- Cybersecurity
- Networks
- Systems & infrastructure
System and network hardening
Layered defences, from switch ports to administrative access
Context
Hardening applied layer by layer: switch ports, packet filtering, administrative access and network services, with monitoring on top.
Each measure removes a specific opportunity, from an unknown device plugged into a port to an exposed management service.
Architecture
Defence in depth, layer by layer
What I did
- Applied complete port security on Cisco switches: port security, VLAN hardening, DHCP snooping, IP Source Guard and dynamic ARP inspection.
- Filtered packets with iptables, with NAT and stateful firewalling.
- Protected administrative access: hardened SSH, CDP disabled, AAA authentication.
- Hardened critical network services, added local firewalling and disabled unused ports and services.
- Set up an active monitoring policy for network anomalies.
Skills demonstrated
Each skill links to the skills map on the home page.