Question Firewall, PfSense, Untangle...?

Dulanic

Diamond Member
Oct 27, 2000
9,957
581
136
OK so I guess I never really followed the trend of all of these various things.. I know some is software, then there are firewall appliances and 100 other things. But I have never gone beyond using a router besides swapping to DD-WRT etc... I always felt like my network was secure, but now all this shit is starting to worry me uggg.

So can anyone give me a basic idea of... why? Why should I use any of this? Where would I start? I guess I got old and content /w technology compared to when I was younger, but I have never been hacked, I have never gotten a virus, well since 92 or 93 when a friend gave me a infected floppy! I know how to build a PC, I know how to SSH, I know how to run a seedbox, I know how to run linux and mess/w CLI. So what am I missing? Why should I need anything else? I mean AFAIK my router (Orbi) won't let in traffic unless I route it. I route all 80/443 and a few various ports to my linux server. I use a reverse proxy through nginx to route all my traffic locally from https to local http docker containers so each is seperate from another... I use cloudflare for my DNS routing...

So again, what does a firewall appliance add for me? Why should I use one? I only port forward 4 ports, thats it... I use cloudflare for my DNS so people don't even know my local IP. Is it a paranoia thing, or am I missing something? I spent the past couple hours watching youtube shit etc... and trying to find out what I am missing, and I don't see much besides seeing where traffic flows, but most of my traffic is thorugh VPN for work. so that wouldnt show me much.
 

SamirD

Golden Member
Jun 12, 2019
1,489
276
126
www.huntsvillecarscene.com
You've actually got everything covered besides deep packet inspection, which your work router is probably doing if you're on a full tunnel. You could use an untangle box for that as I've heard it's great for it, but with the complexity of your network as it is, I think you'd run into issues getting it working smoothly.

NAT does a lot for security. That's why most of the bad stuff comes in via bad web sites over port 80 or via email. Generally if you don't go anywhere 'bad' on the Internet or just use it for singular activities, you're not going to have an issue.
 
  • Like
Reactions: mxnerd

Dulanic

Diamond Member
Oct 27, 2000
9,957
581
136
About what I expected.... I didn't think I should be worried, felt like snake oil for my use case. However, maybe once my son goes online more and one my MIL moves in (Oh god help me), I may need to worry about it more... but then I think all she does is use her phone to go on FB (ugggg) and the odds she pulls in something base is pretty low...

My Orbi came /w Netgear Armor, which I guess is similar, but I quickly got rid of that once they decided my power company was bad and I couldn't access it.
 

SamirD

Golden Member
Jun 12, 2019
1,489
276
126
www.huntsvillecarscene.com
A lot of it is snake oil, especially on the consumer side since they can be duped so easily. I'd actually be more worried about the MIL, lol. I'd put her on her own vlan just in case she starts causing havoc by clicking on everything that pops up. And who knows what is already infected on her devices. I would actually treat her as you biggest attack vector, imho.

And to be honest with you not having vlan capability on the orbi, I'd run a separate access point just for her that connects just for her and is vlan'd off from everything else. You want as straight and insulated pipe to the Internet as you can for her so that when (not if) she gets some bad stuff, you can just shut her down without it affecting everything else.
 

Dulanic

Diamond Member
Oct 27, 2000
9,957
581
136
A lot of it is snake oil, especially on the consumer side since they can be duped so easily. I'd actually be more worried about the MIL, lol. I'd put her on her own vlan just in case she starts causing havoc by clicking on everything that pops up. And who knows what is already infected on her devices. I would actually treat her as you biggest attack vector, imho.

And to be honest with you not having vlan capability on the orbi, I'd run a separate access point just for her that connects just for her and is vlan'd off from everything else. You want as straight and insulated pipe to the Internet as you can for her so that when (not if) she gets some bad stuff, you can just shut her down without it affecting everything else.

I do have a VLAN kind of, I can throw her on the guest Wifi :)