Is CRS or CSS the Better Choice for Small Business Networks?

Correct. The IT-policies is written by the cloud enterprise people, with their cloud glasses.

Here ... I corrected it for you ....

But yet we pass major security vendor audits with just that . . . . all I can say is that it appears that the authors and the auditors don't talk much . . . .

Anything externally IS encrypted, certs etc. The issue (as I understand it), was that cert maintenance/updating had become almost impossible due to the number, so all was migrated to the F5, which handles itnin one place, and can automate updating.

Seems pretty hard to not trust a network on which you control all endpoints and the entire path. (IE datacenter internal only).

(Not my design or network, so don't bother bashing me . . . )

I don't have a dog in the fight. As answer is "it depends" :wink:

Now I'm a RouterOS guy, since you get all the L2 management plane stuff. SwOS has a limited TCP stack, so management across sites is tricky. So I don't use SwOS.

But there is something to be said for SwOS... especially if the network is pretty fixed. e.g. the switch is wired to ports on wall/servers. And while having RouterOS enables more management protocols... there is some benefit to SwOS in its simplicity + focus & if things don't change much that has some benefits than remote management. And better management with RouterOS, comes a risk that bug/attack surface of RouterOS is way bigger.

Of course it makes more sense to terminate SSL/TLS in the load balancer. Any tech know thats. But for an IT-security auditor, any unencrypted HTTP or TCP is a red flag. Even if the traffic only passes trough a datacenter switch.

On the other hand it makes the IDS/IPS/Cyber-people really mad.

The part I’m having trouble getting my head around is the proposition that the solution for the lack of TLS in the CSS is spending the $100 you saved (order of magnitude ballpark) on a five-figure corporate snooping box.

Yes, I get that it exists for reasons other than TLS termination, but why is cost any object in this discussion, if that’s the solution?

Obvious answer: TLS-puncturing middleboxes are not ubiquitous, thank Metcalfe.

Perhaps we get more real-world auditors . . . never said a peep . . . :grin:

Different use case . . . more of an example of acceptible use of unencrypted devices internally in an enterprise (no MikroTik at all, but not really relevant to the example).

I did fail to mention that those of us in IT bypass the balancer/encryption via direct access to the internal VLAN(s), the case being where no outside access is allowed at all, no encryption is in play other than what the VPN introduces.