8 ms·
Router Security
- yjftsjthsd-h 2y agoSo I think this is mostly reasonable advice, but I do have to question disabling ICMP/ping and IPv6. I'm not aware of any actual attack that ping allows? And IPv6 should be fine if you have a firewall (which I would rather expect any regular COTS consumer router to have). The link on that suggestion describes a very specific problem where your router is also your WiFi AP and uses the old approach of just shoving the entire MAC address in to its v6 address, but am I wrong in thinking that it would be weird to see that actually happening in a new router, where new is "still getting security updates"?
- bogantech 2y agoPeople who block ping should get swirlies
- LargoLasskhyfv 2y agoI'd rather swirl pings from the outside, from people who have no business at all to know about my internal infrastructures. Just GTFO.
- bogantech 2y agoIf your internal infrastructure is not internet routable nobody would be able to ping it anyway
- LargoLasskhyfv 2y agoMy comment wasn't about 'if's, but the thought of entitlement to mess around with other peoples stuff, or at least try 'look' at it. That deserves to be flushed down the drain, or the kitchen sink.
- yjftsjthsd-h 2y agoHow would somebody ping your internal network from the outside? Your firewall should block the ping getting past the router, regardless of the external interface responding. That said: Who cares? Even if you published exact list of every single IP on your network, it doesn't do an attacker any good, because again, there's a firewall between them and your devices.
- HeatrayEnjoyer 2y agoNetwork metadata is sometimes valuable all by itself. Investment firms buy satellite imagery to identify the number and models of cars in corporate parking lots, for better inferring internal business conditions. Frequency of pizza deliveries to the Pentagon revealed when major ops were taking place. A private network will ideally present as an opaque black box to the outside.
- deleted 2y ago[deleted]
- peanut-walrus 2y agoThis site is about securing consumer level routers. Nobody using one of those has a network where the internal layout is valuable to a bad guy.
- throw0101b 2y ago> A private network will ideally present as an opaque black box to the outside. Good luck (trying to) scanning a IPv6 /64 subnet. I've been in IT for 20+ years, and I have yet to find a situation where blocking ICMP(v6) caused more benefits than problems. Ditto for my home network: my last ISP had IPv6, and I had an Asus router which blocked unsolicited incoming connections: I could not SSH to any of my Macs from the outside (by default), but could ping if I knew the address (but good luck guessing 2^64). If you want to try to enumerate the equivalent of 4.3 billion IPv4 Internets that is a single IPv6 subnet, have fun.
- ectospheno 2y ago
- nickburns 2y agoWhat do you think about black box/IoT/whatever hosts on your LAN pinging external hosts with unknown payloads while you're not using them? Best security practice is obviously to block any/all ping not intentionally sent by you, whoever the local network admin is, or otherwise only whoever or whatever is explicitly allowed to.
- yjftsjthsd-h 2y ago> What do you think about black box/IoT/whatever hosts on your LAN pinging external hosts with unknown payloads while you're not using them? I think that 1. they can connect out via TCP or UDP much more easily than ICMP, 2. that blanket blocking outbound connections is a short path to madness, 3. if you don't trust a device on your LAN you should unplug it or isolate it, both of which are more effective and less disruptive, and 4. depriving yourself of the most fundamental network diagnostic tool in the name of security is cutting off your nose to spite your face.
- nickburns 2y ago1.) Carried out, that logic suggests not performing any outbound filtering because LAN hosts could simply find another way, protocol or port, out? I understand that 99.9% of LANs are configured default-allow LAN outbound. But the premise of your statement is untrue if the firewall is configured default-deny in all directions on all interfaces. 2.) I've not suggested 'blanket blocks' (nor 'blanket allows' for that matter). Specifically, both ingress and egress ICMP should be filtered by type code. 3.) In a zero trust model[1], every LAN device is untrusted. One should perform as much isolation and filtering as possible at all the relevant network layers. Network security is "disruptive" by definition. 4.) The second paragraph of my comment suggested that ping should be explicitly allowed for anyone/any device on the LAN legitimately utilizing it. [1] https://en.wikipedia.org/wiki/Zero_trust_security_model https://en.wikipedia.org/wiki/Zero_trust_security_model
- o11c 2y agoIf you haven't updated your kernel since 1998, you may be vulnerable to the Ping of Death. (I'm 90% sure this is the origin of this advice)
- fourfour3 2y agoI'd agree - IPv6 is only going to get more important from now. Especially with ISPs doing rollouts paired with moving v4 to address conserving mechanisms like CGNAT. The short list looks pretty sensible to me with those two exceptions. The long list gets a bit paranoid for me at the end - especially 32 onwards or so.
