1. SSH lockdown
- Disable root login:
PermitRootLogin no - Force key-only auth:
PasswordAuthentication no - Change default port 22 → 2222 (reduces 99% scan noise)
- Fail2ban with sshd jail (maxretry 3, bantime 24h)
- 2FA with Google Authenticator (PAM module)
2. iptables / nftables firewall
- Default DROP on INPUT, ACCEPT only on required ports
- GeoIP filtering: block countries you have no legitimate traffic from
- Per-IP rate limiting
3. CrowdSec (modern fail2ban alternative)
Distributed threat intelligence community. Detects attacks and syncs bad IPs globally.
4. Automatic security updates
unattended-upgrades configured strictly for security only.
5. CIS Benchmark + Lynis audit
Run Lynis monthly. Aim for hardening score > 80.
Base commands
A few concrete commands to start hardening right away:
# SSH lockdown + fail2ban (comenzi reale)
sudo sed -i 's/^#\?PermitRootLogin.*/PermitRootLogin no/' /etc/ssh/sshd_config
sudo sed -i 's/^#\?PasswordAuthentication.*/PasswordAuthentication no/' /etc/ssh/sshd_config
sudo systemctl reload ssh
sudo apt -y install fail2ban unattended-upgrades
sudo systemctl enable --now fail2ban
sudo lynis audit system # scor de hardening
Kernel hardening (sysctl)
A few sysctl settings that reduce the network- and kernel-level attack surface:
cat >/etc/sysctl.d/99-hardening.conf <<'EOF'
net.ipv4.conf.all.rp_filter=1
net.ipv4.tcp_syncookies=1
net.ipv4.conf.all.accept_redirects=0
net.ipv4.conf.all.accept_source_route=0
kernel.randomize_va_space=2
kernel.kptr_restrict=2
fs.protected_hardlinks=1
fs.protected_symlinks=1
EOF
sysctl --system
File integrity (AIDE) + auditing (auditd)
You initialize the AIDE database and set auditd rules for critical files:
apt -y install aide auditd
aideinit && mv /var/lib/aide/aide.db.new /var/lib/aide/aide.db
aide --check # ruleaza zilnic din cron
# audit pe fisiere sensibile
auditctl -w /etc/passwd -p wa -k identity
auditctl -w /etc/ssh/sshd_config -p wa -k sshd
ausearch -k identity | tail
AppArmor: enforce a profile
You isolate a service with AppArmor in enforce mode:
apt -y install apparmor-utils
aa-status # ce profile sunt incarcate
aa-enforce /etc/apparmor.d/usr.sbin.nginx
aa-logprof # ajustezi din denials reale
journalctl -k | grep apparmor='DENIED'
SSH 2FA + automatic updates
You add a TOTP code to SSH and enable automatic security updates:
apt -y install libpam-google-authenticator unattended-upgrades
google-authenticator # ca user: scanezi QR in app
# /etc/pam.d/sshd: auth required pam_google_authenticator.so
# /etc/ssh/sshd_config: AuthenticationMethods publickey,keyboard-interactive
dpkg-reconfigure -plow unattended-upgrades
systemctl reload ssh