It depends, my box *IS* the router, therefore having a NetGear router in front of it is mundane and rickety.RBH wrote:I feel left out: despite having had a static IP for nearly 2 and a half years, I've not had one failed SSH login appear in my logs that wasn't my own doing. I run chkrootkit periodically (i.e. when I'm logged in finding things to do) and have never found anything.
I expect this is because my boxes are always behind a router that denies all packets that aren't specifically permitted (HTTP, DNS et al). Do you guys all connect directly, or something? Wouldn't a hardware router - just a bog standard Netgear one - be a good idea?
I might be talking out of my backside and apologies if that's the case, but this seems to be something of an obvious step to take.
Besides, I trust the security of a Gentoo box that I manage 10 fold over a homegrade NetGear router.
Yes, it's added security in the physical sense. But it's one more thing to break, one more thing to manage, and one more thing to go wrong. If your Gentoo box takes care of it, along with the added bonus of being able to log it, why put in a router at all?





