I’d like to gather as much information on hardening Windows Repos and Proxies, and have it all posted below to help others if they are looking for information on this topic.
We all know the Veeam B&R Server has a security checklist which gives you very clear concise things to do for security. There is also the LHR. Following the DISA STIG, or using the ISO is a great way to make sure the software portion of your LHR is safe.
With the above, you still have to protect the underlying hardware. Everything from physically getting at the Disk, Server Bios/UEFI, destroying the hardware, to SSH ports on a SAN, and use of MFA for logins to a SAN to prevent access. Turning on immutable snapshots and 4-eyes features on the storage pools are also great to implement. Lets not forget the VLAN for your management networks and who is allowed to see those IP’s.
Even with all of this, I still don’t see specific documents for hardening a Windows Repository or Proxy server. Many of the same guidelines should be followed as the Veeam B&R server but there are some differences. Veeam has great guides for which ports need to be open, but I’d like to see more on the security for other devices in a single location.
If there are any settings you guys configure on every install post them below and hopefully we can help someone in the future stay safe!
