cloud is inherently dangerous, and that the only way to achieve that level of security in the cloud, meets the rigorous requirements of your organization, is to implement your own private cloud. Do you think this is the correct statement? Unfortunately, there is very little rational about this.

In fact, serious software and hardware vendors are largely responsible for the newspaper duck "The public cloud is dangerous!" - spreading fear, uncertainty and doubt (FUD) in the market. For the creation of private clouds is the purchase of many devices and applications. The last thing vendors want is for their customers to move to the public cloud, if they are real vendors. Don't be fooled.

Public clouds are generally more secure than private clouds for a number of reasons. And that's why.

Why public clouds are more secure: support skills

Public clouds are more "hardened" against hacking - hackers know where to find the most "tasty" things - of course, inside the public cloud, where the information of many clients is stored. If they could break through the "defenses" of the public cloud, they would get a lot. Therefore, the incredible number of hacker attempts such large cloud services as Amazon Web Services, Microsoft Azure and others have been tempered for many years.

Attracting the best security experts - Public cloud providers attract not only hackers, but also talent. If you are a top cloud security expert, where would you like to work: Amazon? Insurance Company? Which manufacturer or government agency? All clear. :)

The use of modern and the latest developments in security - public cloud providers are constantly building new cloud data centers, purchasing equipment and modern software, very quickly pays off due to scale. You do not need to know how their principle is implemented "to the fullest" and "incredibly fast". New developments. In full. Incredibly fast.

Why private clouds are less secure:

Complaints - It's amazing how many businesses think their DMZ

DMZ (demilitarized zone, DMZ) is a technology for ensuring the protection of the information perimeter, along which servers responding to requests from an external network are located in a special network segment (called a DMZ) and are restricted in access to the main network segments using a firewall (firewall , in order to minimize damage when hacking one of the publicly available services that are located in the DMZ (from Wikipedia)

and firewalls (firewalls) can give them proper security. If we are talking about an internal, local network, it probably provides security. Is everything controlled on the Internet? What about email? Not to mention viruses. And what about twenty times the employees uploading malware to the corporate network via phones? Nowadays, the enterprise wants a private cloud, believing that everything they used for the internal network will be crammed into their cloud and have security. Character to them in this!

Implicit Competence of Employees - Of course, your organization has many security people. They all know their stuff. Try this: Throw a big party for them. Look around for two hours. See who is this guy with the lampshade on his head? Ah, he is responsible for the security of your private cloud. :)

Not enough penetration tests - how do you validate to make sure the private cloud or any other part of the IT infrastructure is secure? Very simple: your testers run a series of security tests. Are you hiring a third party to run them for you? If all tests pass, you are safe, right? Perhaps for a few minutes until hackers apply new attacks and hit your security tests. Oops.

Outdated devices / apps in use - you've spent hundreds of thousands of dollars on hardware security. In 2009. You are now in a private cloud. Try this: Ask the SPI for hundreds of thousands of dollars to replace these three year old devices. Answer? Maybe next year. Try updating your patches. Perhaps you will succeed. But don't hesitate to compare your achievements with those shiny things that are collected and updated in public clouds every day.

This article is by ZapThink, a consulting, training and leadership company providing service-oriented architecture and cloud computing for private and public enterprises.

Friday, 21 August 2020

Virtual router: what it is and why you need it

What is it service desk analyst job description

A virtual router (or virtual router) is a small virtual machine with special software. Its purpose is to route between a virtual private network (VPN) and the Internet. Actually, the operation of this VPN connection is provided by the virtual router.

We provide such a virtual machine to customers free of charge and manage it ourselves.

What is a virtual router for?

To begin with, let's consider in what ways you can connect a virtual server to the Internet:

1. The virtual server is connected directly to the Internet. In this case, directly on the virtual server itself, the network interface will have an IP address that is accessible from anywhere on the Internet. Usually these are addresses from such blocks:

193.151.89.0/24 (in Germany);

193.151.90.0/24 (in Germany);

193.151.91.0/24 (in Germany);

195.3.204.0/25 (in Ukraine);

195.3.206.64/26 (in Ukraine);

195.3.206.240/28 (in Ukraine).

In some cases, other IP addresses may be used. Note that this list is current at the time of publication of the article, however, it can and will change.

What features does this type of connection have? In this case, we do not filter traffic between the client's server and other machines on the Internet. The client regulates all access policies at the operating system level.

