Kason Y.โ€™s Post

View profile for Kason Y., graphic

Security Architect | Security Engineer | Cybersecurity Instructor | Network Security Expert | Follow me for fun and engaging insights on cybersecurity and tech.

๐๐ฎ๐ข๐ฅ๐๐ข๐ง๐  ๐š ๐๐ฎ๐ฅ๐ฅ๐ž๐ญ๐ฉ๐ซ๐จ๐จ๐Ÿ ๐‡๐จ๐ฆ๐ž ๐๐ž๐ญ๐ฐ๐จ๐ซ๐ค: ๐€ ๐‚๐ฒ๐›๐ž๐ซ๐ฌ๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ ๐„๐ง๐ญ๐ก๐ฎ๐ฌ๐ข๐š๐ฌ๐ญ'๐ฌ ๐†๐ฎ๐ข๐๐ž Whether you're hosting a public server, need secure remote access to your network, or just want to experiment with network security, this guide is for you. Links to the free open-source software are in the comments. ๐„๐ฑ๐ญ๐ž๐ซ๐ง๐š๐ฅ ๐๐ž๐ญ๐ฐ๐จ๐ซ๐ค โœ” ๐€๐–๐’ ๐’๐ž๐ซ๐ฏ๐ž๐ซ๐ฌ: Secure remote access via WireGuard VPN for redundancy and scalability. Launch an EC2 Instance https://lnkd.in/g9KgYG3g โœ”๐Œ๐ฒ ๐ƒ๐จ๐ฆ๐š๐ข๐ง: Essential for secure hosting and a professional online presence. Registering a Domain with Cloudflare https://lnkd.in/gvkGWWdg Change Nameservers to Cloudflare https://lnkd.in/gXS9j56y โœ”๐Ž๐ฉ๐ž๐ง๐•๐๐ ๐‚๐ฅ๐ข๐ž๐ง๐ญ๐ฌ: Encrypts data for secure remote connections. OpenVPN Download and Windows Setup https://lnkd.in/g3JkZWma ๐ˆ๐ง๐ญ๐ž๐ซ๐ง๐š๐ฅ ๐๐ž๐ญ๐ฐ๐จ๐ซ๐ค โœ”๐๐ž๐ญ๐†๐š๐ญ๐ž ๐…๐ข๐ซ๐ž๐ฐ๐š๐ฅ๐ฅ: Protects the network with pfSense Firewall and Suricata IPS. โœ”๐Œ๐š๐ง๐š๐ ๐ž๐ ๐’๐ฐ๐ข๐ญ๐œ๐ก: Segments traffic for improved security and performance. โœ”๐–๐ข๐ง๐๐จ๐ฐ๐ฌ, ๐Œ๐š๐œ๐Ž๐’, ๐š๐ง๐ ๐‹๐ข๐ง๐ฎ๐ฑ ๐‡๐จ๐ฌ๐ญ๐ฌ: Diverse OS for testing, secured by TrendMicro AV and Elastic-Agent. โœ”๐ˆ๐จ๐“ ๐ƒ๐ž๐ฏ๐ข๐œ๐ž๐ฌ: Isolated to prevent vulnerabilities from affecting the main network. โœ”๐๐ž๐ญ๐ฐ๐จ๐ซ๐ค ๐€๐ญ๐ญ๐š๐œ๐ก๐ž๐ ๐’๐ญ๐จ๐ซ๐š๐ ๐ž (๐๐€๐’): Centralized storage for easy data management and backup. ๐€๐๐ฏ๐š๐ง๐œ๐ž๐ ๐…๐ž๐š๐ญ๐ฎ๐ซ๐ž๐ฌ โœ”๐๐ซ๐จ๐ฑ๐ฆ๐จ๐ฑ ๐‡๐ฒ๐ฉ๐ž๐ซ๐ฏ๐ข๐ฌ๐จ๐ซ & ๐•๐ข๐ซ๐ญ๐ฎ๐š๐ฅ๐ข๐ณ๐š๐ญ๐ข๐จ๐ง: Efficiently run multiple environments. โœ”๐’๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ ๐“๐จ๐จ๐ฅ๐ฌ (๐™๐ž๐ž๐ค ๐ˆ๐ƒ๐’, ๐‘๐ˆ๐“๐€): Continuous monitoring and threat analysis. โœ”๐Š๐š๐ฅ๐ข ๐‹๐ข๐ง๐ฎ๐ฑ: Penetration testing and security assessments. โœ”๐๐ ๐ข๐ง๐ฑ ๐๐ซ๐จ๐ฑ๐ฒ ๐Œ๐š๐ง๐š๐ ๐ž๐ซ: Simplifies secure web service management. โœ”๐–๐ข๐ซ๐ž๐†๐ฎ๐š๐ซ๐ ๐•๐๐ & ๐๐ ๐ข๐ง๐ฑ ๐๐ซ๐จ๐ฑ๐ฒ ๐Œ๐š๐ง๐š๐ ๐ž๐ซ: Ensures secure remote connections and web service management. ๐๐ซ๐š๐œ๐ญ๐ข๐œ๐š๐ฅ ๐“๐ข๐ฉ๐ฌ ๐Ÿ”ง ๐’๐ญ๐š๐ซ๐ญ ๐’๐ข๐ฆ๐ฉ๐ฅ๐ž: Begin with basic components and gradually add advanced features. ๐Ÿ”’ ๐’๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ ๐…๐ข๐ซ๐ฌ๐ญ: Always prioritize security with firewalls, VPNs, and segmentation. ๐Ÿ”„ ๐’๐ญ๐š๐ฒ ๐”๐ฉ๐๐š๐ญ๐ž๐: Keep all software and firmware updated to protect against vulnerabilities. ๐Ÿ“š ๐‹๐ž๐š๐ซ๐ง ๐‚๐จ๐ง๐ญ๐ข๐ง๐ฎ๐จ๐ฎ๐ฌ๐ฅ๐ฒ: Stay informed about the latest trends and technologies in cybersecurity. Like what you see? Follow Kason Y. for daily insights on technology and cybersecurity. Click the ๐Ÿ”” to get a notification so you don't miss my new posts. #cybersecurity #networksecurity #homelab source:https://lnkd.in/g8RHiu3z

