Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


wratterus

1687 posts

Uber Geek
+1 received by user: 678


#271852 29-May-2020 10:53
Send private message

Is it possible to setup remote access (from WAN side) into the new Spark Smart Modems and lock it down to one IP? I've not got one to play with to see if it can be done. Thanks!


Create new topic
wratterus

1687 posts

Uber Geek
+1 received by user: 678


  #2496473 2-Jun-2020 09:45
Send private message

Bump sorry - anyone know?




nztim
4012 posts

Uber Geek
+1 received by user: 2710

ID Verified
Trusted
TEAMnetwork
Subscriber

  #2496475 2-Jun-2020 09:52
Send private message

remote management is not a standard feature of a consumer grade router





Any views expressed on these forums are my own and don't necessarily reflect those of my employer. 


hio77
'That VDSL Cat'
13036 posts

Uber Geek
+1 received by user: 3896

ID Verified
Trusted
Lizard Networks
Subscriber

  #2496479 2-Jun-2020 09:57
Send private message

I'd have to double check, pretty sure we disable turning this functionality off though (I'm not running the public version due to firmware testing)

 

 

 

Regardless, It's not really a great practice, I'd recommend having a VPN and connecting in that way.. 





#include <std_disclaimer>

 

Any comments made are personal opinion and do not reflect directly on the position my current or past employers may have. 




halper86
555 posts

Ultimate Geek
+1 received by user: 156

ID Verified

  #2496483 2-Jun-2020 10:07
Send private message

wratterus:

 

Is it possible to setup remote access (from WAN side) into the new Spark Smart Modems and lock it down to one IP? I've not got one to play with to see if it can be done. Thanks!

 

 

Yes it is possible :)

 

Click to see full size


nztim
4012 posts

Uber Geek
+1 received by user: 2710

ID Verified
Trusted
TEAMnetwork
Subscriber

  #2496487 2-Jun-2020 10:12
Send private message

halper86:

 

Yes it is possible :)

 

Click to see full size

 

 

Make sure you untick "any ip address can remotely manage the smart modem" otherwise you have a death wish - is the external remote management https or http? I sure as hell hope its https

 

Personally, all our clients UTMs that we remote manage are via SSH only with private keys, non standard ports, and very limited IP addresses that are allowed





Any views expressed on these forums are my own and don't necessarily reflect those of my employer. 


hio77
'That VDSL Cat'
13036 posts

Uber Geek
+1 received by user: 3896

ID Verified
Trusted
Lizard Networks
Subscriber

  #2496495 2-Jun-2020 10:20
Send private message

nztim:

 

Personally, all our clients UTMs that we remote manage are via SSH only with private keys, non standard ports, and very limited IP addresses that are allowed

 

 

nonstandard ports always amuse me. 

 

Sure they stop a port knocker, but anyone looking for it will still find a SSH Daemon sitting on a nonstandard port.... 





#include <std_disclaimer>

 

Any comments made are personal opinion and do not reflect directly on the position my current or past employers may have. 


HP

 
 
 
 

Shop now for HP laptops and other devices (affiliate link).
nztim
4012 posts

Uber Geek
+1 received by user: 2710

ID Verified
Trusted
TEAMnetwork
Subscriber

  #2496497 2-Jun-2020 10:22
Send private message

hio77:

 

nztim:

 

Personally, all our clients UTMs that we remote manage are via SSH only with private keys, non standard ports, and very limited IP addresses that are allowed

 

 

nonstandard ports always amuse me. 

 

Sure they stop a port knocker, but anyone looking for it will still find a SSH Daemon sitting on a nonstandard port.... 

 

 

you still need to be coming from an allowed source IP address - the key thing is the private key set for each of our admins





Any views expressed on these forums are my own and don't necessarily reflect those of my employer. 


wratterus

1687 posts

Uber Geek
+1 received by user: 678


  #2496498 2-Jun-2020 10:23
Send private message

Thanks guys. Yes I know it's not best practice and maybe not normal for consumer grade routers, but a Netcomm NF18ACV for example allows this and it can be locked down to one IP, so it's not an awful option as a temporary stop gap measure. 

 

 

 

Thanks again.


Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.