D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Routers was Re: [OT maybe] CVE-2016-5195 vs Amazon FireOS 5.6.2.0

 

On 24/07/2018 10:15, Simon Waters wrote:
The problem with routers is market failure.

It’s almost impossible to buy a broadband router which has decent security stance or 
updates, it is just it hasn’t been exploited much.

The recent example would be the “VPNFilter” malware. This is malware that runs on a 
broad selection of SoHo routers that use Busybox on Linux as their OS.

Typically, for broadband connections I would recommend keeping the openreach modem and sticking a pfsense box (either as a VM, or in one of the compatible appliances you can get e.g. from NetGate), configured to get it's WAN IP via PPPoE.

As I work as a consultant network guy I happen to have a Cisco ASA5505 doing the job now, cheap second hand eBay, but I generally still prefer a Pfsense box for the rich feature set and frequent updates.

--
The Mailing List for the Devon & Cornwall LUG
https://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq