Enterprise Firewall Security
Hi, the situation is quite simple, enterprise level security requires the old moat and castle approach, for this reason having 15000 UDP ports open is rather a big security hole, it makes harder for IDS/IPS systems to analyze and alert admins for possible security issues within the network.
So my suggestion is for discord to provide a way to get the ip list for a specific server from a public API in the form of TXT that can be easily updated into modern firewalls (i.e. pfsense/opnsense).
It would go has follows:
Discord server admin would have access to create an URL that can be shared with the IP's of the voice servers, copy the link and give it to anyone, if for any reason the admin wants to discontinue or change the link he can by just reissuing a the link.
The same goes for ports in use by those servers on a separate link if possible.
This way not only is easy to add servers to the FW but also have them securely but keep them updated in case of server migration.
Until this is done enterprise network admins cannot allow discord voice to be used due to the huge range of ports being open.
Please sign in to leave a comment.
Comments
0 comments