[Question] Protecting outdoor LAN port from infiltration? - eviltoast

If you have an outdoor Ethernet port—in my case with a WiFi AP connected—how can you go about protecting your network from somebody jacking in?

Is there a way to bind that port to only an approved device? I figured a firewall rule to only allow traffic to and from the WiFi AP IP address, but would that also prevent traffic from reaching any wireless clients connected to the AP?

Edit: For more context, my router is a Ubiquiti UDM and the AP is also Unifi AP

  • jet@hackertalks.com
    link
    fedilink
    English
    arrow-up
    2
    ·
    4 months ago

    Some devices will let you specify a list of allowed MAC addresses per port. I believe ubiquity does allow this.

    Some devices will have a whole port security protocol, if they see a Mac address that hasn’t been authenticated, the port is put into violation requiring an admin to physically validate it after visiting the port to make sure nothing nefarious happened. I do not believe ubiquiti has this