Technical Discussion
  >> Home Networking, Internet Connection Sharing, etc.


Register (or login) on our website and you will not see this ad.


Pages in this thread: 1 | 2 | [3] | (show all)   Print Thread
Standard User prlzx
(experienced) Tue 16-Jul-24 13:28:48
Print Post

Re: Draytek 2925 port forwarding


[re: ian72] [link to this post]
 
Personally for incoming connections I'd rather just block everything by default then create an IP allow list consisting of addresses and networks I manage or know about.

Other than that incoming access (particularly for private storage or content) is by (keypair-based) VPN only.

It's all rather tangential to the OP's question anyway but for the sake of technical correctness, the most dangerous sources are those controlled under botnets which by definition are not tied to any single geographical regions.



prlzx on Zen: FTTC (VDSL) at ~40Mbps / 10Mbps
with IP4/6 (no v6? - not true Internet)
Standard User DFScale
(member) Tue 16-Jul-24 14:45:56
Print Post

Re: Draytek 2925 port forwarding


[re: ian72] [link to this post]
 
In reply to a post by ian72:
It isn't false comfort. By blocking by "country" you are able to exclude a large percentage of hackers from Russia and China. Some will still get in. Some people in allowed countries will not be able to access. But, as a blunt tool it can help in giving a level of protection that is probably about 80-90% accurate.

That's false comfort exemplified.
Standard User DFScale
(member) Tue 16-Jul-24 14:46:47
Print Post

Re: Draytek 2925 port forwarding


[re: prlzx] [link to this post]
 
In reply to a post by prlzx:
It's all rather tangential to the OP's question anyway but for the sake of technical correctness, the most dangerous sources are those controlled under botnets which by definition are not tied to any single geographical regions.

Exactly.


Register (or login) on our website and you will not see this ad.

Standard User ian72
(eat-sleep-adslguide) Tue 16-Jul-24 14:46:57
Print Post

Re: Draytek 2925 port forwarding


[re: DFScale] [link to this post]
 
I disagree. It is providing a level of protection - it is by no means perfect but it will reduce risk to some extent. Some mitigation is better than none.
Standard User nofappingway
(member) Tue 16-Jul-24 15:04:57
Print Post

Re: Draytek 2925 port forwarding


[re: ian72] [link to this post]
 
Agreed. No one is stating using Country Blocks is the silver bullet but it does absolutely reduce the surface area of attack considerably.

Edited by nofappingway (Tue 16-Jul-24 17:36:26)

Pages in this thread: 1 | 2 | [3] | (show all)   Print Thread

Jump to