310
this post was submitted on 02 Nov 2024
310 points (98.1% liked)
Technology
59495 readers
3110 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I've had no end of trouble with routers and ones you should choose to be sure of.
The ones where you can flash OpenWRT seems the only choice if you want some semblance of security. But even my current Xiaomi router with stock firmware creates hash mismatches using
apt
to download things, and I don't 100% know with confidence that using OpenWRT on it instead is keeping me right.Any opinion on Mikrotik?
They are frequently targeted because they offer enterprise grade configurations at consumer prices.
Which means, there's a lot that can be misconfigured, and a lot of short staffed and under budgeted IT departments that deploy them, which means they are a good payoff when exploited.
That's the bad part, and the good part.
You really cannot beat their price point to value for professional grade networking equipment. Just take the time to understand what you're doing when doing your configurations, and keep them updated.
Very little is changing over time... I have a proliant salvage server running proxmox with some hosts and the router only port forwards to an NGINX proxy manager instance for the web interfaces on those hosts. I run a synology NAS separate from the proliant hardware that runs through the proxy.
I know I don't understand it all, and i'm open to suggestions.
Did you mean to send that reply to me?
I ask because I'm not quite sure what specific suggestions you're looking for.
But in general, I would suggest not exposing port forwarding.
What services are running behind NGINX? What router/firewall are you using?
Yes, I attribute security significant misconfigurations to a lag between new service deployments and a relevant review by network security (in a business environment. At home it's just me.)
So I'm running Milestone VMS, Synology NAS and maybe in a day a minecraft server for the kids, which should all be available outside my home. I'm using the mikrotik HexPOE which is my main router/firewall.