I run a virtualized instance of pfsense on my home server to function as my router. It works great, though one thing I have always been concerned with is port forwarding.
I have to forward a few ports, notably 21 and a port range for PASV mode. While I haven't had any issues yet, couldn't an attacker compromise the computer that has those ports forwarded to them? What are the best practices for making sure only the desired traffic (FTP) gets through?
I have to forward a few ports, notably 21 and a port range for PASV mode. While I haven't had any issues yet, couldn't an attacker compromise the computer that has those ports forwarded to them? What are the best practices for making sure only the desired traffic (FTP) gets through?