Hi guys, I currently running a Hub-and-spoke topology and I only need remote endpoints to reach both a local DNS and an HTTPS internal web page in the HQ subnet.
So far I have enabled those subnets and ports and a implicit deny all at the bottom (on top of the implicit allow all).
My objective is reduce malware propagation and threats originated internally through the VPN (Ports scans, DDoS). Both Endpoints and HQ have Advanced licence with IDS set @ Prevention / Security
I was wondering what are you Site-to-site outbound firewall best practices? Any other tip to control and secure VPN usage?
Thanks!