security 归档 - 第5页 共9页 - 夜莺博客

标签:security

IPsec VTI vs Policy-Based VPN: Choosing and Configuring

IPsec VTI vs Policy-Based VPN: Choosing and Configuring

Compare IPsec VTI (route-based) with policy-based crypto maps: routing protocol support, NAT and overlapping subnets, VRF awareness, and when to add G

admin admin 2026-09-19
0 0 0
fail2ban jail.local and nftables Backend Setup

fail2ban jail.local and nftables Backend Setup

Configure fail2ban the maintainable way: jail.local overrides, the systemd log backend, nftables banaction, custom filters tested with fail2ban-regex,

admin admin 2026-09-17
0 0 0
SELinux Denials: ausearch, sealert and audit2allow

SELinux Denials: ausearch, sealert and audit2allow

Fix SELinux denials the right way: triage with ausearch and sealert, check labels and booleans first, and only then build a local audit2allow policy m

admin admin 2026-09-17
0 0 0
Unbound DNSSEC Validation: Setup and Debug

Unbound DNSSEC Validation: Setup and Debug

Turn on DNSSEC validation in Unbound: trust anchors, hardened options, verification with delv, and how to debug SERVFAIL from bogus answers.

admin admin 2026-09-15
0 0 0
Cisco uRPF: Strict vs Loose Mode Anti-Spoofing

Cisco uRPF: Strict vs Loose Mode Anti-Spoofing

Deploy uRPF on Cisco IOS/IOS-XE correctly: strict vs loose mode, allow options, where to apply it, and how to avoid dropping valid asymmetric traffic.

admin admin 2026-09-15
0 0 0
Arista EOS ACLs: IPv4, MAC ACLs and Counters

Arista EOS ACLs: IPv4, MAC ACLs and Counters

Build Arista EOS IPv4 and MAC ACLs, enable per-entry counters, apply them to interfaces and verify hits with show ip access-list and show interfaces c

admin admin 2026-09-15
0 0 0
Junos MACsec on EX and QFX: Configuration Guide

Junos MACsec on EX and QFX: Configuration Guide

Configure MACsec on Juniper EX and QFX switches: connectivity associations, static CAK mode, MKA key server priority and verification commands.

admin admin 2026-09-15
0 0 0
华为交换机 DHCP Snooping 与 IPSG 配置:防私接与仿冒

华为交换机 DHCP Snooping 与 IPSG 配置:防私接与仿冒

华为交换机 DHCP Snooping 与 IPSG 配置完整流程:全局与接口使能、信任接口、动态绑定表、静态 user-bind 与常见排障命令。

admin admin 2026-09-14
0 0 0
802.1X Port-Based Authentication on Access Switches

802.1X Port-Based Authentication on Access Switches

Deploy 802.1X on access switches: roles, EAP methods, host modes, dynamic VLAN assignment, fallback and a staged rollout that avoids locking out devic

admin admin 2026-09-13
0 0 0
SNMPv3 Setup: Security Levels, Engine ID, Verify

SNMPv3 Setup: Security Levels, Engine ID, Verify

Configure SNMPv3 correctly: noAuthNoPriv vs authPriv, engine ID and localised keys, group and user ordering, net-snmp verification and the errors you

admin admin 2026-09-13
0 0 0
1 … 3 4 5 6 7 … 9