4 ms·
"What would a more advanced router add?" -> A centrally managed firewall integrated with the rest of the networking stack = having cotroll in one place. You als
by user_agent 6y ago
"What would a more advanced router add?" -> A centrally managed firewall integrated with the rest of the networking stack = having cotroll in one place. You also can use the software one on Linux directly. I like to have a central one, because I have multiple servers behind it and I don't want to think too much about hardening them. This how I can make experiments inside the network not risking anything and overthinking the security for partially ready services. Good security is always about the firewall stuff divided into 2 parts - 1) a firewall on an edge; + 2) a light set of firewall rules on a server. It's just much simpler that way. Even if for the sake of reporting only.
PS: You can also buy just a firewall leaving your current router intact. pfSense is great software and it's free! You can install it on almost anything. An old laptop will do the job. Probably you could even run it on your Pi in a Docker container, leaving your Pi to perform 2 functions with additional Ethernet cards: the www server, and a dedicated firewall. Many options are available and tinkering with that is fun!
The config you've mentioned looks fine. The rest comes down to details: is your network going to survive a lot of incoming DDOS like traffic (how beefy is your network edge device, is your system going to block DDOS attempts automatically (with fail2ban for instance)), etc. Good idea with rate limiting on UFW. Try to take a look on the mentioned fail2ban too. It can do wonders combined with UFW. I consider it a mandatory resource on every of my servers, even if for SSH protection only (controlling login attempts).
If that's not clear enough: at this point I'm pretty sure your server is going to survive a flood of incoming traffic, but I'm not so sure about your router. If it's a consumer grade device, the answer is obvious - it's going to freeze when a DDOS is going to start. Too much traffic to handle. Either make it beefy to handle EVERYTHING possible and/or put a firewall before it, so it can put thru only the valid traffic. Otherwise you have a weak spot. As you see DDOS is also possible when targeted to a network edge, not only www servers.
Ok, let's not be paranoid. If you're going to have real trouble with DDOS your ISP is going to intervene. But anything below massive floods is on you. I'm just saying that most home routers are VERY weak to host any services behind them, so they're naturally a weak spot I'd be targeting first knowing your IP. This is why for anyone serving web services from your home it's worth to buy a professional networking equipment. Ten years ago I was selling that kind of stuff for 5k-40k USD a piece (like Cisco stuff). Now I have a $250 beefy Mikrotik which handles 10Gbps and does things on the Cisco level easily. I like where the networking market went! One of those good and cheap companies is also Ubiquity, which might be better know in the US than Mikrotik.
Have fun!
- ramsj 6y agoThis is incredibly helpful, thank you! I'm definitely going to add fail2ban and UFW rate limiting to start with, and look into a firewall on the edge in the unlikely event that GoAccess shows a deluge of traffic. I feel a bit better at least knowing now what the weak point is, so thanks!
- user_agent 6y agoYou're welcome. It's easy to forget about those things in the age of cloud computing ;)