MEDIUM
The situation is rated as MEDIUM severity because while it does not directly involve a vulnerability, the lack of proper network segmentation can expose sensitive data to potential threats. In homelab environments, this could mean that personal devices or IoT devices are inadvertently connected to work resources, increasing risk.

The query revolves around enhancing network security for remote work setups by potentially using multiple access points (APs) and routers. The user's current setup includes a Verizon Fios internet service, a combination of a VPN/Remote Desktop for secure connections, and Microsoft 365 for collaboration. Adding an additional router and AP could segregate the home network into personal and work segments, reducing the risk of personal devices affecting the security posture of remote work tools like RDP or sensitive data handled by Microsoft 365 applications. This segmentation can improve isolation between different types of activities and devices, which is crucial for maintaining a secure environment when working from home. However, the effectiveness of this approach depends on proper configuration to ensure that each segment remains isolated and securely connected.

Affected Systems
  • Verizon Fios Internet Service
  • Microsoft RDP
  • Microsoft 365
Remediation
  • Set up a dedicated router for the remote work environment using firmware updates from the manufacturer's latest version to ensure security patches are applied.
  • Configure VLANs or separate SSIDs on each router to isolate personal and work networks, ensuring that devices connected to one network cannot access resources on another.
  • Implement strong encryption (WPA3) and complex passwords for both routers' management interfaces and Wi-Fi connections.
  • Regularly update the firmware of all networking equipment and monitor for security advisories from manufacturers.
Stack Impact

The impact on common homelab stacks would involve configuring network devices like routers to isolate work from personal networks. For example, setting up a separate VLAN or SSID for work purposes using firmware versions such as the latest available for routers like Netgear or TP-Link can help in maintaining security.

Source →