3 ms·
Oh you don't need a firewall then? I guess accessing a routers web interface from the WAN is a-okay
by staringback 4y ago
Oh you don't need a firewall then? I guess accessing a routers web interface from the WAN is a-okay
- jraph 4y agoMy shitty cable modem which is also a router does not expose its web interface to the world by default. I don't understand why you'd need a firewall if - you trust devices on your network (yes, big if, but even then: the only reachable ports of a machine from the outside are those explicitly open to the outside, most stuff listens to 127.0.0.1 anyway) - you only configure your NAT to forward ports you would open on your firewall
- staringback 4y ago
- jraph 4y agoWhat's with the attacks?? I make sure what I build supports IPv6 (and I'll use tunnels if it's what it takes) but I can't make the only cable ISP available at my place support IPv6. I wish it did. I wish I didn't have to use its garbage hardware.
- sph 4y agoMy shitty router also firewalls incoming IPv6 connections by default, unless I manually allow them per-device, so I don't get your point.
- jraph 4y agoMy point is lzaaz's one https://news.ycombinator.com/item?id=33897568 https://news.ycombinator.com/item?id=33897568 I didn't think of my cable modem as a firewall. Maybe technically it has one to provide the feature of blocking access to its web interface from the world, or maybe it just listens to the right network. I don't know, but for all intent and purposes, setting up a firewall myself does not seem necessary. To be fair, I was also a bit annoyed by staringback's phrasing.
- lzaaz 4y agoMy router's httpd listens on the LAN not the WAN unless I tell it to. This is unrelated to what I said.