Most probably my ISP has hacked my router. (Dont' argue this).
1. Disable SSH services
2. Disable root user in web gui option
3. WiFI based on MAC Address only
4. Installed Suricata IPS
5. Disable boot into single user mode to prevent hacker change password
6. How to enable sudo?
,,,: "Operative Hektik ersetzt geistige Windstille".
4. Installed Suricata IPSQuoteNo idea, I do not believe in IPS.Expand on this please...Not because I want to debate, but I think you're brilliant, and I've been going back & forth on the decision to implement this in our network.
No idea, I do not believe in IPS.
I found article to hardened OPNsense box.
Quote from: peterwkc on November 27, 2024, 09:23:29 am4. Installed Suricata IPSQuoteNo idea, I do not believe in IPS.Expand on this please...Not because I want to debate, but I think you're brilliant, and I've been going back & forth on the decision to implement this in our network.This is well worth discussing, but maybe in a different thread. I, btw, also don't believe in most of the things IPS is supposed to do.
Quote from: Patrick M. Hausen on November 27, 2024, 09:49:04 amNo idea, I do not believe in IPS.Expand on this please...Not because I want to debate, but I think you're brilliant, and I've been going back & forth on the decision to implement this in our network.
- do monitor what is happening around your network, use an NMS like Observium, NtopNG, some Elastic based solution like pfELK - "The number of times an uninteresting thing occurs is an interesting thing." (Marcus Ranum, IIRC, on firewall-wizards).
Quote- do monitor what is happening around your network, use an NMS like Observium, NtopNG, some Elastic based solution like pfELK - "The number of times an uninteresting thing occurs is an interesting thing." (Marcus Ranum, IIRC, on firewall-wizards).Which from these you use may you/care you share some experience or insights?