Comment on [deleted]

<- View Parent
MigratingtoLemmy@lemmy.world ⁨7⁩ ⁨months⁩ ago

You seem to have a great setup. Since this comment touches on slightly advanced topics, I’ll ask this here:

  1. What use do you have for a WAF?
  2. How did you get your Android clients to trust your certificate? Do you use an MDM? Did you root your devices to access the trusted root store?
  3. Segmenting stuff with VLANs, subnetting and ACLs is a great idea, but do you also make sure that the firmware of the device is somewhat robust? Although I suppose you don’t have to worry about it if Sophos sends out regular updates, however I hate the idea of my switches and routers having to connect to the Internet, pass along credentials and the sort to be able to get updates.

Your measures seem to be focussed more on security than privacy - which is great! It’s my fault for not specifying it in the post, but I’d definitely like to know if you have done anything specific to keep your network private as well as secure.

Thanks for your wonderful comment - saved!

source
Sort:hotnewtop