Lesson 12 - Setting Up System Security

You might also like

Download as pdf or txt
Download as pdf or txt
You are on page 1of 33

Setting up System

Security

This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com


Objectives covered
212.1 Configuring a router (w:3)

212.3 Secure shell (SSH) (w:4)

212.4 Security tasks (w:3)

212.5 OpenVPN (w:2)

2
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
1 Server Network Security

This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com


Port scanning

4
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
Port scanning

5
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
Port scanning

6
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
OpenVAS

7
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
Intrusion Detection Systems – fail2ban

8
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
Intrusion Detection Systems – Snort

9
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
Intrusion Detection Systems – Snort

10
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
External Network Security – NAT

11
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
External Network Security – Firewall

12
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
External Network Security – iptables

13
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
External Network Security – iptables

14
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
External Network Security – iptables

Accept outgoing package

Drop outgoing package


15
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
External Network Security – iptables

Rule options for iptables

16
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
External Network Security – iptables

Restore iptables rules

Backup iptables rules

17
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
External Network Security – routing

The FORWARD chain allows Linux to forward packets to a


remote host, but that feature must be enabled in the kernel

Set the kernel parameter Check the current value

18
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
EXERCISE
Time for labs

19
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
Connecting Securely to a
2
Server

This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com


OpenSSH

OpenSSH Files

OpenSSH server configuration options


21
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
OpenSSH

22
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
OpenSSH

23
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
OpenVPN

24
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
OpenVPN

openvpn configuration files

openvpn configuration options

25
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
OpenVPN

OpenVPN includes several scripts to help generate the Static key encryption method
required certificates and keys:

26
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
OpenVPN - Static key encryption method
Copy secret.key to client

Config file
Config file

On VPN server On VPN client 27


This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
OpenVPN - Static key encryption demo

PRIVATE NETWORK

192.168.56.99 192.168.56.98

Vpn client Vpn server 192.168.57.110


Local server
Ubuntu 10.0.0.1 10.0.0.2 CentOS 192.168.57.2 Ubuntu

28
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
OpenVPN – Demo OpenVPN configuration

29
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
3 Security Resources

This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com


US-CERT

https://us-cert.cisa.gov

31
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
Other resources

Bugtraq mailling list

32
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com
THANKS!
ANY QUESTIONS?

33
This document is created by Nguyen Hoang Chi chi.nguyen.e4w@gmail.com

You might also like