  • No alternative text description for this image
Kason Y.

Security Architect | Security Engineer | Cybersecurity Instructor | Network Security Expert | Follow me for fun and engaging insights on cybersecurity and tech.

1w
Kason Y.

Security Architect | Security Engineer | Cybersecurity Instructor | Network Security Expert | Follow me for fun and engaging insights on cybersecurity and tech.

1w
Like
Reply
Kason Y.

Security Architect | Security Engineer | Cybersecurity Instructor | Network Security Expert | Follow me for fun and engaging insights on cybersecurity and tech.

1w
Like
Reply
Kason Y.

Security Architect | Security Engineer | Cybersecurity Instructor | Network Security Expert | Follow me for fun and engaging insights on cybersecurity and tech.

1w
Like
Reply
Kason Y.

Security Architect | Security Engineer | Cybersecurity Instructor | Network Security Expert | Follow me for fun and engaging insights on cybersecurity and tech.

1w
Like
Reply
Kason Y.

Security Architect | Security Engineer | Cybersecurity Instructor | Network Security Expert | Follow me for fun and engaging insights on cybersecurity and tech.

1w
Like
Reply
Kason Y.

Security Architect | Security Engineer | Cybersecurity Instructor | Network Security Expert | Follow me for fun and engaging insights on cybersecurity and tech.

1w
Like
Reply
Kason Y.

Security Architect | Security Engineer | Cybersecurity Instructor | Network Security Expert | Follow me for fun and engaging insights on cybersecurity and tech.

1w

There is a lot more to unpack for the whole setup. Let me know in the comments if there are any specific topics you would like to hear about, and I will make further posts for more in-depth discussions!

Damien โˆ’ยทยท

Cybersecurity Engineer Freelance at Confidential

1w

Hello, I know this is done to be used by the most of the people... but... :D I recommand to change how the network is handle. You need to think about how you trust each network Flow. In my Case, this is my recommandation (but you need to be crazy like me) For the network and firewall only Box Firewall Brand A Firewall SAS IN Brand A Firewall SAS OUT Brand A Firewall Internal Brand B Firewall for Administration Brand C And if possible another dedicated for the backup. ๐Ÿ˜‹. PS : stop using Pfsense it is too old. Go instead with #OPNsense and the plugin Zenarmor to get a NGFW :).

Mihai Cristian Satmarean

Fractional CTO | DevOps Consultant @ Open Sea Map Volunteer | Certified Scrum Master

1w

Very nice and comprehensive, I would like to see an Ansible set of roles and playbooks that deploy and manage this. Else is too much work to keep it up to date.

See more comments

To view or add a comment, sign in

Explore topics