{"id":31395,"date":"2019-10-31T21:41:01","date_gmt":"2019-10-31T18:41:01","guid":{"rendered":"https:\/\/prohoster.info\/blog\/kak-vzyat-setevuyu-infrastrukturu-pod-svoj-kontrol-glava-tretya-setevaya-bezopasnost-chast-tretya\/"},"modified":"2019-10-31T21:41:01","modified_gmt":"2019-10-31T18:41:01","slug":"kak-vzyat-setevuyu-infrastrukturu-pod-svoj-kontrol-glava-tretya-setevaya-bezopasnost-chast-tretya","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-vzyat-setevuyu-infrastrukturu-pod-svoj-kontrol-glava-tretya-setevaya-bezopasnost-chast-tretya","title":{"rendered":"How to Take Control of Your Network Infrastructure. Chapter Three. Network Security. Part Three","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><i>This article is the fifth in the series 'How to Take Control of Your Network Infrastructure.' You can find the contents of all articles in the series and links here <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/447008\/\">here<\/a><\/noindex><\/i>.<\/p>\n<p>This part will focus on Campus (Office) &amp; Remote Access VPN segments. <\/p>\n<p><img decoding=\"async\" alt=\"How to Take Control of Your Network Infrastructure. Chapter Three. Network Security. Part Three\" src=\"\/wp-content\/uploads\/2019\/04\/c20ea5e670105b5bf9b655a97b82f62f.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nIt may seem that designing an office network is simple. <\/p>\n<p>Indeed, we take L2\/L3 switches, connect them together. Next, we perform basic VLAN configuration, default gateway setup, establish simple routing, connect WiFi controllers, access points, install and configure ASA for remote access, and rejoice that everything works. Essentially, as I mentioned in one of the previous articles <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/434750\/\">articles<\/a><\/noindex> in this cycle, almost any student who has taken (and understood) two semesters of telecommunication courses can design and set up an office network, so that it 'kind of works.'<\/p>\n<p>However, the more you learn, the less simple this task seems. Personally, the subject of office network design does not seem simple at all to me, and in this article, I will try to explain why.<\/p>\n<p>In short, many factors need to be considered. Often, these factors contradict each other, and one has to seek a reasonable compromise. <br \/>\nThis uncertainty is the main difficulty. When it comes to security, we have a triangle with three corners: security, employee convenience, and solution cost. <br \/>\nAnd each time, a compromise must be sought among these three.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h2>Architecture<\/h2>\n<p>\nAs an example of architecture for these two segments, I, as in previous articles, recommend <noindex><a rel=\"nofollow\" href=\"https:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/solutions\/Enterprise\/Security\/SAFE_RG\/SAFE_rg\/chap1.html\">Cisco SAFE<\/a><\/noindex> model: <noindex><a rel=\"nofollow\" href=\"https:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/solutions\/Enterprise\/Security\/SAFE_RG\/SAFE_rg\/chap5.html#wpxref51616\">Enterprise Campus<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/solutions\/Enterprise\/Security\/SAFE_RG\/SAFE_rg\/chap6.html#wpxref74611\">Enterprise Internet Edge<\/a><\/noindex>.<\/p>\n<p>These are somewhat outdated documents. I mention them here because the fundamental schemes and approaches haven't changed, but I prefer this exposition over that in <noindex><a rel=\"nofollow\" href=\"https:\/\/www.cisco.com\/c\/en\/us\/solutions\/enterprise\/design-zone-security\/landing_safe.html#~tab-architecture\">the new documentation<\/a><\/noindex>.<\/p>\n<p>Without urging you to specifically use Cisco solutions, I still believe it\u2019s helpful to closely examine this design. <\/p>\n<p>This article, as usual, does not claim to be exhaustive, but is rather a supplement to this information. <\/p>\n<p>At the end of the article, we will analyze the Cisco SAFE design for the office in light of the concepts presented here.<\/p>\n<h2>General Principles<\/h2>\n<p>\nThe design of the office network must naturally meet the general requirements discussed <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/434750\/\">here<\/a><\/noindex> in the chapter 'Quality Design Evaluation Criteria'. Aside from price and security, which we intend to discuss in this article, there are still three criteria that we must consider when designing (or making changes):<\/p>\n<ul>\n<li>scalability<\/li>\n<li>manageability<\/li>\n<li>availability<\/li>\n<\/ul>\n<p>\nMuch of what has been discussed for <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/435138\/\">data centers<\/a><\/noindex> is also relevant for the office. <\/p>\n<p>However, the office segment has its own specifics, which is critical from a security standpoint. The essence of this specificity is that this segment is created to provide network services to employees (as well as partners and guests) of the company, and consequently, at the highest level of problem consideration, we have two tasks:<\/p>\n<ul>\n<li>to protect the company's resources from malicious actions that may come from employees (guests, partners) and the software they use. This also includes protection against unauthorized network access. <\/li>\n<li>to protect the systems and data of the users themselves<\/li>\n<\/ul>\n<p>\nAnd this is just one side of the problem (or rather one vertex of the triangle). On the other side is user convenience and the cost of the solutions applied.