Thursday, September 20, 2018

Isn't top-of-rack supposed to be secured and isolated?

Maybe I'm crazy here, but I always thought that the "top-of-rack" switch was a secured switch on an isolated network that didn't have any general traffic. (i.e. a "management network") Everything I've seen has ToR as being a general-purpose network that includes management traffic. This seems insane to me, because LoM/management interfaces are intentionally opened for protocols like SNMP, HTTP/S management, and VNC, not to mention how horribly insecure they can be anyway. It seems crazy that people would mix that traffic with general-purpose server traffic. Am I just being paranoid or crazy here? Am I missing something?



No comments:

Post a Comment