Tag Archive

firewall

7 posts found

Why Transport Layer Fingerprinting Will Replace IP Reputation

Perimeter security models that rely on IP reputation fail against residential proxy pools. Edge defense is shifting to transport-layer fingerprinting, inspectin…

Why Dropping All ICMP Breaks Path MTU Discovery

Blocking all ICMP traffic does not hide your servers from network scanners. Instead, it breaks Path MTU Discovery, causing silent connection freezes during TLS …

TPROXY vs REDIRECT: Transparent Socket Interception on Linux

Intercepting routed TCP and UDP traffic on a Linux gateway without rewriting packet headers requires Netfilter TPROXY. Here is why REDIRECT breaks UDP and conne…

Linux Nftables Flowtables: Netfilter Fastpath Connection State Gaps

Software flowtables cut CPU load on Linux routers by bypassing Netfilter chains. Here is why established connections ignore live firewall rule updates and how t…

Debugging WireGuard MTU Bottlenecks and TCP MSS Clamping

Why WireGuard connections drop large TCP payloads when ICMP Path MTU Discovery fails, and how to configure MSS clamping and interface MTU limits on Linux gatewa…

Why Docker Bypasses UFW Rules (And How to Fix It)

Docker manipulates iptables FORWARD chains directly, bypassing UFW INPUT rules. Learn why container ports leak to the public internet and how to secure them.

Hardening Nginx Reverse Proxy: A Production Case Study

A case study of hardening an Nginx reverse proxy on a $6 VPS against constant internet-facing threats, covering TLS tuning, rate limiting, DNS audit, and the op…

Press Cmd K to search