Greetings everyone!
Something I don’t like when I setup networks is that in firewalls there is no feature directly to disallow connection from lan clients to Gateways. A simple button, with a laconic but clear description about it’s function. I come often into disallowing lan networks direct connection to web interfaces of basic gateway and node machines. Seen that in big hotels and organizations too. For example: I join a big transit station, I use a basic and harmless tool like arp-scan and in a few secs and assuming by the network alphanumerics I get into gateway’s web interface, the most ethically easy way. No special tool, no scanning e.t.c
I was thinking that software firewall solutions or related appliances should make this path fool proof with a explanatory description. Alas many sysadmins just buy expensive and bleeding edge equipment instead of toggling features and doing basic iptables rulesets. Perhaps they are not sysadmins at all and they trust sale leaflets and help boards.
I am talking about SoHo and Small organizations - Hotels big or small, Local dpts of Administration and local authority establishments. I haven’t ethically found out accidentally this elsewhere. This must be ISP router > Machine with firewall > LAN. Perhaps small routers -/+ mostly not managed or vlan capable, updated last century.
I am against also the firewall solutions to offer connection to commercial vpn services. I usually do kill switches on the lan machines or between them and the firewall solutions. With or without vpn. Helps me for many other reasons, outside this threat’s purpose.
So this feature of mangling off the connections to the gateway, as described above and in simple buttons of toggling on/off or something similar sounds reasonable? What are your thoughts about it? What else an admin is to do in the most efficient and fast ways?