Files
nix-config/modules/boot/hardened.org
phundrak a2b21feacc refactor: change to litterate config
Configuration is now held by the `.org` files. All `.nix` files are
tangled from the org-mode files.
2026-10-04 22:34:28 +02:00

3.1 KiB
Raw Permalink Blame History

Kernel Hardening

Kernel Hardening

Some of my machines are exposed to the Internet, and therefore get their kernel hardened. First, let me declare the Nix file’s skeleton, with the nixos.hardened module.

{
  flake.modules.nixos.hardened = {
    boot = {
      <<kernel-modules>>
      <<kernel-options>>
    };
  };
}

Kernel Modules

The very first thing to do is to load the tcp_bbr kernel module. It increases the connection speed of the system with a better congestion control. It is particularly interesting for my servers, as they may have to deal with high traffic if a crawler ever decides to explore all webpages offered by some websites I host. See this article by Nixcraft for more details.

kernelModules = ["tcp_bbr"];

Kernel Options

Next are a series of kernel options.

kernel.sysctl = {
  <<sysrq-key>>
  <<icmp>>
  <<icmp-no-accept-redirects>>
  <<icmp-no-send-redirects>>
  <<ip-source-route-packets>>
  <<syn>>
  <<tcp-time-wait>>
  <<bufferfloat>>
  <<latency>>
};

First, we’ll disable the magic SysRq key. Not that I expect anyone to have physical access to my servers, but it is a really powerful tool that I’d rather have off.

"kernel.sysrq" = 0;

Next, we’ll ignore ICMP broadcasts to avoid participating in Smurf attacks, and we’ll also ignore ICMP errors.

"net.ipv4.icmp_echo_ignore_broadcasts" = 1;
"net.ipv4.icmp_ignore_bogus_error_responses" = 1;

Speaking of ICMP, we won’t accept ICMP redirects to prevent some MITM attacks.

"net.ipv4.conf.all.accept_redirects" = 0;
"net.ipv4.conf.default_accept_redirects" = 0;
"net.ipv4.conf.all.secure_redirects" = 0;
"net.ipv4.conf.default.secure_redirects" = 0;
"net.ipv6.conf.all.accept_redirects" = 0;
"net.ipv6.conf.default.accept_redirects" = 0;

And we won’t send ICMP redirects (we’re not a router).

"net.ipv4.conf.all.send_redirects" = 0;

We’re stil not a router, so we’ll refuse IP source route packets, both on IPV4 and IPV6.

"net.ipv4.conf.all.accept_source_route" = 0;
"net.ipv6.conf.all.accept_source_route" = 0;

Now, let’s get some SYN flood protection.

"net.ipv4.tcp_syncookies" = 1;

And protection against TCP time-wait assassination hazards.

"net.ipv4.tcp_rfc1337" = 1;

We will also mitigate bufferfloat, including with BBR (hey, we enabled that above!)

"net.ipv4.tcp_congestion_control" = "bbr";
"net.core.default_qdisc" = "cake";

And lastly, we’ll reduce latency on IPV4.

"net.ipv4.tcp_fastopen" = 3;

And we should be good to go!