- b112 2y agoI'd agree - IPv6 is only going to get more important from now. Yes, but while not inaccurate, I've heard this since 2000.
- kstrauser 2y agoGoogle’s traffic is nearly 50% now: https://www.google.com/intl/en/ipv6/statistics.html https://www.google.com/intl/en/ipv6/statistics.html Are there any cell providers that don’t use native IPv6? Verizon definitely does. I’d be surprised if any big ones don’t.
- wiml 2y agoYeah, in an era when mobile device users are a pretty major customer segment, and they're essentially all native-v6, it's weird to dismiss it.
- b112 2y agoCustomer segment? This is a thread about consumer edge routers. That is, individual people, not corporate connectivity. "Customer segment" is a meaningless term here, Grandma doesn't care about customers. A lot of this is regional, sadly. No mobile phone provider in Canada/US would not allocate ipv4 access. It'd be madness. Too many unreachable endpoints. In fact, no endpoint anywhere in US/Canada can get by without ipv4, but many don't care about ipv6. There will be a point where that changes, but certainly not yet. So why does Grandma care if her router can do ipv6? All major companies world wide, all consumer end points world wide support ipv4. And in US/Canada, everyone does ipv4 unless they are on some political campaign against it. And it will hurt them.
- chgs 2y agoI think the problem with ipv6 is that people may enable firewall rules on ipv4, but completely forget about v6. With auto configuration you may be leaving yourself wide open. By all means enable ipv4 and v6 but remember to ensure you firewall both.
- wmf 2y agoConsumer routers should be default deny so if you don't add any rules you're safe.
- chgs 2y agoOn the outbound? My IoT network has a very controlled list of allowed outbound targets in the ipv4 world. If I blindly enabled IPv6 I’d have to ensure I protected against that too. Of course I also do things like intercept UDP/53 and nat it to my pihole as some devices have hardcoded dns servers, which many purists claim is an “ugly hack”.
- RealStickman_ 2y agoNormal consumers have all outbound traffic open anyways.
- globular-toast 2y agoWhat router software makes it easy to enable the firewall for ipv4 but leave ipv6 completely open? Are these routers without a real firewall at all that just rely on NAT as a pseudo-firewall?
- RecycledEle 2y ago> I do have to question disabling ICMP/ping Ping is a tool I love, but it also allows a bad guy to discover your router with tracert. Disabling icmp/ping responses prevents that.
- kstrauser 2y agoThat doesn’t get you anything. The bad guys assume every IP owned by an ISP has a customer router on it.
- Fnoord 2y agoI recently installed fiber (IPv4 only via this ISP, :/). The moment I connected OPNsense I got all kind of connections on the usual suspect ports. The whole IPv4 address space is scanned within an hour. This doesn't hold up for IPv6 though. This address space is so large, you can run SSH server on it without it ever getting scanned.
- throw0101b 2y ago> Ping is a tool I love, but it also allows a bad guy to discover your router with tracert. And? So some random IP, which is already known to be in the range of a residential ISP (because of ARIN/RIPE/ASN records), is pingable. So what?
- kstrauser 2y agoThat’s dumb advice and makes me question anything else they’d recommend. A ship is safe in harbor, but that’s not what a ship is for. If a router can’t handle IPv6 in 2024, throw it out the window.