<\/p>\n<p>Let's start by examining what users expect from a modern office network. <\/p>\n<h2>Convenience<\/h2>\n<p>\nHere is how I see 'network convenience' for office users:<\/p>\n<ul>\n<li>Mobility<\/li>\n<li>The ability to use a full range of familiar devices and operating systems<\/li>\n<li>Easy access to all necessary company resources <\/li>\n<li>Availability of internet resources, including various cloud services<\/li>\n<li>Fast network performance<\/li>\n<\/ul>\n<p>\nAll of this applies to both employees and guests (or partners), and it is already the engineers' task to differentiate access for different user groups based on authorization.<\/p>\n<p>Let's take a closer look at each of these aspects.<\/p>\n<h3>Mobility<\/h3>\n<p>\nIt is about the ability to work and use all necessary company resources from anywhere in the world (of course, wherever internet access is available).<\/p>\n<p>This fully applies to the office as well. It is convenient when you can continue working from any point in the office, such as checking emails, communicating in corporate messaging, or being available for video calls. Thus, it allows you, on one hand, to address certain matters through 'live' communication (for example, participating in meetings), and on the other hand, to always be online, keep your finger on the pulse, and swiftly tackle urgent high-priority tasks. This is very convenient and indeed enhances the quality of communications.<\/p>\n<p>This is achieved through proper WiFi network design.<\/p>\n<blockquote><p><b>Note<\/b><\/p>\n<p>Here the question usually arises: is it enough to use only WiFi? Does this mean that we can forgo using Ethernet ports in the office? If we are talking only about users and not servers \u2014 which are still advisable to connect via a standard Ethernet port \u2014 then the general answer is yes, you can manage with just WiFi. But there are nuances.<\/p>\n<p>There are important user groups that require a separate approach. These are, of course, administrators. In principle, a WiFi connection is less reliable (in terms of traffic loss) and slower than a regular Ethernet port. This can be significant for administrators. Moreover, network administrators, for example, may have a dedicated Ethernet network for out-of-band connections.<\/p>\n<p>Perhaps there are other groups\/departments in your company for whom these factors are also important.<\/p>\n<p>There is another important point \u2014 telephony. You may not want to use Wireless VoIP for some reasons and prefer to use IP phones with a standard Ethernet connection. <\/p>\n<p>In general, in the companies I have worked for, there was usually the option for both WiFi access and Ethernet ports.<\/p><\/blockquote>\n<p>\nI would like mobility not to be limited to just the office.<\/p>\n<p>To enable work from home (or any other location with available internet), a VPN connection is used. Ideally, employees should not feel the difference between working from home and remote work, which implies having the same accesses. How to organize this will be discussed later in the chapter 'Unified Centralized Authentication and Authorization System.'<\/p>\n<blockquote><p><b>Note<\/b><\/p>\n<p>You are unlikely to provide the same quality of remote work services as you do in the office. Let's assume you are using a Cisco ASA 5520 as your VPN gateway. According to the data sheet, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.cisco.com\/c\/en\/us\/products\/security\/asa-5500-series-next-generation-firewalls\/data_sheet_c78-345385.html\">data sheet<\/a><\/noindex> this device can only handle 225 Mbps of VPN traffic. This means that, certainly, the VPN connection significantly differs from working in the office in terms of bandwidth. Also, if for any reason, latency, packet loss, or jitter (for example, if you want to use office IP telephony) are substantial for your network services, you will not achieve the same quality as if you were in the office. Therefore, when discussing mobility, we must keep potential limitations in mind.<\/p><\/blockquote>\n<p><\/p>\n<h3>Easy access to all company resources<\/h3>\n<p>\nThis task should be addressed together with other technical departments.<br \/>\nThe ideal situation is when a user needs to authenticate only once, and afterwards, they have access to all necessary resources.<br \/>\nProviding easy access without compromising security can significantly enhance productivity and reduce stress levels for your colleagues.<\/p>\n<blockquote><p><b>Note 1<\/b><\/p>\n<p>Convenience of access is not just about how many times you have to enter your password. For instance, if according to your security policy, you must first connect to the VPN gateway to access the data center from the office, and in doing so, you lose access to office resources, that is also very inconvenient.\n<\/p><\/blockquote>\n<blockquote><p><b>Note 2<\/b><\/p>\n<p>There are services (for example, access to network equipment) where we typically have our dedicated AAA servers, and it is normal to authenticate multiple times in this scenario.\n<\/p><\/blockquote>\n<p><\/p>\n<h3>Availability of internet resources<\/h3>\n<p>\nThe internet is not only for entertainment but also a set of services that can be quite useful for work. There are also purely psychological factors. A modern person is connected to others through many virtual threads on the internet, and I believe there is nothing wrong with them continuing to feel this connection even while working.