2. The virtual server is not connected directly to the Internet, but to a separate virtual private network that belongs to this client. These networks often have addresses from ranges that are provided in RFC1918:

10.0.0.0/8;

172.16.0.0/12;

192.168.0.0/16.

This list is also subject to change.

Thus, the server receives an address from this network to the interface, and it is the virtual router that provides routing between the private network and the Internet. Note that this only happens when the client wishes this routing to occur, since it is possible to create a private network without access to the Internet.

The advantage of this method is that the VPN allows you to set up a secure and more reliable connection to the virtual server.

How to set up the ability to connect from the Internet to a server on a private network

When connecting through a virtual router, client servers can connect to the Internet (although this can be disabled). But in order to configure the ability to connect from the Internet to a server that is located on a private network, you should already register policies for forwarding incoming connections. This can be done with our help or on your own. How to perform this procedure with our own hands, we told in a separate article . 

In this case, the network services that the client wants to make available will currently be available at one of the addresses from such blocks (although sometimes there may be others):

193.151.88.0/24 (in Germany);

195.3.205.0/24 (in Ukraine);

195.3.207.0/26 (in Ukraine).

When else come in handy for a virtual router and VPN

A virtual router and VPN will also be useful if the client needs to build secure VPN connections with remote sites or mobile users. We have already shared visual instructions on how to set up a site-to-site VPN in the cloud and a client-to-site VPN in the cloud . But you can read in detail about what happens to packets during connections inside the VPN tunnel between the user's office and the environment in the cloud, as well as when connecting outside the VPN tunnel, here .

Thursday, 20 August 2020

Virtual versus physical servers: what the experts recommend

Almost every company has a choice between virtual and physical servers. The decision is usually influenced by several factors, including: Tech support engineer job description

personal experience in the past;

advice from colleagues or acquaintances;

user reviews on the Internet and more.

How can you make a smart choice? Our experts, renowned specialists in the IT industry - Spartak Polishchuk , founder of Rubicon , and Roman Gershtun , founder of ProCRM , share their opinions, which were formed on the basis of personal experience and the experience of their clients.

Despite the fact that more and more companies are moving to the cloud, some business owners are still convinced that only the presence of iron in the office guarantees them peace and security for data.

Roman Gershtun also notes this : there is one point that clients often talk about - this is the desire to have their own server and manage it, in a word, to have a certain ownership right. But in fact, if you have your own server, you need to invest in it and constantly look after it. That is why a physical server works well only if the company has its own IT department and the ability to administer these servers, maintain their operability and timely upgrade. Therefore, if you do not have your own IT staff, it is best not to set up physical servers in your office.

Spartak Polishchuk noted that in the IT field, prejudices, in the literal sense of the word, do not exist. Most likely, they can be called fears. For example, fear of the security of their personal data, coupled with a lack of fundamental knowledge of the cloud, can lead customers to use physical servers.

Roman Gershtun

In addition to possible biases, there are still many myths surrounding virtual servers. For example, that clouds are expensive or dangerous. But how is everything really?

Roman Gershtun notes that there are usually three such myths. The first is cost, the second is security, and finally privacy. “Let's consider each of them. For example, that clouds are expensive. What is expensive? When you invest in a physical server, you pay the cost, the work of the system administrator. Then spend money on upgrades and technical support for that server. And with clouds, all these services are already included in the cost of services, ”says our partner.

The second point, as Roman Gershtun notes, is safety: “Let's simulate two situations. Fire in the office or "visit" of intruders. If the server is located in your office, its level of security is significantly inferior to virtual servers. "

And the third point is confidentiality. According to the expert, if even the American Pentagon can be broken, then it is easy to guess which server is more secure: a server of a specialized organization providing cloud solutions, or a server run by a system administrator who may not even have sufficient qualifications to ensure the proper protection level.

Roman Gershtun also expresses the opinion that one should not be afraid that information may be lost on a certain server, but that the data may disappear. This is a much bigger loss than just copying data to another resource. Of course, any cloud service has a much higher level of security than a physical server.

"Of course, any cloud service has a much higher level of security than a physical server."

Roman Gershtun

Let's say you have a choice right now. It is necessary to decide: work on an iron or cloud server? The choice is not easy, therefore, for it to be deliberate, our experts share their experience, what to look for and what characteristics to compare.

