Security Stack - What Blocks, What Only Watches

Security Stack - What Blocks, What Only Watches An architecture diagram generated by Archify. Internet · scanners · brute force · Architecture component Internet scanners · brute force CrowdSec bouncers · iptables/ipset + nginx Lua · Enforcement - these layers actually block traffic · 3 live CrowdSec bouncers iptables/ipset + nginx Lua 3 live CrowdSec LAPI + AppSec · CT142 · 10.10.0.142 · v1.7.6 · Enforcement - these layers actually block traffic CrowdSec LAPI + AppSec CT142 · 10.10.0.142 · v1.7.6 Fail2ban sshd jail · 24 hosts · 4 retries → 1 week · Enforcement - these layers actually block traffic Fail2ban sshd jail 24 hosts · 4 retries → 1 week Game nodes · node001 · node002 · wings-eu · Architecture component Game nodes node001 · node002 · wings-eu AbuseShield · proxy / tunnel / miner scanner · Architecture component AbuseShield proxy / tunnel / miner scanner Pterodactyl Panel · suspension target · Architecture component Pterodactyl Panel suspension target Estate agents · 38 Wazuh agents + node_exporter · Observability - sees everything, blocks nothing Estate agents 38 Wazuh agents + node_exporter Wazuh manager · CT144 · v4.14.6 · Observability - sees everything, blocks nothing Wazuh manager CT144 · v4.14.6 Wazuh indexer · CT143 · SCA is the live signal · Observability - sees everything, blocks nothing Wazuh indexer CT143 · SCA is the live signal Monitoring · CT160 · Prometheus · Alertmanager · Grafana · Observability - sees everything, blocks nothing Monitoring · CT160 Prometheus · Alertmanager · Grafana HTTP floods + AppSec SSH brute force pull decisions every 10 s scan containers + volumes suspend on HIGH confidence only wazuh-agent + node_exporter 1514 / 1515 filebeat scraped :9100 Enforcement - these layers actually block traffic Observability - sees everything, blocks nothing Legend Backend Database Security Message bus External

What actually blocks

  • • CrowdSec holds 33,885 active ban decisions, 33,881 of them from the community blocklist
  • • Three live bouncers: firewall on CT111 and on the LAX host, plus an nginx Lua bouncer
  • • Fail2ban runs one hardened sshd jail on 24 hosts, escalating to a one-week ban
  • • AbuseShield auto-suspends only HIGH-confidence findings; MEDIUM is never flag-stored

What only watches

  • • Wazuh collects from 38 enrolled agents, all Active and all on v4.14.6
  • • SCA (CIS benchmarks) is the live signal and is current for every agent
  • • Vulnerability detection silently 401'd for five months; fixed 2026-08-04
  • • Ubuntu agents still return zero vulnerability states - a feed gap, not a clean bill of health

Known gaps

  • • node_exporter on tcp/9100 is reachable from the public internet on all three hypervisors
  • • 8 of 9 Pterodactyl root_admin accounts have no 2FA
  • • CrowdSec AppSec bans uploads over 10 MiB uninspected and creates no decision or alert, so cscli looks clean while customers are blocked
  • • Every hardening playbook writes IPv4 rules only