5
Asuswrt-merlin + ClamAV (self.selfhosted)
submitted 6 months ago by Dust0741 to c/selfhosted

Any way to use ClamAV on an Asus router running merlin?

top 10 comments
sorted by: hot top controversial new old
[-] eth0slash0 6 points 6 months ago

But, why?

ClamAV is a scanning engine that uses a database and heuristics to detect an infection.

Are you looking for an Anti Virus Scanner, or Intrusion Prevention System?

[-] Dust0741 1 points 6 months ago

I guess I'm not 100% sure. Which would I need/which would increase security?

[-] eth0slash0 5 points 6 months ago* (last edited 6 months ago)

It sounds like you're looking for intrusion detection or prevention rather than antivirus.

Great list here https://github.com/sbilly/awesome-security#ids--ips--host-ids--host-ips

However it's likely that these do not run on asuswrt-merlin out of the box and may require additional setup or hardware.

You may even be good enough by using the built in firewall on the router interface and making sure no ports are open/forwarded.

[-] Dust0741 1 points 6 months ago

Yea I think intrusion detection is what I want. I'll have a look at that page, but I may end up just going with pfsense one day.

[-] SheeEttin 4 points 6 months ago

If your goal is network security, you'd probably be best off deploying something like Security Onion.

After the basics like having a firewall, making sure you have the strongest wireless encryption your devices support (WPA3 probably, WPA2 if 3 isn't supported), stuff like that.

[-] Dust0741 1 points 6 months ago

Okay this seems neat. Would this be usable for a home network?

[-] [email protected] 2 points 6 months ago* (last edited 6 months ago)

ClamAV is an anti-virus software that you would run on end-devices to scan files, an intrusion detection scans network traffic to detect anything potentially malicious. I don't know your exact router model but I suspect it's way too weak to run intrusion detection. If you have a switch that's capable of mirroring you could use that to utilize a more powerful machine to scan network traffic.

[-] Dust0741 1 points 6 months ago

Ah gotcha. Makes sense. Would something like WatchYourLAN or Pi.Alert be good?

[-] [email protected] 2 points 6 months ago* (last edited 6 months ago)

It's a good way to see if someone has cracked your WiFi password for example so why not. Doesn't add much security but better than nothing.

[-] RegalPotoo 1 points 6 months ago

What do you mean by "increase security"? Security isn't a thing where you get +5 points for every antivirus you have installed - it's about risks, and how you mitigate them. A perfect antivirus isn't going to protect you if you have a crappy password on something you forgot about, or if you are running software with a serious security vulnerability.

this post was submitted on 25 Oct 2023
5 points (72.7% liked)

Selfhosted

36999 readers
312 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 11 months ago
MODERATORS