Files
rick-infra/docs/security-hardening.md
2025-11-12 20:48:28 +01:00

401 B

Securing the VPS

Network Security

  • SSH Hardening: Password authentication disabled, root login disabled, key-only authentication
  • Firewall Configuration: UFW with deny-all incoming, allow-all outgoing defaults
  • Fail2ban: SSH brute-force protection with configurable ban times
  • Kernel Network Hardening: IP forwarding disabled, source routing blocked, ICMP redirects disabled