What are the basic security configurations to the router I should do from the Default one, thank you
IIRC the default settings are already secure. i.e. no remote access, enforced user-specified passwords. In other words, the user would have to make changes that reduced the security.
why not WireGuard for rule #2?Rule #1: The only port opened on the WAN side shall be the port the VPN server listens on! All outside access to other LAN services (HTTP(s), SSH, FTP, SMB, etc.) shall be done via the VPN tunnel. Disable WAN access to WebGUI and SSH.
Rule #2: "VPN server" means either OpenVPN (preferred) or IPSec server. The PPTP VPN server is not considered as secure.
Rule #3 (it is a result from applying Rule #1): Do not use Asus Android App!
Rule #4: Disable UPnP and WPS!
Rule #5: Change the name of the admin user from the default name "admin". Use strong password.
Just because it is too "young" I like it, but I am a 60+ "dinosaur" and do believe that the conservatism is a preferred approach when we deal with computer security. The OpenVPN has a long and successful history and a lot of operating experience.why not WireGuard for rule #2?
Why OpenVPN is preferred to IPSec?Rule #1: The only port opened on the WAN side shall be the port the VPN server listens on! All outside access to other LAN services (HTTP(s), SSH, FTP, SMB, etc.) shall be done via the VPN tunnel. Disable WAN access to WebGUI and SSH.
Rule #2: "VPN server" means either OpenVPN (preferred) or IPSec server. The PPTP VPN server is not considered as secure.
Rule #3 (it is a result from applying Rule #1): Do not use Asus Android App!
Rule #4: Disable UPnP and WPS!
Rule #5: Change the name of the admin user from the default name "admin". Use strong password.
Also, WireGuard is not an option in the GUI (although Instant Guard may be).Just because it is too "young" I like it, but I am a 60+ "dinosaur" and do believe that the conservatism is a preferred approach when we deal with computer security. The OpenVPN has a long and successful history an a lot of operating experience.
It depends on your priorities. Personally I prefer the OpenVPN as most mature solution, its security has been independently verified many times. It is able to create Ethernet tunnels. But it is slower and sometimes difficult to configure. Here you can read one of the hundreds comparisons made available in the Net. https://codilime.com/blog/ipsec-vs-openvpn-what-are-the-differences/Why OpenVPN is preferred to IPSec?
Thank you for all your recommendations.
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!