Thoughts on how I could improve my network security?
- 
 @tim_g said in Thoughts on how I could improve my network security?: A lot of places will have SonicWALLs who haven't gotten it through an ITSP. Upper management made the decision to get a SonicWALL through their own research. And that's the way it is, in the real world. Not in Scott's world, but the real world. It happens like that in so many places it's actually odd to me that you haven't seen it happen. Perhaps you've only ever delt with F500s and that's how it is for them. Then eventually, IT staff comes on board who does know that SoincWALLs and UTMs shouldn't be used in those cases, but they are already there and nobody wants to spend the money to do it better. This is often the case, adn is what Dash was referring to I think. That's part of it. Apparrently I want to insult most adults by saying they can't or don't adult - i.e. don't know the difference between VAR and ITSP, but so few people actually put any thought into it. This makes me think that there is a hugely untapped market for ITSP like services to the common man. Find a way to siphon 50% of the wasted money that people spend by getting people better options when they are buying stuff. 
- 
 @tim_g said in Thoughts on how I could improve my network security?: Then eventually, IT staff comes on board who does know that SoincWALLs and UTMs shouldn't be used in those cases, but they are already there and nobody wants to spend the money to do it better. This is often the case, adn is what Dash was referring to I think. He might be referring to the case, but why refer to it? What's the relevance? No one was questioning the process by which bad companies do bad things. Only pointing out how good decisions get made and what they would look like. 
- 
 @coliver said in Thoughts on how I could improve my network security?: @tim_g said in Thoughts on how I could improve my network security?: A lot of places will have SonicWALLs who haven't gotten it through an ITSP. Upper management made the decision to get a SonicWALL through their own research. And that's the way it is, in the real world. Not in Scott's world, but the real world. It happens like that in so many places it's actually odd to me that you haven't seen it happen. Perhaps you've only ever delt with F500s and that's how it is for them. Then eventually, IT staff comes on board who does know that SoincWALLs and UTMs shouldn't be used in those cases, but they are already there and nobody wants to spend the money to do it better. This is often the case, adn is what Dash was referring to I think. This is the Cisco arguement. Upper management sees Cisco advertisements during the a football game. That's the extent of their research. If the case is upper management made the decision and you've made the case as to why that's not the best decision in this situation. Then you did what you could. "Not my Monkey, not my Circus." Notice I didn't say a bad decision, no one is criticizing or saying the solution won't work. 
- 
 @dashrender said in Thoughts on how I could improve my network security?: Apparrently I want to insult most adults by saying they can't or don't adult - i.e. don't know the difference between VAR and ITSP, but so few people actually put any thought into it. I simply don't believe this "people are so stupid" argument. I can't. It's so insulting to business owners. That they don't care, yeah, I'm all on board. That they can't figure out their agents from their enemy agents, their representative from sales people is just absurd. yes, someone somewhere actually can't tell the difference, and they should probably be in a rubber room. But this takes no mental energy, no special knowledge, no business sense... just having grown up and being an adult. 
- 
 @scottalanmiller said in Thoughts on how I could improve my network security?: @tim_g said in Thoughts on how I could improve my network security?: Perhaps you've only ever delt with F500s and that's how it is for them. I deal with every business type of every size. But it would be odd for someone to hire me without any intention of trying to do IT well. Just doesn't make sense. So of course, I see only the top crust of any market. ITSPs, practically by defition, never see bad companies or even average. Only VARs see those. Yet there are a ton more VARs out there than ITSPs. I'm guessing the ITSPs just aren't marketing themselves effectively, otherwise you'd think even crazy emotional business people would realize that saving money by using an ITSP would be good. 
- 
 @dashrender said in Thoughts on how I could improve my network security?: This makes me think that there is a hugely untapped market for ITSP like services to the common man. Yes, there is a massive market there. And loads of people making money at it. Life coaches, personal shoppers, Pioneer woman, etc. People need ITSP equivalents for everything in life, and they are available. 