- ssl-3 2y ago> I'm not aware of any actual attack that ping allows? DoS. There may have been a time once, when some of us may have been minors, that using a command like "ping -f -s 1000" from a well-connected host to a specific dialup user's IP address may have been able to completely obliterate their connection to the point that it would fuck up their network stack enough to reliably disconnect their PPP session and send them back into redialing the local ISP's busy modem pool. Maybe. And that kind of thing might still work today for devices that respond to ICMP pings. (I'm no longer an angsty teenager so I wouldn't know, but angsty teenagers are still things that get made in factories every day.)
- globular-toast 2y agoHow much does disabling or filtering ping do to help, though? Won't they still saturate your downstream and put load on the firewall?
- ssl-3 2y agoThe downstream side may be relatively small and easy to saturate, but the upstream side is [typically] even smaller and easier to saturate.
- neilalexander 2y agoBelieve it or not, blocking ping at your router would have done absolutely nothing to prevent this, as those packets would likely have still been delivered to the router and possibly saturated the link anyway, regardless of whether the recipient was dropping them or not. That is why nearly all DoS flood-style attacks are UDP-based — unless you are behind a CGNAT or an upstream restrictive firewall, you can't really opt out of those packets being routed to you.
- ssl-3 2y agoBelieve it or not, blocking pings at the router prevents said router from responding to pings, and this eliminates 50% of the problem on symmetric connections (and >50% on asymmetric connections). Don't let perfect be the enemy of good.
- Havoc 2y agoI’m much more comfortable use something like opnsense. Router manufacturers seem to just yolo it judging by backdoors etc found frequently > At some point you will go a year or two, or more, without any updates. That's when it is time for a new router. Is that good advice? Swapping a mature and patched platform for whatever device with new A.I. enabled half test beta firmware that just got rushed to market?
- yjftsjthsd-h 2y agoYes. If the thing sitting on the external side of your network, exposed to the open internet, isn't getting security patches, then it's time to replace it with something that is.
- BobbyTables2 2y agoDoesn’t even have it be on the external side. Non-updated LAN device making outbound connections puts the entire LAN at risk…
- BenjiWiebe 2y agoHow much is exposed? How much attack surface is Internet accessible on, say, a 5 year old netgear router? I guess I think it might be quite low.
- yjftsjthsd-h 2y agoIf you've port scanned your public IP(s) and there are zero open ports, then you only have to worry about bugs in the TCP/IP stack, services listening on UDP, and intentional backdoors (which shouldn't happen but keep popping up). If there are exposed ports, then there's even more attack surface. Edit: actually I forgot the like of UPnP so that's not exhaustive.
- transpute 2y agoDoes OPNsense GUI support configuration of the router as a VPN client to commercial servers? Most of the docs cover site-to-site VPNs.
- ajb 2y agoI get reducing your attack surface, but to what extent do modern devices still trust the network by default? Laptops and phones have to assume that the WiFi network is not under the control of the user. I guess printers etc assume they are in a trusted network?
- hi-v-rocknroll 2y ago0. Don't use a garbage retail or ISP-provided, closed-source router. Here's one option: https://shop.opnsense.com/product/dec740-opnsense-desktop-security-appliance/ https://shop.opnsense.com/product/dec740-opnsense-desktop-se... 1. Suggesting turning off IPv6 is ridiculous security theater. It's a known quantity deployed at scale. Dual stack or turn in your "hacker cred" card now. ;)
- mito88 2y ago€749,00 gulp
- bpye 2y agoPerhaps a more affordable option, find some hardware that runs OpenWRT [0]. [0] - https://openwrt.org/toh/start https://openwrt.org/toh/start
- kQq9oHeAz6wLLS 2y agoI run a cheap tiny PC and OpenBSD, if you want a more hands-on config process.
- bpye 2y agoMaybe more fun than practical, given the performance you'll see [1], but OpenBSD has a mips/octeon port which runs on some of Ubiquiti's hw [0]. [0] - https://www.openbsd.org/octeon.html https://www.openbsd.org/octeon.html [1] - https://kernelpanic.life/hardware/openbsd-router-benchmarks.html https://kernelpanic.life/hardware/openbsd-router-benchmarks....
