Dang! that's awesome
pretty solid config!! I like how a unique sessions is being made automatically within 15 minutes and I like how the web filter works and TNDA as well
So if I understand you correctly, basically
IF any malwares or spywares or any users attempting to access the internet they simply got blocked automatically right?
Although this kind of setup is kinda overrated and unnecessary for casual home users like me but this is perfectly fit for doing serious stuff like you do!! I like it! thanks for sharing you config
PS : I simply agree with Bora
Well the setup is solid and is used amongst better organized companies who deal with large amounts of private costumer data.
If i would not maintain some level of security then if things go wrong my clients would sue me so hard that i do not taste the difference anymore between ##### and French fries after they are done with me.
And i am not sure what you mean with overrated? But the security is not that tight, i could switch a few things around and make it fortnox however the biggest plus to this setup is that it has so called self recovery.
Lets assume that the security fails for whatever reason and rootkit/killsystem.lmao is being applied then it still would have no effect as the self recovery feature within the session control will instant wipe the client PC and deny any system change.
So incase of a large security breach or a system error the Admin server can correct it right away and deal with it.
And yes due to the 15 minutes session expire time you basically have a hardened virtual box that does not allow any intrusion & malwares penetrate the system as the system itself just does not allow any data transmission unless specific specified in the root config.
So to explain it even better it is a closed network that by default will block and deny any contact with the outside world unless specific specified. Or in a funny way i created my own little cyber North Korea lmao.
But yeah the system is solid, hardened and virtually hacker proof.
And yes it is NOT configured for home use as it is configured for a specific goal and a pre-defined set of work options.
Cheers