<\/p>\n<p>From a time-wasting perspective, it is not a big deal if an employee has Skype running, and they spend 5 minutes communicating with a close person if necessary.<\/p>\n<p>Does this mean that the internet should always be accessible, and that employees can have access to all resources without any control?<\/p>\n<p>No, it doesn\u2019t mean that, of course. The level of internet openness can vary for different companies\u2014from complete closure to complete openness. We will discuss traffic control methods later in the sections dedicated to security measures. <\/p>\n<h3>The ability to use a full range of familiar devices<\/h3>\n<p>\nIt's convenient when, for example, you can continue to use all your usual communication tools at work. It's not technically complicated to implement. You just need WiFi and a guest VLAN.<\/p>\n<p>It's also good if you can use the operating system you're used to. But, in my observation, this is usually allowed only for managers, administrators, and developers. <\/p>\n<blockquote><p><b>Example<\/b><\/p>\n<p>Of course, you can take the route of prohibitions: forbid remote access, ban connections from mobile devices, limit everything to static Ethernet connections, restrict internet access, and routinely confiscate cell phones and gadgets at the entrance... Some organizations with heightened security requirements indeed go this route, and maybe in some cases it can be justified, but... let's agree that it looks like an attempt to halt progress within a given organization. Certainly, it would be nice to combine the opportunities provided by modern technologies with an adequate level of security.<\/p><\/blockquote>\n<p><\/p>\n<h3>Fast network performance<\/h3>\n<p>\nThe speed of data transmission technically consists of many factors, and the speed of your connection port is usually not the most important one. Slow application performance is not always linked to network issues, but we are currently only interested in the network aspect. The most common reason for local network 'slowdowns' is packet loss. This usually occurs due to 'bottleneck' effects or L1 (OSI) problems. Less frequently, in some designs (for example, when your subnets' default gateways are firewalls, causing all traffic to pass through them), there may be insufficient equipment performance. <\/p>\n<p>Therefore, when selecting equipment and architecture, you need to align the speeds of the endpoint ports, trunks, and equipment performance.<\/p>\n<blockquote><p><b>Example<\/b><\/p>\n<p>Suppose you are using switches with 1-gigabit ports as access layer switches. They are interconnected via Etherchannel 2 x 10 gigabits. For the default gateway, you are using a firewall with gigabit ports, for which you connect to the office's L2 network using 2 gigabit ports combined in Etherchannel. <\/p>\n<p>This architecture is quite convenient in terms of functionality, as all traffic passes through the firewall, allowing you to comfortably manage access policies and apply complex traffic control algorithms and prevention of potential attacks (more on this later); however, regarding bandwidth and performance, this design certainly has potential issues. For instance, 2 hosts downloading data (at a port speed of 1 gigabit) can completely saturate the 2-gigabit connection to the firewall, thereby leading to service degradation for the entire office segment.<\/p><\/blockquote>\n<p>\nWe have examined one vertex of the triangle; now let's look at what means we can use to ensure security.<\/p>\n<h2>Security Measures<\/h2>\n<p>\nSo, of course, typically, our goal (or rather, our management's goal) is to achieve the impossible: to provide maximum convenience with maximum security at minimal cost.<\/p>\n<p>Let's explore what methods we have for providing protection.<\/p>\n<p>For the office, I would highlight the following:<\/p>\n<ul>\n<li>zero trust approach in design<\/li>\n<li>high level of security <\/li>\n<li>network visibility<\/li>\n<li>unified centralized system of authentication and authorization<\/li>\n<li>host checking <\/li>\n<\/ul>\n<p>\nNext, let's take a closer look at each of these aspects.<\/p>\n<h3>Zero Trust<\/h3>\n<p>\nThe IT world is changing rapidly. In just the last 10 years, the emergence of new technologies and products has led to a significant revision of security concepts. Ten years ago, from a security standpoint, we segmented the network into trust, DMZ, and untrust zones, applying the so-called 'perimeter protection', where there were two lines of defense: untrust -&gt; DMZ and DMZ -&gt; trust. Additionally, protection was typically limited to access lists based on L3\/L4 (OSI) headers (IP, TCP\/UDP ports, TCP flags). Anything related to higher levels, including L7, was left to the operating system and protection products installed on end hosts.<\/p>\n<p>The situation has changed drastically now. The modern <noindex><a rel=\"nofollow\" href=\"https:\/\/doubleoctopus.com\/security-wiki\/network-architecture\/zero-trust\/\">zero trust<\/a><\/noindex> concept stems from the idea that it is no longer possible to consider internal systems, that is, those within the perimeter, as trusted, and the very concept of a perimeter has become blurred.<br \/>\nIn addition to internet connectivity, we also have<\/p>\n<ul>\n<li>users' remote access VPNs<\/li>\n<li>various personal gadgets, brought laptops connecting through office WiFi<\/li>\n<li>other branch offices<\/li>\n<li>integration with cloud infrastructure <\/li>\n<\/ul>\n<p>\nHow does the Zero Trust approach look in practice?