3 ms·
I think we're already there. Site I manage run separate VLANS for admin (switches, APs, etc) and Internet-of-Things, and both of those VLANS are default deny o
by daedalus_j 7y ago
I think we're already there.
Site I manage run separate VLANS for admin (switches, APs, etc) and Internet-of-Things, and both of those VLANS are default deny on outbound. That rule blocks a fair amount of traffic.
I wonder if part of the answer is better tools in firewalls for this sort of thing. Easily tagging "unstrusted device" or something perhaps.
- lostlogin 7y agoPihole, a router that forces anything on port 53 back to the Pihole and careful device selection seems to be very much required already.