Security Infrastructure
Security Infrastructure
Section titled “Security Infrastructure”Last Updated: 2026-02-15 (historical — see caution above) Security Level: Hardened (Post-Incident Review)
Overview
Section titled “Overview”This section covers security tools and configurations protecting iSu Technologies infrastructure. Following a security incident on 2026-02-12 to 2026-02-14, comprehensive hardening measures and incident response tools have been implemented.
Security Stack (as of 2026-02, superseded — see caution banner)
Section titled “Security Stack (as of 2026-02, superseded — see caution banner)”| Tool | Purpose | Status | Jails/Rules |
|---|---|---|---|
| fail2ban | Intrusion prevention | ⚠️ Retired, replaced by CrowdSec | was 5 jails, 189 IPs banned |
| UFW/iptables | Firewall | ✅ Active | 9 permanent bans |
| SSH Hardening | Access control | ✅ Hardened | Key-only, restricted |
| Kernel Hardening | System protection | ✅ Active | 20+ sysctl rules |
| Auto-Updates | Patch management | ✅ Active | Daily security patches |
| Incident Response Tools | Threat detection & investigation | ✅ Active, commands need a CrowdSec pass | 6 automated tools |
Defense in Depth
Section titled “Defense in Depth”Our security approach uses multiple layers:
┌─────────────────────────────────────────────────────────────┐│ LAYER 1: DETECTION ││ CrowdSec + firewall-bouncer (was fail2ban) + PLGT Stack │├─────────────────────────────────────────────────────────────┤│ LAYER 2: PREVENTION ││ UFW Firewall + iptables + banned IPs │├─────────────────────────────────────────────────────────────┤│ LAYER 3: HARDENING ││ SSH (key-only, 3 retries) + Kernel (sysctl) + Auto-updates │├─────────────────────────────────────────────────────────────┤│ LAYER 4: MONITORING ││ Verbose logging + Security banner + Audit trails │└─────────────────────────────────────────────────────────────┘Quick Status Commands
Section titled “Quick Status Commands”# Overall security status (CrowdSec, current)cscli decisions list # Active banscscli metrics # Bouncer + scenario statsufw status verbose # Firewall rulesQuick Links
Section titled “Quick Links”- 🚨 Incident Response Tools - Security investigation & remediation toolkit (commands predate the CrowdSec switch — verify before use)
- fail2ban Guide - Historical — fail2ban is retired, this guide describes a tool no longer installed
- SSH Hardening - Access control configuration
- Kernel Hardening - System protection
- Firewall Rules - UFW/iptables configuration (fail2ban references need a CrowdSec pass)
- PLGT Stack - Observability and alerting
- Server Management Guide - current facts for both production servers (Dube TradePort + Hetzner)
Active Protection Summary (historical — fail2ban jail config, retired)
Section titled “Active Protection Summary (historical — fail2ban jail config, retired)”fail2ban Jails (retired, kept for historical record)
Section titled “fail2ban Jails (retired, kept for historical record)”| Jail | Protection | Ban Time | Max Retry |
|---|---|---|---|
| sshd | SSH brute force | 1 week | 2 |
| recidive | Repeat offenders | 30 days | 2 |
| nginx-http-auth | HTTP auth attacks | 1 day | 3 |
| nginx-botsearch | Bot scanning | 1 week | 2 |
| nginx-req-limit | Request flooding | 1 day | 5 |
CrowdSec’s equivalent scenario coverage isn’t documented here yet — check
cscli scenarios list on the box directly until this section gets a proper
rewrite.
Firewall Ports
Section titled “Firewall Ports”| Port | Service | Access |
|---|---|---|
| 22 | SSH | Rate-limited |
| 80/443 | HTTP/HTTPS | Open |
| 3004 | Grafana | Open |
| 3005 | ThriveSend | Open |
| 8001/8003 | Backend APIs | Open |
Emergency Response
Section titled “Emergency Response”Under Attack?
Section titled “Under Attack?”# 1. Check current attacks (CrowdSec, current)cscli alerts list
# 2. Manually ban aggressive IPcscli decisions add --ip <IP_ADDRESS> --reason "manual ban" --duration 168h
# 3. Permanent UFW ban for persistent attackersufw insert 1 deny from <IP_ADDRESS> comment "Permanent ban - reason"
# 4. Check active decisionscscli decisions listEmergency Contacts
Section titled “Emergency Contacts”- Primary: Nhlanhla Mnyandu (nhlanhla@isutech.co.za)
- Servers: Dube TradePort (
isutech-svr-01,41.78.233.110, primary) and Hetzner (production-server-01,46.224.40.5, legacy, being emptied) — see Server Management Guide - Incident Log: /var/log/security-incidents.log
Hardened: 2026-02-09 | fail2ban→CrowdSec switch + Dube TradePort added: update this page fully, tracked as a gap | Maintained by iSu Technologies Security Team