My unifi controller runs in a VM, The APs have no access to anything but that VM. Wondering if I should limit outgoing traffic from my controller.
Possibly even proxy the traffic via something able to do SSL strip/re-encrypt and monitor that traffic with an IDS.
However speaking to some people at work who have had experience in the past, seems most malware (and that includes IOT devices) doesn't bother validating certificates or things like ESNI and (validated) DOH, so there's a lot you can find out without breaking TLS, due to the lazineess/incompetence of the malware writers.