My network has all the web ui stuff kept local and only accessible via OpenVPN on port 443, with fail2ban as well.
By the time a would-be attacker realizes it’s not actually a webserver, they’ll have exhausted most, if not all, of their public IP addresses on fuzzing for webserver vulnerabilities.
EDIT: and as a bonus, I can also just punch out through the firewall my work has on the visitor network with ease. All I needed was a second fail2ban rule for their static IP to deal with followup scans.
My network has all the web ui stuff kept local and only accessible via OpenVPN on port 443, with fail2ban as well.
By the time a would-be attacker realizes it’s not actually a webserver, they’ll have exhausted most, if not all, of their public IP addresses on fuzzing for webserver vulnerabilities.
EDIT: and as a bonus, I can also just punch out through the firewall my work has on the visitor network with ease. All I needed was a second fail2ban rule for their static IP to deal with followup scans.