Earlier quoted context omitted.
I currently rely pretty much exclusively on my Unifi gateway’s not-great IPS/IDS system, which allegedly receives updated threat intelligence feeds periodically. Outside of actual intrusion detection, I prevent my IoT devices (which are located in their own VLAN) from contacting the internet wherever possible, and entirely block any inter-VLAN traffic other than responses to connections initiated from devices residin…
> their own VLAN) from contacting the internet wherever possible, and entirely block any inter-VLAN traffic other than responses to connections initiated from devices residing on a “trusted clients network”, which hosts my phone, laptop etc. I am interested in this kind of setup but lack relevant experience. Is this stuff you set up in the stock Unifi admin pages?
What are Attackers after on IoT Devices?
21–29 of 29 posts
Re: What are Attackers after on IoT Devices?
#22Re: What are Attackers after on IoT Devices?
#23how are people performing intrusion detection on home iot devices?
If you’re running your custom homebuilt router, you can use IDS systems like snort[0] or suricata[1] It’s pretty fun to setup !, you can take any old desktop/laptop at your home and make them into your own custom router by running a linux or bsd instance on it. If you go this route, I would recommend suricata ids as you can setup more complex and sophisticated system easily, compared to snort. [0]( https://www.snort.…
One compromise would be to add an extra hop (like a raspberry pi ) to the IOT vlan, and install snort there. That way I could retain my primary router (currently Ubnt ERX).
Great tip!
Re: What are Attackers after on IoT Devices?
#24Earlier quoted context omitted.
If you’re running your custom homebuilt router, you can use IDS systems like snort[0] or suricata[1] It’s pretty fun to setup !, you can take any old desktop/laptop at your home and make them into your own custom router by running a linux or bsd instance on it. If you go this route, I would recommend suricata ids as you can setup more complex and sophisticated system easily, compared to snort. [0]( https://www.snort.…
Thanks this is a great idea. One compromise would be to add an extra hop (like a raspberry pi ) to the IOT vlan, and install snort there. That way I could retain my primary router (currently Ubnt ERX). Great tip!
Happy tinkering ^^ and merry christmas
Re: What are Attackers after on IoT Devices?
#25Earlier quoted context omitted.
I currently rely pretty much exclusively on my Unifi gateway’s not-great IPS/IDS system, which allegedly receives updated threat intelligence feeds periodically. Outside of actual intrusion detection, I prevent my IoT devices (which are located in their own VLAN) from contacting the internet wherever possible, and entirely block any inter-VLAN traffic other than responses to connections initiated from devices residin…
> their own VLAN) from contacting the internet wherever possible, and entirely block any inter-VLAN traffic other than responses to connections initiated from devices residing on a “trusted clients network”, which hosts my phone, laptop etc. I am interested in this kind of setup but lack relevant experience. Is this stuff you set up in the stock Unifi admin pages?
Re: What are Attackers after on IoT Devices?
#26Earlier quoted context omitted.
If you’re running your custom homebuilt router, you can use IDS systems like snort[0] or suricata[1] It’s pretty fun to setup !, you can take any old desktop/laptop at your home and make them into your own custom router by running a linux or bsd instance on it. If you go this route, I would recommend suricata ids as you can setup more complex and sophisticated system easily, compared to snort. [0]( https://www.snort.…
Thanks this is a great idea. One compromise would be to add an extra hop (like a raspberry pi ) to the IOT vlan, and install snort there. That way I could retain my primary router (currently Ubnt ERX). Great tip!
Re: What are Attackers after on IoT Devices?
#27Re: What are Attackers after on IoT Devices?
#28Earlier quoted context omitted.
Thanks this is a great idea. One compromise would be to add an extra hop (like a raspberry pi ) to the IOT vlan, and install snort there. That way I could retain my primary router (currently Ubnt ERX). Great tip!
Are you running stock firmware on the ERX and are you happy with it? Looking into potentially setting one up as well, any resources you could recommend for making best use of one?
I recommend the 2 vlan setup and disable switch0 for the best performance .
It's a step up from consumer routers with more powerful firewall, qos, and configuration .
Ubiquitis docs are great
https://help.ui.com/hc/en-us/articles/115002531728-EdgeRoute...
Re: What are Attackers after on IoT Devices?
#29Earlier quoted context omitted.
Are you running stock firmware on the ERX and are you happy with it? Looking into potentially setting one up as well, any resources you could recommend for making best use of one?
Yep I use the stock /latest 2.x firmware. It includes a wizard to set up the lans, nat and firewall . I recommend the 2 vlan setup and disable switch0 for the best performance . It's a step up from consumer routers with more powerful firewall, qos, and configuration . Ubiquitis docs are great https://help.ui.com/hc/en-us/articles/115002531728-EdgeRoute...