Comment on Internal network monitoring

thelittleblackbird@lemmy.world ⁨2⁩ ⁨weeks⁩ ago

Segment the network as much as feasible, forbid the communication between the segments via FW rules, and set an alert when those rules are triggered.

For example: your dmz should never initiate any type of communication with your lan segment, your lan segment should not try to access services outside ports 80/443, your dns should log all resolutions performed and it would be nice to have at least a black list.

None of them should have dns over tls, and for specific hosts and networks segments, new domains with very looong active but idle connections should trigger an alert.

My personal opinion is that for a homelab is not realistic to perform a dpi to check that there is not an active attack ongoing, neither from the raw processing power, either from the human effort side, your best chance is to alert when something unusual is happening and then adjust your rules of the are false positives

original
Sort:hotnewtop