- transpute 2y agoFanless 10GbE is pricy. OPNsense is based on FreeBSD, runs on $100 micro PCs with PCIe quad NIC, https://www.servethehome.com/introducing-project-tinyminimicro-home-lab-revolution/ https://www.servethehome.com/introducing-project-tinyminimic...
- transpute 2y agoWi-Fi router security could be improved by per-device passwords and micro-segmentation, as seen in OSS https://github.com/spr-networks/super https://github.com/spr-networks/super. VLAN for insecure IoT devices is a fallback.
- fulafel 2y agoWow, disabling IPv6? Yeah, turning off your internet may increase security but this is pretty nihilist advice. Add "disable IPv4" too.
- guilhas 2y agoHome users, or people serving ipv4 only, have no use for ipv6 Some ISPs, and routers, don't even process it correctly To avoid headaches, and extra work, disable ipv6
- fulafel 2y agoPeople incl home users have a lot of uses for e2e connectivity. But it's of course a self-fulfilling prophecy, when we make the internet more like TV ("receive only") the network effects curve down and people use less of it.
- janwillemb 2y agoAlso, use two routers in serial. One is provided by my isp, the other is my own. The chances of both getting compromised at the same time are lower.
- kstrauser 2y agoFor peak security, unplug one of them.
- deleted 2y ago[deleted]
- kkfx 2y agoThe real main point is: how much control users of commercial routers could have with a reasonable effort (I mean, I know most are GNU/Linux machines, where the OEM sometimes respect the GPL providing the sources but there is no easy custom build and rom flash with very few exception like the little GL.iNet devices). If the router is just a person mini-computer with some *nix OS and it's config, directly tied to a media converter from the ISP it's a thing, otherwise it's essentially next to impossible doing most of reasonable actions including properly probing the internet-side for a small potatoes audit. Some countries have mandatory free router choice, like Italy (curiously), where at least the user is allowed by law to run it's own router so ISPs are obliged to give all settings, VoIP included, without making like of their customers needlessly harder, but that's not true in most countries. Some ISPs (i.e. Orange France) run arbitrary custom solution to makes people life harder if their put another router behind the ISP provided one. People choice is very limited even for those who would know and want to run their own home/SOHO LAN.
- commandersaki 2y agoSo what is the reality with respect to router security? Looking at https://routersecurity.org/othersgripeonrouters.php https://routersecurity.org/othersgripeonrouters.php some 2019 article headline says "the worst is yet to come." Virtually all routers do not have an admin interface exposed on Internet facing side, moreso due to CGNAT. What threats from routers are we seeing in the wild that are actually having an impact?
- neilalexander 2y agoDisabling IPv6 in 2024 is bad advice. IPv6 adoption is undeniably on the rise. Better advice would be to ensure that the IPv6 firewall is configured to sane defaults, i.e. allow established/related, drop invalid, reject unexpected, just like you'd expect an IPv4 firewall to be. Disabling ICMP is also bad advice. If you want Path MTU discovery to work, you need ICMP. If you want to be told about TTL exceeded (which usually shows a routing loop), you need ICMP. If you are uniquely worried about ping for some reason, then block those ICMP type numbers specifically, not the entire protocol.
- johnklos 2y agoIt really is difficult to take this seriously when they suggest disabling IPv6. There are already quite a good number of ISPs that use CGNAT for IPv4, which often means that connections die or are intentionally killed in short amounts of time, which can be a huge PITA for certain uses (interactive shells, large downloads, et cetera). Take Starlink for instance. When on IPv4, you really feel like you're on a janky network that's being rebooted every hour or two. After Starlink enabled IPv6, all sorts of things no longer required babysitting and restarting. The quality difference between IPv4 via CGNAT and native IPv6 is huge and noticeable, even for people who have no idea what's going on behind the scenes. Perhaps regular people can naively suggest turning off IPv6 because they don't know any better and they believe the FUD they've heard and read about, but if you're putting up a web site claiming to have good advice and you put more weight on FUD over real world experience and solid reasoning, then I'd be suspicious about everything they've written.