Alta should have a default rule that is set on all of their WAN facing devices (route10) that limits ssh, http and https to alta only IP ranges.
currently im able to hit the IP my WAN gave me and I see the alta message, which is not great if someone wants to do a DDOS or figures out issues with the device itself and attacks.
limiting the mgmt to specific Alta’s IPs locks things down further.
potentially someone might want to open that traffic to specific IPs out there but should default be denied.
over the weekend I was able to hit from outside my route10 both https and ssh to it.
now I cannot.
would love to see in read only mode the rules that are applied to the device to be in the known.