Consumer appliance here (Linksys), my needs are fairly simple right now. I run no servers that need to be seen from the outside world, so simply disabling WAN requests entirely and forwarding a few port ranges works just fine, and keeps me safe from the more mundane crap out there (IE exploits aside). I can see where I will run into the limits of how many port ranges can be forwarded as I add more devices, I guess I'll cross that bridge when I come to it.
|