    I am setting up a Router Only platform and was wondering if there were best practices that could be recommended?

    I did look but really didn't find what I was looking for.

    This router will be located between the ISP's edge router and our CARP external pfSense firewalls.  50 up/down service.  Focus is on Website and DNS services.

  • Ok, just to clarify, not looking for anything in depth.  Just settings / sections to focus on, lessons learned, etc…

    I pretty much have it programmed and am willing to plug it in (after hours) and monitor for issues.  I'm posting my question because you guys ROCK and always seem to have a nugget that makes a big difference.


  • Anyone?  …

  • Switch to AON, then delete all the NAT rules.
    Make specific blocks for ntp, ssh, https to the box, then allow everything else.
    That's about all I can think of.

  • I figured it was that simple.


