From 3ac86e5e8b3095d6f29cc1873961d948a0a3f9cb Mon Sep 17 00:00:00 2001 From: ebner Date: Thu, 24 Nov 2022 11:50:45 +0100 Subject: [PATCH] cleanup overview? --- ...infrastructure_security_concept.drawio.svg | 536 ++++++++++-------- 1 file changed, 298 insertions(+), 238 deletions(-) diff --git a/proposals/draft_infrastructure_security_concept.drawio.svg b/proposals/draft_infrastructure_security_concept.drawio.svg index 4051f65f..11b00ea7 100644 --- a/proposals/draft_infrastructure_security_concept.drawio.svg +++ b/proposals/draft_infrastructure_security_concept.drawio.svg @@ -1,14 +1,16 @@ - + - + + + - - + + -
+
https/443 @@ -18,7 +20,7 @@
- + https/443... @@ -80,12 +82,12 @@ - - + + -
+
https/443 @@ -93,7 +95,7 @@
- + https/443 @@ -117,12 +119,12 @@ - - + + -
+
tftp @@ -134,7 +136,7 @@
- + tftp... @@ -144,7 +146,7 @@ -
+
443 @@ -177,7 +179,7 @@ - + @@ -199,7 +201,7 @@ - + @@ -220,7 +222,7 @@ - + @@ -259,12 +261,12 @@ - + -
+
5665 @@ -272,7 +274,7 @@
- + 5665 @@ -294,12 +296,12 @@ - - + + -
+
???? @@ -307,7 +309,7 @@
- + ???? @@ -329,12 +331,12 @@ - - + + -
+
@@ -356,30 +358,11 @@
- + nrpe... - - - - -
-
-
- agent(s) -
-
-
-
- - agent(s) - -
-
- - @@ -421,7 +404,7 @@ -
+
https @@ -429,7 +412,7 @@
- + https @@ -486,132 +469,42 @@ - + -
-
+
+
- any supported system in +
+ + + All Networks + + +
- ANY + [Security Level 3] - zone !!!!
- - any supported system in... + + All Networks[Security L... - + - + + + -
-
-
- security level -
-
-
-
- - security l... - -
-
- - - - - - -
-
-
- https/443 -
- 8140 -
-
-
-
- - https/443... - -
-
- - - - - -
-
-
- 5665 -
-
-
-
- - 5665 - -
-
- - - - - - - -
-
-
- https/443 -
-
-
-
- - https/443 - -
-
- - - - - - -
-
-
- (specific) managed Linux machines -
-
-
-
- - (specific) managed Linux machines - -
-
- - - - - - -
+
Icinga Satellite @@ -621,43 +514,20 @@
- + Icinga Satellite... - + -
-
-
- - DMZ - -
- - DMZ responsible ? -
- - Periodic reviews -
-
-
-
- - DMZ... - -
-
- - - - -
+
- - Systems are installed in the DMZ + - Systems are installed in the DMZ?
@@ -673,23 +543,26 @@
+ - DMZ responsible? +
+ - Periodic reviews?
- - - Systems are installed in the DMZ... + + - Systems are installed in the DMZ?... - + -
+
5665 @@ -697,16 +570,16 @@
- + 5665 - + -
+
Icinga Satellites @@ -714,51 +587,16 @@
- + Icinga Satellites - - + -
-
-
- 5665 -
-
-
-
- - 5665 - -
-
- - - - -
-
-
- agent(s)/beat(s) -
-
-
-
- - agent(s)/b... - -
-
- - - - -
+
logstash @@ -766,17 +604,17 @@
- + logstash - + -
+
???? @@ -784,17 +622,17 @@
- + ???? - - + + -
+
@@ -816,11 +654,233 @@
- + nrpe... + + + + + +
+
+
+ + nrpe + +
+ + ns-client++ + +
+ + snmp + +
+ + other ports + +
+
+
+
+ + nrpe... + +
+
+ + + + + +
+
+
+ + DataCenter Network +
+ [Security level 3] +
+
+
+
+ + SSH access only through dedicated SSH gateways. + +
+
+
+
+
+ + DataCenter Network... + +
+
+ + + + +
+
+
+
+ + + All Networks + + +
+ + [Security Level 4-5] + +
+
+
+
+ + All Networks[Security L... + +
+
+ + + + + + + + + + +
+
+
+ agents +
+
+
+
+ + agents + +
+
+ + + + +
+
+
+ beats +
+
+
+
+ + beats + +
+
+ + + + +
+
+
+ beats +
+
+
+
+ + beats + +
+
+ + + + + +
+
+
+ ???? +
+
+
+
+ + ???? + +
+
+ + + + + +
+
+
+ 5665 +
+
+
+
+ + 5665 + +
+
+ + + + +
+
+
+
+ + DMZ + +
+ + [Security Level 2] + +
+
+
+
+ + DMZ[Security Level 2] + +
+
+ + + + + +
+
+
+ 5665 +
+
+
+
+ + 5665 + +
+