SayCyberOnceMore

  • 6 Posts
  • 157 Comments
Joined 2 years ago
cake
Cake day: June 17th, 2023

help-circle







  • Kinda Scenario 1 is the standard way: firewall at the perimeter with separately isolated networks for DMZ, LAN & Wifi

    The Firewall provides a proxy for anything in the DMZ, so all the filtering is done there and not on the DMZ device(s).

    GeoIP on the firewall, so anything that’s opened to the interweb - inc. inbound VPNs can only come from selected regions.

    Fail2Ban on DMZ device(s), to prevent repeated login attacks.

    Wifi has multiple SSIDs to block / permit outbound access to the internet (IoT stuff), LAN (Guests), etc.

    Then regular updates / patching / backups…













  • I’ve done similar with an old Android tablet. Installed Fully Kiosk Browser to display the dashboard AND read the battery level - above 75%, switch off power…

    But… automations only trigger when going past the threshold once, so if there’s a random issue where HA doesn’t see the battery drop below 10%, (had that happen a few times in the past), then I also have multiple triggers for 5% and 2%… to turn the power back on again 😉