ESET Proxy Hardening

Hi Forum!

We use squid proxy in our dmz for remote users to talk to esmc without vpn.

log files show, the service is attacked very often (no surprise opening that port in the internet).

Anyone got any ideas hardening the proxy eg

1. by using a different port

2. by using the Agent-Certificate to authenticate against the proxy service? Could the not be done by just adding the CA-cert to squid?

Thanks in advance!


