32. Linux and Network Hardening
Chala mitrano, attack kasa hoto he aapan khup baghitla. Aata ulta vichar karu: server itka majboot kasa karaycha ki attack yashasvi ch hou naye? Yalach "hardening" mhantat – ghar la chaan kulup, CCTV ani majboot darwaja lavne. Ya chapter madhe SSH lock karne, fail2ban, firewall, updates, users ani permissions, Apache/Nginx hardening, VPN ani IDS (Snort/Suricata) shiku. Pratyek step tumchya Chapter 6-16 madhlya EC2 server var lagu hote. Samjla ka? Chala!
What you will learn in this chapter
- Hardening principles: least privilege, attack surface, defence in depth
- SSH hardening: keys only, no root login, fail2ban
- Host firewall with firewalld and ufw
- Patching, users, sudo, file permissions and services
- Web server hardening for Apache and Nginx
- Network hardening: segmentation, VPN, and IDS/IPS with Snort and Suricata
Before you change SSH or the firewall
Always keep your current SSH session open while you test a new setting in a second terminal. If the new login fails you can still fix it from the first session. Test on a lab VM or a fresh EC2 instance first, never directly on a live customer server.
Concepts in this chapter
- 32.1Hardening Principles
- 32.2SSH Hardening and fail2ban
- 32.3Host Firewall: firewalld and ufw
- 32.4Patching, Users, Permissions and Services
- 32.5Web Server Hardening
- 32.6Network Hardening: Segmentation, VPN and IDS/IPS
- 32.7Red vs Blue, Project and Real Incidents
The chapter recap is at the end of the last concept page.