That's true, if the thing has no network capabilities whatsoever then I'm pretty much golden. And using iptables is clever too, knc1. Actually, I could probably blacklist every destination IP address other than the local network and a machine I can connect to via ssh, but I'm not too sure how capable my hypothetical device would be.
And thank you, eureka, that's a very good point. I can probably check the completeness of the provided solution by running tcpdump on the router. The router has linux on it, like my ideal would-be device, and my computer.
|