Hacker News new | ask | show | jobs
by mikewarot 1862 days ago
If you put a data diode between your infrastructure and the internet, you can see the status from anywhere, yet never compromise it from the outside.
1 comments

Yes, I think we are on the same page.

I was trying to explain that having a separate monitoring infra and network group wouldn't work as a replacement for unidirectional network setup, because you sill need to open network access between critical infra and the monitoring system in your design, which will expose it to the internet.

So like you said, you still need to have an unidirectional network in place.