security 归档 - 第3页 共9页 - 夜莺博客

标签:security

Captive Portal Deployment Guide: DHCP, RA and CAPPORT

Captive Portal Deployment Guide: DHCP, RA and CAPPORT

Deploy a standards-based captive portal using DHCP option 114, DHCPv6 option 103 and the RFC 8908 API instead of fragile TLS hijacking.

admin admin 2026-10-01
0 0 0
BGP Session Hardening: GTSM, MD5 and TCP-AO

BGP Session Hardening: GTSM, MD5 and TCP-AO

Harden BGP sessions with TTL security (GTSM, RFC 5082), MD5 authentication and TCP-AO (RFC 5925), including configuration and migration notes.

admin admin 2026-09-30
0 0 0
Post-Quantum Cryptography in IPsec and IKEv2

Post-Quantum Cryptography in IPsec and IKEv2

Prepare IPsec VPNs for quantum risk: ML-KEM (FIPS 203), IKEv2 multiple key exchanges (RFC 9370), vendor support and migration planning.

admin admin 2026-09-30
0 0 0
OT/SCADA Network Segmentation and the Purdue Model

OT/SCADA Network Segmentation and the Purdue Model

Segment OT and SCADA networks using the Purdue model: zones and conduits, industrial DMZ design, firewall rules and monitoring for plant traffic.

admin admin 2026-09-30
0 0 0
DNS over HTTPS and DNS over TLS: Encrypted DNS Deployment

DNS over HTTPS and DNS over TLS: Encrypted DNS Deployment

Deploy encrypted DNS with DoH and DoT: protocol differences, resolver configuration, firewall port planning and trade-offs for enterprises.

admin admin 2026-09-30
0 0 0
DNS RPZ: Building a DNS Firewall with Response Policy Zones

DNS RPZ: Building a DNS Firewall with Response Policy Zones

Use DNS Response Policy Zones to block malware and phishing at the resolver: RPZ triggers, policy actions, BIND configuration and testing.

admin admin 2026-09-30
0 0 0
Cisco TrustSec SGT: Classification and SGACL Enforcement

Cisco TrustSec SGT: Classification and SGACL Enforcement

Learn how Cisco TrustSec works: SGT classification, propagation with inline tagging or SXP, and SGACL enforcement on switches, routers and firewalls.

admin admin 2026-09-30
0 0 0
MACsec Switch-to-Switch Encryption with MKA

MACsec Switch-to-Switch Encryption with MKA

Configure MACsec on Cisco switches: MKA key chains with CKN and CAK, policy on the interface, verification with show macsec, and where it fits versus

admin admin 2026-09-23
0 0 0
Snort 3 Installation and Rule Configuration Guide

Snort 3 Installation and Rule Configuration Guide

Install and configure Snort 3: dependencies, LibDAQ, Lua configuration, module tuning, rule files and includes, plus snort2lua migration from Snort 2.

admin admin 2026-09-23
0 0 0
Zeek Network Security Monitoring: Setup and Logs

Zeek Network Security Monitoring: Setup and Logs

Deploy Zeek for network security monitoring: sensor placement, pcap and live capture, conn.log and http.log pivoting, zeekctl clusters and custom scri

admin admin 2026-09-23
0 0 0
1 2 3 4 5 … 9