security 归档 - 夜莺博客

标签:security

OpenSSH Server Hardening: sshd_config Guide

OpenSSH Server Hardening: sshd_config Guide

Harden an OpenSSH server with a single drop-in config: key-only authentication, no root login, AllowUsers allowlists, modern ciphers and a tested, rev

admin admin 2026-10-07
0 0 0
arp-scan, fping and masscan: Host Discovery Sweeps

arp-scan, fping and masscan: Host Discovery Sweeps

Choose the right host discovery tool: arp-scan for authoritative L2 sweeps, fping for parallel ICMP, masscan for large-scale port discovery, with real

admin admin 2026-10-06
0 0 0
DNSSEC ZSK and KSK Key Rollover with BIND 9

DNSSEC ZSK and KSK Key Rollover with BIND 9

Roll DNSSEC keys safely in BIND 9: dnssec-policy, ZSK pre-publish versus KSK double-KSK strategies, rndc dnssec status checks and DS submission steps.

admin admin 2026-10-06
0 0 0
GTP-U Tunnel Inspection on Next-Generation Firewalls

GTP-U Tunnel Inspection on Next-Generation Firewalls

Configure stateful GTP-U and GTP-C inspection on next-gen firewalls: interface roles for S1-U/N3, GTP profiles, tunnel limits and mobile-core security

admin admin 2026-10-06
0 0 0
Samba as an Active Directory Domain Controller

Samba as an Active Directory Domain Controller

Deploy Samba as an AD domain controller on Linux: provisioning, DNS, Kerberos, joins, GPO handling and the replication checks that prove it is healthy

admin admin 2026-10-05
0 0 0
Linkerd Service Mesh mTLS Configuration Guide

Linkerd Service Mesh mTLS Configuration Guide

Install Linkerd, enable automatic mTLS between Kubernetes workloads, verify identity with the CLI, and add authorization policies without changing app

admin admin 2026-10-05
0 0 0
Cisco IOS XR ACL Configuration and Verification

Cisco IOS XR ACL Configuration and Verification

Configure and verify access lists on Cisco IOS XR: extended ACLs, sequence numbering, counter checks, object groups and the mistakes that silently dro

admin admin 2026-10-05
0 0 0
Carrier-Grade NAT (CGNAT) Design and Configuration

Carrier-Grade NAT (CGNAT) Design and Configuration

CGNAT design essentials: log-port ranges, deterministic NAT, port-block allocation, logging requirements and how to size a NAT444 deployment from RFC

admin admin 2026-10-05
0 0 0
DNS Zone Transfer Hardening: AXFR and IXFR

DNS Zone Transfer Hardening: AXFR and IXFR

Zone transfers replicate DNS and leak your host list. Learn how AXFR and IXFR work and how to lock them down with TSIG and allow-transfer on BIND and

admin admin 2026-10-05
0 0 0
RADIUS CoA and Disconnect-Message Configuration Guide

RADIUS CoA and Disconnect-Message Configuration Guide

How RADIUS Change-of-Authorization and Disconnect-Message work, how to enable them on Cisco, Aruba and FreeRADIUS, and how to debug the common silent

admin admin 2026-10-05
0 0 0
1 2 3 … 9