Hacker News new | past | comments | ask | show | jobs | submit login

That DMZ is fine already, assuming they can't start hacking your routers.

What you ideally want is network segmentation, use VLANS and put devices in their isolated network, only allowed to talk to the router/firewall, which only allows incomming traffic and doesn't allow the web server to initiate connections to the internet, except for NTP, software updates and DNS (fixed ips).




Yeah I actually had a Ubiquiti Edgerouter doing this but I was never confident enough it was set up properly, hence the other solution.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: