CRITICAL INFRA
Loading critical CVEs…
ALL EXPLOITED
Loading…

Linux server hardening 2026: complete guide

1. SSH lockdown

2. iptables / nftables firewall

3. CrowdSec (modern fail2ban alternative)

Distributed threat intelligence community. Detects attacks and syncs bad IPs globally.

4. Automatic security updates

unattended-upgrades configured strictly for security only.

5. CIS Benchmark + Lynis audit

Run Lynis monthly. Aim for hardening score > 80.

Base commands

A few concrete commands to start hardening right away:

# SSH lockdown + fail2ban (comenzi reale)
sudo sed -i 's/^#\?PermitRootLogin.*/PermitRootLogin no/' /etc/ssh/sshd_config
sudo sed -i 's/^#\?PasswordAuthentication.*/PasswordAuthentication no/' /etc/ssh/sshd_config
sudo systemctl reload ssh
sudo apt -y install fail2ban unattended-upgrades
sudo systemctl enable --now fail2ban
sudo lynis audit system      # scor de hardening

Kernel hardening (sysctl)

A few sysctl settings that reduce the network- and kernel-level attack surface:

cat >/etc/sysctl.d/99-hardening.conf <<'EOF'
net.ipv4.conf.all.rp_filter=1
net.ipv4.tcp_syncookies=1
net.ipv4.conf.all.accept_redirects=0
net.ipv4.conf.all.accept_source_route=0
kernel.randomize_va_space=2
kernel.kptr_restrict=2
fs.protected_hardlinks=1
fs.protected_symlinks=1
EOF
sysctl --system

File integrity (AIDE) + auditing (auditd)

You initialize the AIDE database and set auditd rules for critical files:

apt -y install aide auditd
aideinit && mv /var/lib/aide/aide.db.new /var/lib/aide/aide.db
aide --check          # ruleaza zilnic din cron

# audit pe fisiere sensibile
auditctl -w /etc/passwd -p wa -k identity
auditctl -w /etc/ssh/sshd_config -p wa -k sshd
ausearch -k identity | tail

AppArmor: enforce a profile

You isolate a service with AppArmor in enforce mode:

apt -y install apparmor-utils
aa-status                       # ce profile sunt incarcate
aa-enforce /etc/apparmor.d/usr.sbin.nginx
aa-logprof                      # ajustezi din denials reale
journalctl -k | grep apparmor='DENIED'

SSH 2FA + automatic updates

You add a TOTP code to SSH and enable automatic security updates:

apt -y install libpam-google-authenticator unattended-upgrades
google-authenticator            # ca user: scanezi QR in app
# /etc/pam.d/sshd:  auth required pam_google_authenticator.so
# /etc/ssh/sshd_config:  AuthenticationMethods publickey,keyboard-interactive
dpkg-reconfigure -plow unattended-upgrades
systemctl reload ssh