Hacker News new | ask | show | jobs
by gojomo 5845 days ago
The software firewall is plenty. Make sure services on the ports that are open are as locked-down as possible: no brute-forceable passwords for SSH; conservative web server configuration and vigilant security updates of all software used.

Then spend the money saved on the hardware firewall on more frequent and offsite backups of crucial data.