<\/p>\n<p>Ideally, only the traffic that is necessary should be allowed, and if we are talking about an ideal situation, control should be not only at the L3\/L4 level but at the application level. <\/p>\n<p>For instance, if you have the ability to route all traffic through a firewall, you can try to approach the ideal. However, such an approach may significantly reduce the overall bandwidth of your network, and application filtering does not always work effectively.<\/p>\n<p>When controlling traffic at a router or L3 switch (using standard ACLs), you encounter other issues:<\/p>\n<ul>\n<li>this is only L3\/L4 filtering. Nothing prevents an attacker from using permitted ports (for example, TCP 80) for their application (not http)<\/li>\n<li>complex ACL management (difficult to analyze ACL)<\/li>\n<li>this is not a stateful firewall, which means you have to explicitly allow reverse traffic<\/li>\n<li>in the case of switches, you are usually quite rigidly limited by TCAM size, which in the case of applying the 'allow only what is needed' approach can quickly become a problem<\/li>\n<\/ul>\n<p><\/p>\n<blockquote><p><b>Note<\/b><\/p>\n<p>Speaking of reverse traffic, we must remember that we have the following option (Cisco) <\/p>\n<p>permit tcp any any established<\/p>\n<p>But it should be understood that this line is equivalent to two lines:<br \/>\npermit tcp any any ack<br \/>\npermit tcp any any rst<\/p>\n<p>This means that even if there was no original TCP segment with the SYN flag (that is, the TCP session did not even start establishing), this ACL will allow the packet with the ACK flag, which a malicious actor can exploit to transfer data.<\/p>\n<p>So, this line does not turn your router or L3 switch into a stateful firewall in any way.<\/p><\/blockquote>\n<p><\/p>\n<h3>High level of protection<\/h3>\n<p>\nIn <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/435138\/\">article<\/a><\/noindex> In the section dedicated to data centers, we discussed the following protection methods.<\/p>\n<ul>\n<li>stateful firewalling (by default)<\/li>\n<li>ddos\/dos protection<\/li>\n<li>application firewalling<\/li>\n<li>threat prevention (antivirus, anti-spyware, and vulnerability)<\/li>\n<li>URL filtering<\/li>\n<li>data filtering (content filtering)<\/li>\n<li>file blocking (file types blocking)<\/li>\n<\/ul>\n<p>\nIn the case of an office, the situation is similar, but the priorities are slightly different. Office availability is usually not as critical as in the case of a data center, while the likelihood of 'internal' malicious traffic is significantly higher. <br \/>\nTherefore, the following protection methods for this segment become critical:<\/p>\n<ul>\n<li>application firewalling<\/li>\n<li>threat prevention (anti-virus, anti-spyware, and vulnerability)<\/li>\n<li>URL filtering<\/li>\n<li>data filtering (content filtering)<\/li>\n<li>file blocking (file types blocking)<\/li>\n<\/ul>\n<p>\nAlthough all these protection methods, except for application firewalling, have traditionally been and continue to be implemented on end hosts (for example, by installing antivirus software) and through proxies, modern NGFW also provide these services. <\/p>\n<p>Security equipment vendors are striving to create comprehensive protection, so alongside local box protection, various cloud technologies and client software for hosts (end point protection\/EPP) are offered. For example, from <noindex><a rel=\"nofollow\" href=\"https:\/\/www.fairline.com.tw\/data\/editor\/files\/01%20%20Gartner%20-%20Magic%20Quad%20-%20Endpoint%20Protection%20Platforms%201-2018.pdf\">the Gartner Magic Quadrant of 2018<\/a><\/noindex> we see that Palo Alto and Cisco have their EPP (PA: Traps, Cisco: AMP), but are not leading.<\/p>\n<p>Enabling these protections (usually by purchasing licenses) on the firewall is, of course, not mandatory (you can take the traditional path), but it provides certain advantages:<\/p>\n<ul>\n<li>in this case, there is a single point of application of protection methods, which improves visibility (see the next topic). <\/li>\n<li>if an unprotected device is found in your network, it is still covered under the \u2018umbrella\u2019 of the firewall's protection.<\/li>\n<li> By using firewall protections alongside endpoint defenses, we increase the likelihood of detecting malicious traffic. For example, utilizing threat prevention on local hosts and the firewall boosts detection rates (provided, of course, that these solutions are based on different software products).<\/li>\n<\/ul>\n<blockquote><p><b>Note<\/b><\/p>\n<p>If, for instance, you use Kaspersky as your antivirus on both the firewall and endpoint hosts, it obviously won't significantly enhance your chances of preventing a virus attack in your network.<\/p><\/blockquote>\n<p><\/p>\n<h3>Network visibility<\/h3>\n<p>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/blog.gigamon.com\/2017\/11\/01\/what-is-network-visibility\/\">The main idea<\/a><\/noindex> is simple \u2013 to 'see' what is happening in your network, both in real-time and historical data. <\/p>\n<p>I would divide this 'vision' into two groups:<\/p>\n<p><b>Group one:<\/b> what your monitoring system typically provides.<\/p>\n<ul>\n<li>hardware utilization<\/li>\n<li>bandwidth utilization<\/li>\n<li>memory usage<\/li>\n<li>disk usage<\/li>\n<li>changes in the routing table <\/li>\n<li>link status<\/li>\n<li>availability of equipment (or hosts)<\/li>\n<li>\u2026<\/li>\n<\/ul>\n<p><b>Group two: <\/b>information related to security.