<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-GB">
	<id>https://wiki.apoyar.eu/index.php?action=history&amp;feed=atom&amp;title=Apoyar_Infrastructure_Security</id>
	<title>Apoyar Infrastructure Security - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.apoyar.eu/index.php?action=history&amp;feed=atom&amp;title=Apoyar_Infrastructure_Security"/>
	<link rel="alternate" type="text/html" href="https://wiki.apoyar.eu/index.php?title=Apoyar_Infrastructure_Security&amp;action=history"/>
	<updated>2026-07-21T03:48:02Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.41.0</generator>
	<entry>
		<id>https://wiki.apoyar.eu/index.php?title=Apoyar_Infrastructure_Security&amp;diff=165&amp;oldid=prev</id>
		<title>Admin: Created page with &quot;We have 2 ESX host, 1 Disk array these provides access to VM’s  We have separate server Vcentre, which is a physical server and provides  - management over vpshere  - access...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.apoyar.eu/index.php?title=Apoyar_Infrastructure_Security&amp;diff=165&amp;oldid=prev"/>
		<updated>2021-04-22T09:07:04Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;We have 2 ESX host, 1 Disk array these provides access to VM’s  We have separate server Vcentre, which is a physical server and provides  - management over vpshere  - access...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;We have 2 ESX host, 1 Disk array these provides access to VM’s&lt;br /&gt;
&lt;br /&gt;
We have separate server Vcentre, which is a physical server and provides&lt;br /&gt;
&lt;br /&gt;
- management over vpshere&lt;br /&gt;
&lt;br /&gt;
- access to VM’s&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We have firewall called Juniper (2 firewall), if one fails other starts&lt;br /&gt;
&lt;br /&gt;
Also we have Clavister, which has same level as Juniper. Clavister has better support for different types of VPN &lt;br /&gt;
&lt;br /&gt;
It supports 3 types of VPN&lt;br /&gt;
&lt;br /&gt;
- L2TP&lt;br /&gt;
&lt;br /&gt;
- IPsec (used to connect customer’s)&lt;br /&gt;
&lt;br /&gt;
- OpenVPN&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 Connecting any of Apoyar server&lt;br /&gt;
----------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Weather we are connecting through OpenVPN or L2TP, we always getting through Clavister.&lt;br /&gt;
&lt;br /&gt;
For connecting using OpenVPN, we just need AD logins&lt;br /&gt;
&lt;br /&gt;
If we are connecting as L2TP user, it uses passphrase&lt;br /&gt;
&lt;br /&gt;
If we are connecting from any AWS console VM, it uses certificate&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Certificates on AWS RMG server&lt;br /&gt;
-------------------------------&lt;br /&gt;
&lt;br /&gt;
Login to rmg.aws.apoyar &lt;br /&gt;
&lt;br /&gt;
•	Cd /etc/isakmpd&lt;br /&gt;
&lt;br /&gt;
•	cd ca&lt;br /&gt;
&lt;br /&gt;
•	ls&lt;br /&gt;
&lt;br /&gt;
ca.crt (this is the certificate authority of mother or father certificate)&lt;br /&gt;
&lt;br /&gt;
It is only saved on clavister (one copy)&lt;br /&gt;
&lt;br /&gt;
Also on each AWS console machine, its only get compared not sent&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
To see certificates&lt;br /&gt;
--------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
•	openssl  x509  –in  ca.crt  –text –noout&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
To check local certificate&lt;br /&gt;
&lt;br /&gt;
•	Cd ../certs/&lt;br /&gt;
&lt;br /&gt;
•	openssl   x509  –in  local.crt  –text  –noout&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
these certificates contain the information related to&lt;br /&gt;
&lt;br /&gt;
•	Issuer&lt;br /&gt;
&lt;br /&gt;
•	Customer&lt;br /&gt;
&lt;br /&gt;
•	Expiry&lt;br /&gt;
&lt;br /&gt;
•	DNS&lt;/div&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
</feed>