• Cybersecurity
  • Networks
  • Systems & infrastructure

System and network hardening

Layered defences, from switch ports to administrative access

Context

Hardening applied layer by layer: switch ports, packet filtering, administrative access and network services, with monitoring on top.

Each measure removes a specific opportunity, from an unknown device plugged into a port to an exposed management service.

Architecture

Defence in depth, layer by layer

Hardening of the network and the hosts Unknown device plugged into a port SSH · AAA Administrator via SSH, with AAA Cisco switch blocked Port security VLAN hardening DHCP snooping IP Source Guard ARP inspection CDP disabled Linux host iptables local firewalling stateful NAT SSH hardened Services unused ones off Active monitoring network anomalies anomaly Hardening of the network and the hosts Unknown device plugged into a port Administrator via SSH, with AAA SSH · AAA Cisco switch blocked Port security VLAN hardening DHCP snooping IP Source Guard ARP inspection CDP disabled Linux host iptables local firewalling stateful NAT SSH hardened Services unused ones off Active monitoring network anomalies anomaly
Five layers of controls. Access ports on Cisco switches are locked down, packets are filtered statefully with iptables, administrative access is protected and authenticated, unused ports and services are disabled, and an active monitoring policy watches for network anomalies.

What I did

  • Applied complete port security on Cisco switches: port security, VLAN hardening, DHCP snooping, IP Source Guard and dynamic ARP inspection.
  • Filtered packets with iptables, with NAT and stateful firewalling.
  • Protected administrative access: hardened SSH, CDP disabled, AAA authentication.
  • Hardened critical network services, added local firewalling and disabled unused ports and services.
  • Set up an active monitoring policy for network anomalies.

Skills demonstrated

Each skill links to the skills map on the home page.

Command palette

At a glance
Experience
Projects
Skills
Credentials
Education
About
Languages
Journey
Contact
Secure IoT telemetry
Secure multi-site architecture
5G Standalone network
System and network hardening
Vulnerability assessment and exploitation
Multi-site network design and security
Regenerative repeater for satellite links
Use the light theme
Use the dark theme
Use the system theme
Lire en français
Copy my email address
Download my CV (PDF)
Open my LinkedIn profile
Back to the top