Ask Your Question
0

Is it safe to expose openstack horizon on the internet ?

asked 2016-10-11 02:20:45 -0500

bahaika gravatar image

If it isn't safe, why ? If it is safe, is there anything to do to secure the setup (like a fail2ban) ?

edit retag flag offensive close merge delete

1 answer

Sort by ยป oldest newest most voted
1

answered 2016-10-11 13:51:36 -0500

I would recommend you to hide your complete OpenStack management network in a separate VLAN. And then setup a HaProxy as firewall and just forward the needed ports (with a ip whitelist if possible). Or just use a VPN server to access these services.

Horizon does not have protections against brute-force attacks or something like that. The same counts also for the Keystone API.

edit flag offensive delete link more

Comments

Agree. I wouldn't recommend leaving Horizon open to the Internet. Limiting ports & using an IP whitelist is a good idea as a min precaution. VPN is best. There are various free VPN solutions out there. SoftEther is a nice little VPN with lots of functionality. Untangle is a good free FW w/ VPN

Rick Kundiger gravatar imageRick Kundiger ( 2016-10-11 16:41:50 -0500 )edit

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Get to know Ask OpenStack

Resources for moderators

Question Tools

1 follower

Stats

Asked: 2016-10-11 02:20:45 -0500

Seen: 128 times

Last updated: Oct 11 '16