Fair enough....hopefully someone chimes in. I do appreciate your input. And that thread you pointed was a little over my head....but excellent nonetheless.
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Show posts MenuQuote from: Patrick M. Hausen on March 15, 2025, 12:36:50 AMIf you have inbound port forwarding rules or IPv6 allow rules for publicly accessible services, Crowdsec or blocklists are worth considering, IMHO.
Not a fan of IDS/IPS in general, because I think it's a fundamentally flawed concept.
I stopped using Crowdsec because the free blocklists are really not worth the effort of configuring and maintaining the service. For a company I would consider it, but just a bit under 100$ per month for the most basic subscription is prohibitive for me as a private user. All the interesting blocklists are subscription only.
100$ per year like I pay for Proxmox and I would be in.
So I just use FireHOL and friends for inbound connections, now.
If you do not have inbound connections for public services at all, I don't see a reason to use any of these products/technologies.
Install AdGuard Home for some DNS based filtering for outbound and you are good to go.
Quote from: dseven on February 24, 2025, 10:51:11 AMside-note: using ".local" for anything other than mDNS is generally not recommended
Since presumably "ourhome.local" is internal-only, you could change [Services > Unbound DNS > General > Local Zone Type] to "static"