Network Device Hardening¶
Baseline hardening for network infrastructure: general attack-surface-reduction techniques, hardening VPN gateways specifically, hardening routers/switches/firewalls, and the tooling used to monitor network devices once they're deployed.
| Topic | Description |
|---|---|
| Common Hardening Techniques | General hardening principles, secure protocols, removing insecure protocols, and monitoring/logging (Syslog, SNMP, NetFlow, packet captures). |
| Hardening VPNs | Strong encryption ciphers, keeping VPN software current, strong authentication, default settings, and Perfect Forward Secrecy. |
| Hardening Routers, Switches & Firewalls | Default credentials, secure protocols, traffic rules, port forwarding, scheduled task monitoring, firmware updates, port security, ARP spoofing, rogue DHCP, and IPv6. |
| Network Monitoring Tools | Comparison of Nagios, SolarWinds NPM, PRTG, and Zabbix. |