<\/p>\n<ul>\n<li>various kinds of statistics (for example, related to applications, URL visits, what types of data were downloaded, user data)<\/li>\n<li>what has been blocked by security policies and for what reason, namely\n<ul>\n<li>prohibited application<\/li>\n<li>blocked based on ip\/protocol\/port\/flags\/zones<\/li>\n<li>threat prevention<\/li>\n<li>url filtering<\/li>\n<li>data filtering<\/li>\n<li>file blocking<\/li>\n<li>\u2026<\/li>\n<\/ul>\n<\/li>\n<li>statistics on DOS\/DDOS attacks<\/li>\n<li>failed attempts at identification and authorization<\/li>\n<li>statistics on all the aforementioned security policy violation events<\/li>\n<li>\u2026<\/li>\n<\/ul>\n<p>\nIn this chapter focusing on security, we are particularly interested in the second part.<\/p>\n<p>Some modern firewalls (from my experience, Palo Alto) provide a good level of visibility. However, the traffic of interest must go through this firewall (in which case you have the opportunity to block traffic) or be mirrored to the firewall (used only for monitoring and analysis), and you must have licenses that allow you to enable all these services.<\/p>\n<p>There is, of course, an alternative route, or rather, a traditional one, for example,<\/p>\n<ul>\n<li>session statistics can be collected through netflow and then analyzed using specialized tools for information analysis and data visualization.<\/li>\n<li>threat prevention \u2013 special programs (anti-virus, anti-spyware, firewall) on endpoint hosts.<\/li>\n<li>URL filtering, data filtering, file blocking \u2013 on proxy<\/li>\n<li>you can also analyze tcpdump using, for example, <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/cisco\/blog\/268207\/\">snort<\/a><\/noindex><\/li>\n<\/ul>\n<p>\nYou can combine these two approaches, complementing the missing functions or duplicating them to increase the likelihood of detecting an attack.<\/p>\n<p>Which approach to choose?<br \/>\nIt largely depends on the qualifications and preferences of your team.<br \/>\nBoth have their pros and cons.<\/p>\n<h3>A unified centralized authentication and authorization system<br \/>\n<\/h3>\n<p>\nWith a good design, the mobility discussed in this article implies that you have the same access whether you are working from the office, at home, in the airport, in a caf\u00e9, or any other location (with the limitations discussed above). What seems to be the problem? <br \/>\nTo better understand the complexity of this task, let's consider a typical design.<\/p>\n<blockquote><p><b>Example<\/b><\/p>\n<ul>\n<li>You grouped all employees. You decided to provide access by groups.<\/li>\n<li>Inside the office, you control access at the office firewall.<\/li>\n<li>You control traffic from the office to the data center at the data center firewall.<\/li>\n<li>As a VPN gateway, you use Cisco ASA and for controlling traffic entering your network from dedicated clients, you use local (on ASA) ACLs.<\/li>\n<\/ul>\n<p>\nNow, suppose you are asked to add additional access for a specific employee. You are requested to grant access only to him and no one else in his group.<\/p>\n<p>To do this, we need to create a separate group for this employee, that is,<\/p>\n<ul>\n<li>create a separate IP pool for this employee on ASA.<\/li>\n<li>add a new ACL on ASA and associate it with this remote client.<\/li>\n<li>create new security policies on the office and data center firewalls.<\/li>\n<\/ul>\n<p>\nThis is fine if this event is rare. However, in my experience, there have been cases where employees participated in different projects, and this set of projects changed quite often for some of them, and it wasn\u2019t just 1-2 people, but dozens. Clearly, something needed to change here.<\/p>\n<p>This was resolved in the following way.<\/p>\n<p>We decided that the sole source of truth determining all possible accesses for an employee would be LDAP. We created various groups that define sets of accesses, and each user was linked to one or more groups. <\/p>\n<p>For example, let's assume there were groups: <\/p>\n<ul>\n<li>guest (Internet access)<\/li>\n<li>common access (access to shared resources: email, knowledge base, \u2026)<\/li>\n<li>accounting<\/li>\n<li>project 1<\/li>\n<li>project 2<\/li>\n<li>database administrator<\/li>\n<li>Linux administrator<\/li>\n<li>\u2026<\/li>\n<\/ul>\n<p>\nIf any employees were involved in both project 1 and project 2, and they required access necessary to work on those projects, then that employee was accordingly linked to the groups:<\/p>\n<ul>\n<li>guest <\/li>\n<li>common access<\/li>\n<li>project 1<\/li>\n<li>project 2<\/li>\n<\/ul>\n<p>\nHow can we now turn this information into access for network equipment? <\/p>\n<p>Cisco ASA Dynamic Access Policy (DAP) (see <noindex><a rel=\"nofollow\" href=\"https:\/\/www.cisco.com\/c\/en\/us\/support\/docs\/security\/asa-5500-x-series-next-generation-firewalls\/108000-dap-deploy-guide.html\">www.cisco.com\/c\/en\/us\/support\/docs\/security\/asa-5500-x-series-next-generation-firewalls\/108000-dap-deploy-guide.html<\/a><\/noindex>) is the solution that fits this task.<\/p>\n<p>Briefly about our implementation: during the identification\/authorization process, ASA receives a set of groups corresponding to the user from LDAP and \"collects\" a dynamic ACL from several local ACLs (each corresponding to a group) with all necessary accesses, fully meeting our requirements.