• 0 posts
  • 12 comments
Joined 3 years ago
Cake day: June 16th, 2023
  • I’ve been down this rabbit hole and it’s not a good option for standard matx or mini itx. Best I did was get a supermicro board and a supermicro 1u half-depth chassis. It was OK for a while, but the HDDs did not cool off very well.

    I’ve now not got a nas just as fast with a radxa rock 2a, a penta sata hat, some FPC cables between them and some cable bodging in a jonsbo n1 case. Drives are happy, less power consumed.

  • Running suricata on your wan interface is just generating a ton of noise and will be really confusing for you if you haven’t reviewed packet inspection alerts before. Not a lot of value in it unless you have many users “phoning home”.

    Just run it on the lan interface.

    Your approach of deny all until something complains is pretty much the most solid way to get a grip on security.

    I assess and recommend security practices for a living, and I would say the most important first step is understanding where your data lives and where it goes. Once you know that, the rest is relatively easy with the tools available to us.