Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

+1.

I've done cross cloud connects where the cloud vendors are on the phone with me and eventually say "We really don't have any idea why the tunnels are not connecting". And that's when using Cisco VPN appliances, no less, following everyone's setup instructions to the letter.

Indeed, not a trivially solved problem yet.



Had the same problem with Verizon Medium Business in 2015. Turns out there was basically one guy who knew the internals of the (required) IPSec VPN, he couldn’t figure out why the tunnel wasn’t working and I gave up and switched to another provider.


Sounds like a real shitshow all around. Building IPSec tunnels between ASAs isn’t rocket science.

I would be worried about downstream issues with the security architecture, especially down the road when you pick up clients with compliance requirements.


...and I quote,

"3DES in combination with MD5 is a common candidate..."

If a security architecture is a priority, then these people will not be customers.

Triple DES is not "boring crypto" by any means.

https://news.ycombinator.com/item?id=13383006

Wireguard's crypto is boring. That's the point.


Yeah that’s a similar example of incompetent security or network engineering. (Or lack thereof)


I had one from Cisco to Meraki (who is owned by Cisco), they eventually gave up and told me to just buy another Cisco of the same model on the other side.


I don't have a horse in this race, but this sounds like a Cisco problem.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: