8 ms·
Thanks for all the advice! You've definitely introduced me to some things I've never considered before. Now to cram more learnings into my brain... :)
by robmclarty 13y ago
Thanks for all the advice! You've definitely introduced me to some things I've never considered before. Now to cram more learnings into my brain... :)
- mschuster91 13y ago:D Yet another thing that just came to my mind: use different operating systems and software stacks on the two bastion hosts (or, at least, OS A on the bastion host and OS B on the "normal" hosts). You may, for example, choose a *BSD variant for the bastion host, and a Linux variant for the web hosts. Simple reason: if the software stack of one of the hosts gets compromised (e.g. a 0day is found in OpenSSH), then the other bastion host cannot be compromised with the same exploit.