Skip to content

Security Infrastructure

Last Updated: 2026-02-15 (historical — see caution above) Security Level: Hardened (Post-Incident Review)


This section covers security tools and configurations protecting iSu Technologies infrastructure. Following a security incident on 2026-02-12 to 2026-02-14, comprehensive hardening measures and incident response tools have been implemented.

Security Stack (as of 2026-02, superseded — see caution banner)

Section titled “Security Stack (as of 2026-02, superseded — see caution banner)”
ToolPurposeStatusJails/Rules
fail2banIntrusion prevention⚠️ Retired, replaced by CrowdSecwas 5 jails, 189 IPs banned
UFW/iptablesFirewall✅ Active9 permanent bans
SSH HardeningAccess control✅ HardenedKey-only, restricted
Kernel HardeningSystem protection✅ Active20+ sysctl rules
Auto-UpdatesPatch management✅ ActiveDaily security patches
Incident Response ToolsThreat detection & investigation✅ Active, commands need a CrowdSec pass6 automated tools

Our security approach uses multiple layers:

┌─────────────────────────────────────────────────────────────┐
│ LAYER 1: DETECTION │
│ CrowdSec + firewall-bouncer (was fail2ban) + PLGT Stack │
├─────────────────────────────────────────────────────────────┤
│ LAYER 2: PREVENTION │
│ UFW Firewall + iptables + banned IPs │
├─────────────────────────────────────────────────────────────┤
│ LAYER 3: HARDENING │
│ SSH (key-only, 3 retries) + Kernel (sysctl) + Auto-updates │
├─────────────────────────────────────────────────────────────┤
│ LAYER 4: MONITORING │
│ Verbose logging + Security banner + Audit trails │
└─────────────────────────────────────────────────────────────┘
Terminal window
# Overall security status (CrowdSec, current)
cscli decisions list # Active bans
cscli metrics # Bouncer + scenario stats
ufw status verbose # Firewall rules

Active Protection Summary (historical — fail2ban jail config, retired)

Section titled “Active Protection Summary (historical — fail2ban jail config, retired)”

fail2ban Jails (retired, kept for historical record)

Section titled “fail2ban Jails (retired, kept for historical record)”
JailProtectionBan TimeMax Retry
sshdSSH brute force1 week2
recidiveRepeat offenders30 days2
nginx-http-authHTTP auth attacks1 day3
nginx-botsearchBot scanning1 week2
nginx-req-limitRequest flooding1 day5

CrowdSec’s equivalent scenario coverage isn’t documented here yet — check cscli scenarios list on the box directly until this section gets a proper rewrite.

PortServiceAccess
22SSHRate-limited
80/443HTTP/HTTPSOpen
3004GrafanaOpen
3005ThriveSendOpen
8001/8003Backend APIsOpen
Terminal window
# 1. Check current attacks (CrowdSec, current)
cscli alerts list
# 2. Manually ban aggressive IP
cscli decisions add --ip <IP_ADDRESS> --reason "manual ban" --duration 168h
# 3. Permanent UFW ban for persistent attackers
ufw insert 1 deny from <IP_ADDRESS> comment "Permanent ban - reason"
# 4. Check active decisions
cscli decisions list
  • Primary: Nhlanhla Mnyandu (nhlanhla@isutech.co.za)
  • Servers: Dube TradePort (isutech-svr-01, 41.78.233.110, primary) and Hetzner (production-server-01, 46.224.40.5, legacy, being emptied) — see Server Management Guide
  • Incident Log: /var/log/security-incidents.log

Hardened: 2026-02-09 | fail2ban→CrowdSec switch + Dube TradePort added: update this page fully, tracked as a gap | Maintained by iSu Technologies Security Team