- 
 @dashrender said in Thoughts on how I could improve my network security?: @scottalanmiller said in Thoughts on how I could improve my network security?: @tim_g said in Thoughts on how I could improve my network security?: Perhaps you've only ever delt with F500s and that's how it is for them. I deal with every business type of every size. But it would be odd for someone to hire me without any intention of trying to do IT well. Just doesn't make sense. So of course, I see only the top crust of any market. ITSPs, practically by defition, never see bad companies or even average. Only VARs see those. Yet there are a ton more VARs out there than ITSPs. I'm guessing the ITSPs just aren't marketing themselves effectively, otherwise you'd think even crazy emotional business people would realize that saving money by using an ITSP would be good. Why does that say "yet", when it should say "obviously?" Of course VARs are more common, that's what I just explained. They have way more market to grab, and way higher profits. 
- 
 @scottalanmiller said in Thoughts on how I could improve my network security?: @dashrender said in Thoughts on how I could improve my network security?: Apparrently I want to insult most adults by saying they can't or don't adult - i.e. don't know the difference between VAR and ITSP, but so few people actually put any thought into it. I simply don't believe this "people are so stupid" argument. I can't. It's so insulting to business owners. That they don't care, yeah, I'm all on board. Why does care vs stupid play such a pivotal role for you? 
- 
 @scottalanmiller said in Thoughts on how I could improve my network security?: @dashrender said in Thoughts on how I could improve my network security?: Apparrently I want to insult most adults by saying they can't or don't adult - i.e. don't know the difference between VAR and ITSP, but so few people actually put any thought into it. I simply don't believe this "people are so stupid" argument. I can't. It's so insulting to business owners. That they don't care, yeah, I'm all on board. That they can't figure out their agents from their enemy agents, their representative from sales people is just absurd. yes, someone somewhere actually can't tell the difference, and they should probably be in a rubber room. But this takes no mental energy, no special knowledge, no business sense... just having grown up and being an adult. I'm not convinced by this. Have you talked to an average American adult lately? 
- 
 The average and under business, meaning most businesses, don't care about doing a good job or can't figure out how to. These are the customers for VARs. So obviously VARs have the much larger scale. And since VARs get to outright take advantage of their customers instead of representing them or trying to help, they get to make way more money off of each one. So the market in terms of customers is much larger, and the profit per customer is much, much larger. 
- 
 @dashrender said in Thoughts on how I could improve my network security?: @scottalanmiller said in Thoughts on how I could improve my network security?: @dashrender said in Thoughts on how I could improve my network security?: Apparrently I want to insult most adults by saying they can't or don't adult - i.e. don't know the difference between VAR and ITSP, but so few people actually put any thought into it. I simply don't believe this "people are so stupid" argument. I can't. It's so insulting to business owners. That they don't care, yeah, I'm all on board. Why does care vs stupid play such a pivotal role for you? Personal ethics, I guess. I grew up in an ethics system where condescending was considered bad. I understand that lots of people aren't super smart, but I don't believe that most people are truly idiots. 
- 
 @coliver said in Thoughts on how I could improve my network security?: @scottalanmiller said in Thoughts on how I could improve my network security?: @dashrender said in Thoughts on how I could improve my network security?: Apparrently I want to insult most adults by saying they can't or don't adult - i.e. don't know the difference between VAR and ITSP, but so few people actually put any thought into it. I simply don't believe this "people are so stupid" argument. I can't. It's so insulting to business owners. That they don't care, yeah, I'm all on board. That they can't figure out their agents from their enemy agents, their representative from sales people is just absurd. yes, someone somewhere actually can't tell the difference, and they should probably be in a rubber room. But this takes no mental energy, no special knowledge, no business sense... just having grown up and being an adult. I'm not convinced by this. Have you talked to an average American adult lately? Yes, and the key problem I always see is not caring. 
- 
 @dashrender said in Thoughts on how I could improve my network security?: I'm guessing the ITSPs just aren't marketing themselves effectively, Not really relavent if you assume... - ITSPs are the better choice.
- Business owners are idiots and too stupid to do things in their own best interest and/or just don't care.
