- The default rules and settings protect 100% from outside.
- From inside, your best enemy is yourself.
- Ignoring internal devices, if the goal is to secure Router Access, reserve 1 phisical port for MGMT if some settings go wrong...
- No MGMT by wifi.
- For MGMT use two-factor autentication.
- No pptp or other buggy VPN for remote MGMT...
- Do not use admin, root, or other shi~~y usernames for the Rotuer configuration.
- Do not delete admin, just leave it enabled with complex password and NO RIGHTS profile.
- If you know how to work around something security, don't assume you're the only one who knows how.
- If you DON'T know how to work around something security, assume there's definitely someone who does.