1. SSH-Lockdown
- Root-Login deaktivieren
- Nur Key-Auth erzwingen
- Standard-Port 22 → 2222 ändern
- Fail2ban mit SSH-Jail
- 2FA mit Google Authenticator
2. iptables / nftables Firewall
DROP-Default auf INPUT, GeoIP-Filterung, Rate-Limiting pro IP.
3. CrowdSec
Verteilte Threat-Intelligence-Community.
4. Automatische Sicherheitsupdates
unattended-upgrades konfiguriert nur für Sicherheit.
5. CIS Benchmark + Lynis Audit
Lynis monatlich ausführen. Hardening-Score > 80 anstreben.
Basis-Befehle
Einige konkrete Befehle, um sofort mit dem Hardening zu beginnen:
# SSH lockdown + fail2ban (comenzi reale)
sudo sed -i 's/^#\?PermitRootLogin.*/PermitRootLogin no/' /etc/ssh/sshd_config
sudo sed -i 's/^#\?PasswordAuthentication.*/PasswordAuthentication no/' /etc/ssh/sshd_config
sudo systemctl reload ssh
sudo apt -y install fail2ban unattended-upgrades
sudo systemctl enable --now fail2ban
sudo lynis audit system # scor de hardening