Hardening your NAS Linux kernel to CIS Level 2 standards
Over 40 sysctl parameters, module blacklisting, GRUB settings and filesystem hardening to achieve CIS Level 2 security on Debian.
- Published on
- 7 min read
Over 40 sysctl parameters, module blacklisting, GRUB settings and filesystem hardening to achieve CIS Level 2 security on Debian.
Setting up UFW with deny-by-default and Fail2ban with progressive bans to effectively protect a Debian NAS against network intrusions.
Configuring OpenSSH with post-quantum key exchanges (ML-KEM768, sntrup761), Ed25519 keys, and hardened authentication for your NAS.
How to create a custom Debian ISO with preseed for a fully automated NAS installation on a TerraMaster, from boot to first SSH connection.