<\/p>\n<p>But this is only for VPN connections. To equalize the situation for employees connecting via VPN and those in the office, the following step was taken. <\/p>\n<p>When connecting from the office, users would either go to a guest VLAN (for guests) or to a common access VLAN (for company employees) using the 802.1x protocol. Then, to gain specific accesses (for example, to projects in the data center), employees had to connect via VPN.<\/p>\n<p>Different tunnel groups were used on ASA for connections from the office and home. This was necessary so that the traffic to shared resources (used by all employees, such as email, file servers, ticketing systems, DNS, ...) for those connecting from the office would not go through ASA, but rather through the local network. In this way, we did not overload ASA with unnecessary traffic, including high-intensity traffic.<\/p>\n<p>Thus, the task was solved. <br \/>\nWe received <\/p>\n<ul>\n<li>an identical set of accesses for both office connections and remote connections<\/li>\n<li>no degradation of service when working from the office, related to the transfer of high-intensity traffic through ASA<\/li>\n<\/ul>\n<p>\nWhat other advantages does this approach have?<br \/>\nIn access administration. Accesses are easily changed in one place.<br \/>\nFor example, if an employee leaves the company, you simply remove them from LDAP, and they automatically lose all accesses.\n<\/p><\/blockquote>\n<p><\/p>\n<h3>Host checking<\/h3>\n<p>\nWith the possibility of remote connections, we face the risk of not only allowing company employees into the network but also any malware that might be present on their computers (for instance, their home machines). Furthermore, through this software, we may inadvertently provide access to our network for an attacker who uses this host as a proxy.<\/p>\n<p>It is wise to apply the same security requirements for remotely connected hosts as for those located in the office.<\/p>\n<p>This includes having the 'right' version of the OS, anti-virus, anti-spyware, and firewall software, along with regular updates. Usually, this capability exists on the VPN gateway (for ASA, see for example, <noindex><a rel=\"nofollow\" href=\"https:\/\/community.cisco.com\/t5\/security-documents\/how-to-configure-anyconnect-host-scan\/ta-p\/3118732\">here<\/a><\/noindex>).<\/p>\n<p>It is also prudent to apply the same traffic analysis and blocking methods (see 'High Level of Protection') that align with your security policy applicable to office traffic. <\/p>\n<p>One should assume that your office network is no longer limited to the office building and the hosts within it.<\/p>\n<blockquote><p><b>Example<\/b><\/p>\n<p>A good approach is to provide each employee who needs remote access with a quality, user-friendly laptop and require them to work both in the office and from home only on that device.<\/p>\n<p>This not only enhances the security level of your network but is also quite convenient and generally viewed positively by employees (if it is indeed a good and user-friendly laptop).<\/p><\/blockquote>\n<p><\/p>\n<h2>On the sense of measure and balance<\/h2>\n<p>\nEssentially, this is a discussion about the third peak of our triangle \u2014 the price.<br \/>\nLet's consider a hypothetical example.<\/p>\n<blockquote><p><b>Example<\/b><\/p>\n<p>You have an office with 200 people. You decided to make it as comfortable and secure as possible.<\/p>\n<p>Therefore, you decided to route all traffic through a firewall, making it the default gateway for all office subnets. In addition to security software installed on each endpoint (anti-virus, anti-spyware, and firewall software), you've also opted to implement all possible protective measures on the firewall.<\/p>\n<p>To ensure high connection speeds (all for convenience), you selected access switches with 10-gigabit access ports and high-performance NGFW firewalls, such as the Palo Alto 7K series (with 40-gigabit ports), of course, with all licenses included and, of course, a High Availability pair.<\/p>\n<p>Of course, to work with this lineup of equipment, we need at least a couple of highly qualified security engineers.<\/p>\n<p>Next, you decided to provide each employee with a good laptop.<\/p>\n<p>In total, about 10 million dollars for implementation, hundreds of thousands of dollars (I think closer to a million) for annual support and salaries for engineers.<\/p>\n<p>Office, 200 people\u2026<br \/>\nConvenient? Probably, yes. <\/p>\n<p>You present this proposal to your management\u2026<br \/>\nPerhaps there are some companies in the world for which this is an acceptable and correct solution. If you are an employee of such a company \u2014 congratulations, but in the overwhelming majority of cases, I am sure your knowledge will not be appreciated by management.<\/p><\/blockquote>\n<p>\nIs this example exaggerated? The next chapter will answer this question.<\/p>\n<p>If in your network you do not see anything from the above, then that is normal.<br \/>\nFor each specific case, you need to find a reasonable compromise between convenience, cost, and security. Often, an NGFW is not required in your office, and L7 protection on the firewall is not needed. It is enough to ensure a good level of visibility and alerts, and this can be done using open source products, for example. Yes, your reaction to an attack won't be instantaneous, but the main thing is that you will see it, and with the right processes in your department, you will be able to neutralize it quickly.