Thursday, October 28, 2021

Dumb question - from amateur trying to connect things and giving IT dept a solution

Let's start with background:

  1. main corporate network, on-board IT watching it, with redundancy, VPNs, proxies, etc.

Things like intranet, management and apps for it work there. Regular full corporate.

  1. additional network, with security measures (firewall, anti-malware) moved outside of our company (on ISP side, packet scanning, semi/full-automatic). Reason? 2nd network is used for live streaming, Zoom/vMix/Skype/other needed connections, sharing big files (videos) outside + video editing from shared NAS/server; whole 2nd network is bandwidth/CPU limited internally during work hours. Plus my/our personal preference - Parsec - as on-the-run/from-home access tool. So as you may gather from that - 2nd network may throttle easily on switches/routers already (especially on 4K RAW, yes, we need to move to 10Gbps), and CPUs hindered by suprisingly heavy corporate anti-malware thingies would lower video editors efficiency (-10-15% on mixed workload from my limited measurements)

So, what I'd like to get from you is - is it possible to connect network no.2 to no.1 (for intranet/mail config only, maybe letting IT access said PC remotely), without hindering video editing station performance? As in even some app that would let "outsiders" access 1st network intranet, without routing all of their traffic inefficiently?

PS.:

Both networks exist in the same building - but since we'd like to eliminate human factor when it comes to white/black-listings and other stuff that usually happens withing regular work hours (so when live streaming usually happens - and there was an accident when outgoing streaming packets were blacklisted by one of the admins mid-conference) - 2nd network is void of any major internal IT Security influence (aside from their suggestions - which can not override whitelist settings due to how we/ISP made it).

Everything else like anti-DDoS, Firewall, AntiMalware, is handled by ISP; we have logins like admin/every-other-obvious-points-of-entry disabled on every router/NAS/PC within the network; and MS Defender+Malwarebytes(lowest CPU usage from tests).



No comments:

Post a Comment