Spartak Polishchuk asserts: “With an eye to the future, I would never compare a cloud with a physical server. The fact is that if you need to scale, expanding clouds is much easier than a physical server. This can usually be done in a matter of minutes. A physical server requires significant financial and time costs. For example, one of our clients wanted to scale their server by adding RAM to it. And as a result of the transition of the whole world to new memory standards, he had to look for this RAM in the secondary market, since the motherboard did not support the modern standard. And it would be much cheaper and easier to switch to the clouds. "

Roman Gershtun draws an analogy with a car: you can buy a new one, or you can buy a used one. “When leaving the salon, a new car immediately loses value. Additionally, this vehicle will need to be upgraded. When buying a used car, you save on cost, and less money will be spent on modernization, ”the expert explains. And he says that the same difference between virtual servers and hardware. 

“When you rent a cloud, pay for only the resources you need. Moreover, they can be easily increased. If necessary, you can configure the creation and storage of backups in the clouds, and system snapshots are already included in the cost of services. As a result, you will get safety, reliability and cost optimization, ”notes Roman Gershtun.

Spartak Polishchuk

Of course, there are specific cases when you can consider both physical and virtual servers to work. What exactly are these cases? And what types of business should definitely be preferred over clouds?

According to Spartak Polishchuk, there is a certain law in the implementation of CRM systems that requires data to be placed on physical servers among companies in the banking and medical sector. In all other cases, it is better to use the cloud, for example, to host the boxed version of Bitrix24.

Roman Gershtun says that the main thing is the principle, not the size of the business. “A simple example: you have an IT company that provides system administration services. There is a staff of IT professionals who make up the backbone of the business. Considering a physical server is possible when you have the appropriate staff and the necessary resources for this, - our partner is convinced. "If you are a startup and do not have this opportunity, then, of course, you should give preference to the clouds." Using the clouds, you can save on the maintenance of a staff of specialists and get more profit from the sale of goods or services. “For example, you need to build a website, install a CRM system and automate it all. If you purchase your own physical server, you will need to have staff to maintain it. With clouds, you can easily increase the amount of space, without buying additional hardware and saving time. And now it is the most important investment in business. If you understand that it is more profitable for you than maintaining a state and your own server, then, undoubtedly, you should give preference to clouds, ”Roman Gershtun shares his opinion.

“With clouds, you can easily increase the amount of space without buying additional hardware and saving time. And now it is the most important investment in business "

Wednesday, 19 August 2020

TuchaFlex + VPS builder test plan. 1C in the cloud

We continue the series of publications about competent testing of Tucha services, today we will talk about the VPS TuchaFlex + constructor . The range of its capabilities is very wide: from virtualizing a small application or an entire office to creating a serious data center for solving large-scale problems. Therefore, we decided not to spray everything at once, but to consider each of the possibilities in more detail. Let's start by transferring the 1C program to the cloud - perhaps the main application of most accountants.

First of all, connect to a remote desktop, as described in our instructions . You will also need a distribution kit with an .exe file of the program. It can be downloaded from the official 1C user support website. That, in fact, is all, now you can start installing support analyst.

1. Copy the distribution kit with the .exe file to the virtual machine and run it.

2. If you are using 32-bit Windows, the first three items in the window of available components should be disabled, 1C: Enterprise Server is enabled, and the rest - as desired.

64-OS ryazryadnoy all almost the same, but the choice will be binding on the two items: Access Components 1C: Enterprise server and server 1C: Enterprise .

Click "Next" on this and the next tab.

3. In the window that opens, check the box next to Install 1C: Enterprise server as a Windows service . Select or create a user, set a password and click Next .

4. On the last tab, click Install .

Now you need to transfer the existing 1C database from the local machine to the server.

5. Open 1C on the local computer, go to the Configurator , in the Administration section, click Upload infobase and specify any folder for uploading.

6. Go to Start > Computer . You will see all available local and virtual disks. In our case, Disks C and D on DESKTOP-RM7A1B0 are local, and Disk (C :) is virtual. Copy the database from the local to the virtual disk in the same way as from a regular flash drive (Copy-Paste).

7. Open 1C in a virtual machine, go to the Configurator , in the Administration section, click Download infobase and select the folder where you copied it earlier.

Cisco Updates Certified Network Design Engineer Curriculum

Cisco has updated its CCDA® Associate Certification Preparation Program in Network Design. Updating curricula and exam requirements will ens...