<\/p>\n<p>And, let me remind you that the intent of this series of articles is not to design a network, but rather to improve what you have been given.<\/p>\n<h2>Analysis of SAFE architecture in the office<\/h2>\n<p>\nPay attention to this red square, which I highlighted on the diagram from <noindex><a rel=\"nofollow\" href=\"https:\/\/www.cisco.com\/c\/dam\/en\/us\/solutions\/collateral\/enterprise\/design-zone-security\/safe-architecture-guide-secure-campus.pdf\">SAFE Secure Campus Architecture Guide<\/a><\/noindex>, which I would like to discuss here.<\/p>\n<p><img decoding=\"async\" alt=\"How to Take Control of Your Network Infrastructure. Chapter Three. Network Security. Part Three\" src=\"\/wp-content\/uploads\/2019\/04\/617b6561b6ebb17d4f015251abcadf9b.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThis is one of the key places in the architecture and one of the most important uncertainties.<\/p>\n<blockquote><p><b>Note<\/b><\/p>\n<p>I have never configured or worked with FirePower (from Cisco's line of firewalls \u2014 only with ASA), so I will consider it like any other firewall, for example, like Juniper SRX or Palo Alto, assuming it has the same capabilities.<\/p><\/blockquote>\n<p>\nFrom the usual designs, I see only 4 possible ways to use the firewall in such a connection:<\/p>\n<ul>\n<li>the default gateway for each subnet is the switch, while the firewall operates in transparent mode (meaning all traffic goes through it, but it does not create an L3 hop).<\/li>\n<li>The default gateway for each subnet is the firewall's sub-interfaces (or SVI interfaces), with the switch acting as L2.<\/li>\n<li>Different VRFs are used on the switch, and traffic between VRFs goes through the firewall, while traffic within a single VRF is controlled by ACL on the switch.<\/li>\n<li>All traffic is mirrored to the firewall for analysis and monitoring, but traffic does not pass through it.<\/li>\n<\/ul>\n<p><\/p>\n<blockquote><p><b>Note 1<\/b><\/p>\n<p>Combinations of these options are possible, but for simplicity, we will not consider them.<\/p><\/blockquote>\n<blockquote><p><b>Note 2<\/b><\/p>\n<p>There is also the option of using PBR (service chain architecture), but while it seems like an attractive solution, it is more exotic and I will not consider it here.<\/p><\/blockquote>\n<p>\nFrom the flow descriptions in the document, we see that traffic does indeed go through the firewall, meaning that according to Cisco's design, the fourth option is ruled out.<\/p>\n<p>Let's first consider the first two options.<br \/>\nIn these options, all traffic goes through the firewall.<\/p>\n<p>Now let's take a look. <noindex><a rel=\"nofollow\" href=\"https:\/\/www.cisco.com\/c\/en\/us\/products\/collateral\/security\/firepower-ngfw\/data_sheet-c78-736661.html\">data sheet<\/a><\/noindex>, let's examine. <noindex><a rel=\"nofollow\" href=\"https:\/\/itprice.com\">Cisco GPL<\/a><\/noindex> and see that if we want to have a total bandwidth for our office of at least around 10 to 20 gigabits, we need to purchase the 4K version.<\/p>\n<blockquote><p><b>Note<\/b><\/p>\n<p>When I talk about total bandwidth, I mean the traffic between subnets (not within a single VLAN).<\/p><\/blockquote>\n<p>\nFrom the GPL, we see that for the HA Bundle with Threat Defense, the price varies depending on the model (4110 - 4150) from about 0.5 to 2.5 million dollars.<\/p>\n<p>So our design starts to resemble the previous example.<\/p>\n<p>Does this mean that this design is incorrect?<br \/>\nNo, it doesn't mean that. Cisco provides you with the maximum possible protection based on the product line it has. But that doesn't mean it's a must-do for you. <\/p>\n<p>In essence, this is a common question that arises when designing an office or data center, and it just means that a compromise needs to be sought. <\/p>\n<p>For example, not all traffic should go through the firewall, and in this case, the third option seems quite appealing to me, or (see the previous section), maybe you don't need 'Threat Defense' or even a firewall in this segment of the network, and it may suffice to stick to passive monitoring using paid (not expensive) or open-source solutions, or you may need a firewall, but from a different vendor.<\/p>\n<p>There is usually always this uncertainty, and there is no definitive answer as to what solution is best for you.<br \/>\nThat's the complexity and beauty of this task.<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/447610\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u042d\u0442\u0430 \u0441\u0442\u0430\u0442\u044c\u044f \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043f\u044f\u0442\u043e\u0439 \u0432 \u0446\u0438\u043a\u043b\u0435 \u0441\u0442\u0430\u0442\u0435\u0439 \u00ab\u041a\u0430\u043a \u0432\u0437\u044f\u0442\u044c \u0441\u0435\u0442\u0435\u0432\u0443\u044e \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0443 \u043f\u043e\u0434 \u0441\u0432\u043e\u0439 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044c\u00bb. \u0421\u043e\u0434\u0435\u0440\u0436\u0430\u043d\u0438\u0435 \u0432\u0441\u0435\u0445 \u0441\u0442\u0430\u0442\u0435\u0439 \u0446\u0438\u043a\u043b\u0430 \u0438 \u0441\u0441\u044b\u043b\u043a\u0438 \u043c\u043e\u0436\u043d\u043e \u043d\u0430\u0439\u0442\u0438 \u0437\u0434\u0435\u0441\u044c. \u042d\u0442\u0430 \u0447\u0430\u0441\u0442\u044c \u0431\u0443\u0434\u0435\u0442 \u043f\u043e\u0441\u0432\u044f\u0449\u0435\u043d\u0430 