My network has all the web ui stuff kept local and only accessible via OpenVPN on port 443, with fail2ban as well.
By the time a would-be attacker realizes it's not actually a webserver, they'll have exhausted most, if not all, of their public IP addresses on fuzzing for webserver vulnerabilities.
EDIT: and as a bonus, I can also just punch out through the firewall my work has on the visitor network with ease. All I needed was a second fail2ban rule for their static IP to deal with followup scans.