I decided (a long time ago!) To create a Minecraft server. Everything went well. I published it, and after 2 days the first griefers were there… Of course I saved everything. Now I'm a little afraid that if a hacker (someone who knows his way around) comes and hacked at the router, into our network with the help of the open ports, i.e. Into our network and then removed or deleted a few important data or whatever it did with it. Now I have set myself the goal of securing the network so that you can't ping another PC in the network from my PC (host computer where the server is running), but the other PCs can ping me.
Does anyone have an IDEA how to do it or suggestions how I can do it that you can't get into another PC (so hackers don't get any data)?
I'm thankful for every answer!
You could build a second network, so the PC would only have access to the second network, which uses the first network as Internet access.
Implementation: Connect Rasperry Pi, LAN and connect to the PC via Wi-Fi or vice versa (WLAN, LAN) or buy an antenna if necessary.
But it is probably enough if you only have the necessary ports open and your system is always up to date, people who do something like this really have no idea, script kiddis. They will hardly have the stamina to hack a well-protected, well-configured server. Install an IDS and be a good admin.
Sorry I'm a bit stupid, what do I have to do now and, above all, how do I do this when implementing it? And again sorry, what is an IDS or how do I do it?
You can google IDS, it monitors the requests made to your server and warns you when it detects an attack.
This would be a guide:
If you have a Rasperry Pi 3 / 3b / 3b +, you do not need a WLAN stick, it is already integrated.
If you have any questions, write to me privately.
Thank you write privately!