Skip to content

Network Device Hardening

Baseline hardening for network infrastructure: general attack-surface-reduction techniques, hardening VPN gateways specifically, hardening routers/switches/firewalls, and the tooling used to monitor network devices once they're deployed.

Topic Description
Common Hardening Techniques General hardening principles, secure protocols, removing insecure protocols, and monitoring/logging (Syslog, SNMP, NetFlow, packet captures).
Hardening VPNs Strong encryption ciphers, keeping VPN software current, strong authentication, default settings, and Perfect Forward Secrecy.
Hardening Routers, Switches & Firewalls Default credentials, secure protocols, traffic rules, port forwarding, scheduled task monitoring, firmware updates, port security, ARP spoofing, rogue DHCP, and IPv6.
Network Monitoring Tools Comparison of Nagios, SolarWinds NPM, PRTG, and Zabbix.