Campus (Office) &amp; Remote access VPN \u0441\u0435\u0433\u043c\u0435\u043d\u0442\u0430\u043c. \u041c\u043e\u0436\u0435\u0442 \u043f\u043e\u043a\u0430\u0437\u0430\u0442\u044c\u0441\u044f, \u0447\u0442\u043e \u0434\u0438\u0437\u0430\u0439\u043d \u043e\u0444\u0438\u0441\u043d\u043e\u0439 \u0441\u0435\u0442\u0438 \u2013 \u044d\u0442\u043e \u043f\u0440\u043e\u0441\u0442\u043e. \u0414\u0435\u0439\u0441\u0442\u0432\u0438\u0442\u0435\u043b\u044c\u043d\u043e, \u0431\u0435\u0440\u0435\u043c L2\/L3 \u043a\u043e\u043c\u043c\u0443\u0442\u0430\u0442\u043e\u0440\u044b, \u0441\u043e\u0435\u0434\u0438\u043d\u044f\u0435\u043c \u0438\u0445 \u043c\u0435\u0436\u0434\u0443 \u0441\u043e\u0431\u043e\u0439. \u0414\u0430\u043b\u0435\u0435, \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u043c \u044d\u043b\u0435\u043c\u0435\u043d\u0442\u0430\u0440\u043d\u0443\u044e \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0443 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":23359,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-31395","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u042d\u0442\u0430 \u0441\u0442\u0430\u0442\u044c\u044f \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043f\u044f\u0442\u043e\u0439 \u0432 \u0446\u0438\u043a\u043b\u0435 \u0441\u0442\u0430\u0442\u0435\u0439 \u00ab\u041a\u0430\u043a \u0432\u0437\u044f\u0442\u044c \u0441\u0435\u0442\u0435\u0432\u0443\u044e \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0443 \u043f\u043e\u0434 \u0441\u0432\u043e\u0439 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044c\u00bb.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-vzyat-setevuyu-infrastrukturu-pod-svoj-kontrol-glava-tretya-setevaya-bezopasnost-chast-tretya\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u0430\u043a \u0432\u0437\u044f\u0442\u044c \u0441\u0435\u0442\u0435\u0432\u0443\u044e \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0443 \u043f\u043e\u0434 \u0441\u0432\u043e\u0439 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044c. \u0413\u043b\u0430\u0432\u0430 \u0442\u0440\u0435\u0442\u044c\u044f. \u0421\u0435\u0442\u0435\u0432\u0430\u044f \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c. \u0427\u0430\u0441\u0442\u044c \u0442\u0440\u0435\u0442\u044c\u044f | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u042d\u0442\u0430 \u0441\u0442\u0430\u0442\u044c\u044f \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043f\u044f\u0442\u043e\u0439 \u0432 \u0446\u0438\u043a\u043b\u0435 \u0441\u0442\u0430\u0442\u0435\u0439 \u00ab\u041a\u0430\u043a \u0432\u0437\u044f\u0442\u044c \u0441\u0435\u0442\u0435\u0432\u0443\u044e \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0443 \u043f\u043e\u0434 \u0441\u0432\u043e\u0439 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044c\u00bb.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-vzyat-setevuyu-infrastrukturu-pod-svoj-kontrol-glava-tretya-setevaya-bezopasnost-chast-tretya\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:41:01+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:41:01+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47How to Take Control of Your Network Infrastructure. Chapter Three. Network Security. Part Three | ProHoster","description":"This article is the fifth in the series \"How to Take Control of Your Network Infrastructure.\"","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-vzyat-setevuyu-infrastrukturu-pod-svoj-kontrol-glava-tretya-setevaya-bezopasnost-chast-tretya","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u0430\u043a \u0432\u0437\u044f\u0442\u044c \u0441\u0435\u0442\u0435\u0432\u0443\u044e \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0443 \u043f\u043e\u0434 \u0441\u0432\u043e\u0439 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044c. \u0413\u043b\u0430\u0432\u0430 \u0442\u0440\u0435\u0442\u044c\u044f. \u0421\u0435\u0442\u0435\u0432\u0430\u044f \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c. \u0427\u0430\u0441\u0442\u044c \u0442\u0440\u0435\u0442\u044c\u044f | ProHoster","og:description":"\u042d\u0442\u0430 \u0441\u0442\u0430\u0442\u044c\u044f \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043f\u044f\u0442\u043e\u0439 \u0432 \u0446\u0438\u043a\u043b\u0435 \u0441\u0442\u0430\u0442\u0435\u0439 \u00ab\u041a\u0430\u043a \u0432\u0437\u044f\u0442\u044c \u0441\u0435\u0442\u0435\u0432\u0443\u044e \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0443 \u043f\u043e\u0434 \u0441\u0432\u043e\u0439 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044c\u00bb.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-vzyat-setevuyu-infrastrukturu-pod-svoj-kontrol-glava-tretya-setevaya-bezopasnost-chast-tretya","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:41:01+00:00","article:modified_time":"2019-10-31T18:41:01+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"31395","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 05:58:22","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 03:17:26","updated":"2026-01-21 05:58:22","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/31395","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=31395"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/31395\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/23359"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=31395"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=31395"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=31395"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}