Recommendations for sensible ruleset?

You are much braver than I.
I have not changed my default to blocked.
In this post Jon uses ASN to make a firewall rule.

Your first option of opening port 500 to the users that need it.
I find nothing wrong with that.
You could limit it to 1 County within red.

1 Like