Unable to load image

[Networking Noob] So I installed an OPNsense firewall a few months ago and I'm getting massively high volume of connection attempts that are all being denied but it still seems like a lot. Is that normal?

I'd provide a picture but I'm too lazy

20
Jump in the discussion.

No email address required.

yeah those are just script kiddies or botnets.

you can scan the entirety of the IPv4 address space in a matter of minutes...and a lot of bots do.

IPv6 makes this much harder on paper but it's still realistically doable using heuristics.

If you keep your ports closed and only use something like Tailscale to get in, you'll be safe.

Even if you do open ports, using trusted HTTP servers like Apache and nginx as proxies are perfectly safe with a good password.

Jump in the discussion.

No email address required.

So what you're saying is that I should just open up all the ports on prod and see what happens?

Jump in the discussion.

No email address required.

No, you should run a tor exit node though.

Jump in the discussion.

No email address required.

Submitting the propsal to my boss right now as we speak

Jump in the discussion.

No email address required.

okay good, i was kinda worried for a bit lol especially since my title (network noob) is pretty accurate as this is my first time really screwing around with it and i was hoping to learn as much as possible

Jump in the discussion.

No email address required.

yeah when it comes to network security keeping your ports closed and unbound is like 80% of the battle. If there's an exploit on your system that can phone out, you're already kind of fricked.

Jump in the discussion.

No email address required.

I'm not too good with network shit but is it good enough to use password ssh if it's like 20 characters long and a specific long named login account with restricted privileges?

I did that before and I think it's good enough until I figured out proper ssh but how close was I to assraping

Jump in the discussion.

No email address required.

I mean it'll be OK if you've never reused the password but “key based authentication” is just so much better and avoids a whole class of attacks.

I would definitely recommend using the “overlay VPN” TailScale as well. It will let you access machines remotely without needing to open up ports on the internet.

I would watch some videos on “public key cryptography” to wrap your head around what you're doing. I always liked this explanation

Jump in the discussion.

No email address required.

Link copied to clipboard
Action successful!
Error, please refresh the page and try again.