• 1 Post
  • 396 Comments
Joined 2 years ago
cake
Cake day: June 30th, 2023

help-circle


  • None of those speak to the reliability of iptables. They all sound like skill issues.

    In 15 years of network engineering iptables has been the simplest part.

    A layered approach with hardware firewalls is valid but when those firewalls get popped, looking at you Cisco, Fortinet, and PA you still want host level restrictions.
    Your firewall or switch should never be used as a jump host to servers













  • And on the whole your ISP knows what you are doing. It’s not entirely true unless you are in specific countries where you have a government CA certificate installed in your browser.

    A normal ISP can see you are accessing bing or google, but don’t know what you are searching for. They can see you are accessing Netflix, but can’t see what show you are watching. VPN providers will likely see the same information.

    More concerning is your browser, it will know what show you are watching and what thing you searched for on Bing or Google.