• rehydrate5503@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    2 年前

    How can you ensure this is done? There are so many devices that need to connect to the internet and some that require access to other network devices to function.

    • Semperverus@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      edit-2
      2 年前

      You basically need to employ network engineering level security - very tight firewall rules, use NAT where it’s available (IPv6 removes NAT, which ipv6 apologists will tell you is a good thing - they’re wrong, as it removes per-service level control and moves it out to per-device/per-NIC), and punch very specific holes to grant access where needed.

      Prevent north/south traffic entirely, limit east/west traffic heavily