Logistics

The exposed Linux server stopped being reachable.

An air-express and cargo operator put one access model in front of every application across its warehouse network, and took the server that had been open to the internet off it.

Supervisor watching parcels on a sorting-floor conveyor
The situation

Where they started.

Warehouse office overlooking the loading floor

The customer is one of India's leading air-express shipping, cargo and logistics companies, working through a wide network of warehouses and franchise partners.

Endpoints are spread across those sites, many of them Linux, and the enterprise application they all needed was being reached through a Linux server that sat exposed on the public internet. Anything that could find the address could knock on it.

The company wanted one way to reach every application, cloud-hosted or in its own data centre, that worked on every operating system in the estate. It also wanted the exposed server to stop being a public address.

The problem

What was in the way.

  • Linux estateSecure remote access had to cover Linux machines, not only the Windows desktops most access products assume.
  • One way inEvery enterprise application needed to be reachable through a single method, instead of one arrangement per application.
  • A public addressThe Linux server used to reach the enterprise application was exposed, so it could be found and probed by anyone.
The build

What was put in place.

Each control below has its own page. If a row makes a claim, the link is where you check it.

  1. Server concealedThe exposed Linux server stopped answering the public internet; it accepts a session only after the user, the device and the context have been checked.More
  2. One catalogueApplications in the data centre and applications in the cloud are published and granted from the same console.More
  3. Remote sessions visibleAccess by remote and off-premise users is recorded per session, so the warehouse network is legible from one place.More
Courier scanning a parcel at the back of a delivery van
OUTCOMES

What a distributed estate getsfrom one door

Three consequences of publishing applications instead of exposing the machines that serve them.

Need-to-know reach

A user is granted the applications their role requires and cannot enumerate the rest.

Every operating system

Windows, macOS and the Linux machines in the warehouses all use the same access path.

Sites, not exceptions

A new warehouse or franchise inherits the policy instead of negotiating its own.

InstaSafe stands out in terms of its flexibility and adaptability to dynamic hybrid environments. With singular visibility and management of access for any type of application, we are assured of better leg space in terms of security and cost effectiveness
IT leadershipAir express, cargo and logistics

Seven more stories, filtered by sector and by the problem they started with.

All customer stories

//Ready when you are//

Take one exposed server off the internet.

Bring the address that worries you most. We will show you what the port scan returns afterwards.

Regulated, air-gapped, or on-premise? See deployment options