Hey y'all,
I have a small network with opnsense firewall, a unify ap, some client in different subnets, vpn, DNS and some servers.
As I am completely self thought, I got everything to run reading the docs and forums, but I have no idea how to test if what I build is safe and stable.
Are there good up to date tools, or checklists one could follow to audit the different parts of the network (most important the opnsense config)?
What do you check if looking for security issues?
The network mostly relies on client separation through different subnets on different vlans, but I fear I dont understand how for example the vpn and the nas work together in detail to be sure there is no security implication I oversee.
Also: how do you handle client authentication for devices on the same subnet? I know IP/mac-adress ARP entries are easily spoofed and therefore not secure, but I haven't seen how to do it correctly
Thanks a lot, this seems logical, since I am not good enough in IT stuff to rely soley on the auth of the server and I want a second layer of protection to at least reduce the attack surface to known devices, i will look into a local VPN, but if this is also overkill for my skills, I may just buy a second AP for more WiFi networks. Would be beneficial for coverage anyway.