Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That DMZ is fine already, assuming they can't start hacking your routers.

What you ideally want is network segmentation, use VLANS and put devices in their isolated network, only allowed to talk to the router/firewall, which only allows incomming traffic and doesn't allow the web server to initiate connections to the internet, except for NTP, software updates and DNS (fixed ips).



Yeah I actually had a Ubiquiti Edgerouter doing this but I was never confident enough it was set up properly, hence the other solution.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: