The Firewall Rule Order That's Breaking Your Setup
Firewall rules are evaluated top-down, first match wins. One misplaced ALLOW rule above your denials silently defeats all your security. Here's the fix.
All the articles with the tag "linux".
Firewall rules are evaluated top-down, first match wins. One misplaced ALLOW rule above your denials silently defeats all your security. Here's the fix.
Understand sticky bit, setuid, and setgid: what they do, how to set them, security implications, and real-world use cases.
Verify fail2ban is protecting you: check jails, test bans, monitor logs, common misconfiguration, and unban IPs when needed.
Your Linux box takes forever to boot? systemd-analyze shows exactly which services drag it down. Read blame, critical-chain, plot, and fix the slow ones.
SSHFS mounts remote filesystems over SSH so you can browse and edit files locally, faster than scp for interactive work.
systemctl status packs a lot into 12 lines. What Loaded, Active, Invocation, Main PID, Tasks, and the CGroup tree each tell you when a service misbehaves.
Understand SSH agent forwarding security risks. When it's safe (almost never), and better alternatives like ProxyJump for jump hosts.
Default mount options and journald settings burn SSD write endurance. Check health with smartctl, mount noatime, move logs to tmpfs, find the real writer.
Essential journalctl commands: -u, -f, --since, -p, -k, -b, --no-pager, JSON output. The queries you need on a broken server at 2 AM.
Fix SSH timeouts: ServerAliveInterval, ServerAliveCountMax, ClientAliveInterval. Understand NAT, firewalls, and TCP keepalive.
ss replaces netstat on modern Linux: faster, shows more socket detail, and reads from the kernel. Every netstat command you rely on, rewritten for ss.
Cron runs a different PATH, mutes stdout, and breaks MAILTO quietly. Absolute paths, an explicit PATH, log redirection, and how to test a job first.