IT jack of all trades. Licensed pillow fort architect.

  • 0 Posts
  • 3 Comments
Joined 1 month ago
cake
Cake day: February 18th, 2025

help-circle
  • To follow up on this, I’d look to network segmentation as another useful security barrier. I’ve just started playing around with VLANs, but the way I plan on setting things up is to have individual VLANs for services, management and IoT, with the LAN for all other user-land devices. On top of this you add strict firewall rules to what can talk to what, on which ports, etc. So all devices on the network can do DNS queries to my two DNS servers, for instance, but things from my services VLAN can’t reach anything outside of this VLAN…