 
- 
 @scottalanmiller said in Thoughts on how I could improve my network security?: The average and under business, meaning most businesses, don't care about doing a good job or can't figure out how to. These are the customers for VARs. So obviously VARs have the much larger scale. And since VARs get to outright take advantage of their customers instead of representing them or trying to help, they get to make way more money off of each one. So the market in terms of customers is much larger, and the profit per customer is much, much larger. See that's where I don't agree - I don't think they don't care, I consider it that they are ignorant - they simply don't know. They haven't been trained to really think that way. Perhaps, perhaps if you sat them down you could get them to explain it, but I'm almost positive that if without any actual discussion, that you couldn't get most business owners, or normal average adults to explain the difference between buyer's and seller's agents and how they apply to their near daily lives. (that last part is key). 
- 
 @scottalanmiller said in Thoughts on how I could improve my network security?: @dashrender said in Thoughts on how I could improve my network security?: I'm guessing the ITSPs just aren't marketing themselves effectively, Not really relavent if you assume... - ITSPs are the better choice.
- Business owners are idiots and too stupid to do things in their own best interest and/or just don't care.
 So which is it? stupid or don't care? 
- 
 @dashrender said in Thoughts on how I could improve my network security?: ... otherwise you'd think even crazy emotional business people would realize that saving money by using an ITSP would be good. This is assuming that even emotional people are rational when it comes to business, which directly goes against everything else said. The reality is, most business owners in the SMB don't care about making money. They have other, emotional things, that they care about more. Like getting to feel in control or just playing at business without real responsibilities. Making money is actually, quite rarely, the driving factor regardless of what people say. You can see this in.... just about any business that you talk to. 
- 
 @dashrender said in Thoughts on how I could improve my network security?: @scottalanmiller said in Thoughts on how I could improve my network security?: @dashrender said in Thoughts on how I could improve my network security?: I'm guessing the ITSPs just aren't marketing themselves effectively, Not really relavent if you assume... - ITSPs are the better choice.
- Business owners are idiots and too stupid to do things in their own best interest and/or just don't care.
 So which is it? stupid or don't care? Doesn't matter, in either case the result is the same. You think it's stupid, I think it's don't care, but the result is the same in this case. 
- 
 @dashrender said in Thoughts on how I could improve my network security?: See that's where I don't agree - I don't think they don't care, I consider it that they are ignorant - they simply don't know. I realize that I've been incorrect about ignorant in the past. In this case, I can't believe anyone can be that ignorant as a functional adult, hence my point. It would requiring ignoring basic common sense and adult skills to not understand this, hence why ignorant is wrong because ignorant means uninformed, rather than a state of having ignored. The real issue has to be a state of having ignored obvious knowledge. 
- 
 @scottalanmiller said in Thoughts on how I could improve my network security?: But, like all things of this nature, I've presented my side as to "why" keeping firewalls and the things considered "UTM functions" in separate places. Now, some feel the opposite. For those that want to say that UTMs (putting lots of applications together onto the router/firewall box) is better than the normal industry standard practice of keeping applications isolated, please present your reasons for wanting that. I've presented solid reasons, that you might not agree with, for why I'd follow industry best practice here. I don't remember anyone saying why they'd do the opposite, only questioning why I'd not do it, which isn't the same as presenting a reason. So I'm asking... what's the reasons for going against the grain in this one case? There are exceptions to most every rule, but I've not seen anyone anywhere ever present an argument for UTMs, only that they'd use them despite the reasons against them. It is not only the IT industry that does this. The audio/video industry does this also, maybe others do too. In a business or enterprise setup we never use equipment that contains all the functions in a single box, which is analogous to UTM's in the IT space. We separate out all the functions because it is more versatile, more reliable, usually more cost effective, and easier to troubleshoot issues. Do companies make boxes that include a pre-amp, amp, tuner, networking, storage, disc players, switchting, video processors and sound processors? Yes they do. Should you ever use one if your a business? Absolutely not if you can avoid it. If you have no other choice, like if someone else bought it and its your job to support then you just have to make do. If you have the budget then use separates, whether vm's or physical devices if you can't use a vm. 
- 
 @dashrender said in Thoughts on how I could improve my network security?: They haven't been trained to really think that way. - This is why I always refer to it as basic adulting - you can't reasonably get to be an adult without being exposed to this. It's totally unreasonable to assume anyone you've ever met that doesn't have an in home care provider doesn't know this. 



