Local Guard Security Setup Guide
Learn how to configure and manage Local Guard, a self-security enhancement module operating within individual servers.
📋 Overview
Local Guard is a security-specialized sub-module of the GIIP agent that monitors abnormal signs occurring within the server itself, independent of network security. It functions as a Host-based Intrusion Prevention System (HIPS).
🛠️ Key Security Features
1. Login Auditing
- Records all SSH and local login attempts.
- Specifically tracks direct logins to the
rootaccount or repeated attempts at short intervals in real-time.
2. Critical File Protection
- Originally blocks or immediately sends warnings for modification attempts on core system files such as
/etc/shadoworC:\Windows\System32\config.
3. Local Firewall Policy Integration
- Immediately reflects security policies set in the GIIP console to the corresponding server's
iptablesor Windows Firewall to block access from unauthorized IPs.
🔍 Configuration & Operation
- Activation Status: You can toggle the operation status of Local Guard On/Off in the [Server Detail] > [Security Settings] tab.
- Exception Handling: Register actions of backup programs or antivirus software modifying files in the 'Whitelist' to prevent false positives.
⚠️ Emergency Response
When an intrusion attempt is detected by Local Guard, the following actions are possible:
- Force Session Termination: Immediately disconnect the terminal session being used by the attacker.
- Permanent IP Block: Register the attacker's source IP in a blacklist to prevent access from all servers belonging to the project.
💡 Important Notes
- Enabling the Local Guard feature may consume a small amount of additional system resources (less than 1% CPU).
Troubleshooting
| Symptom | Cause | Solution |
|---|---|---|
| Legitimate backup/antivirus activity is falsely flagged as file tampering | The program is not registered in the Whitelist | Register the backup program or antivirus software in the Whitelist. |
| Local Guard is not working | Local Guard is set to Off in [Security Settings] | Toggle Local Guard On in the [Server Detail] > [Security Settings] tab. |
| A blocked attacker IP keeps attempting access from other servers | The block was applied to only one server | Use Permanent IP Block to add it to the blacklist for all servers in the project. |
| Security policies set in GIIP are not reflected on the server | Local firewall (iptables/Windows Firewall) integration is not applied | Save the policy in the console, then verify the local firewall policy integration status. |
Version: 1.0
Last Updated: 2026-03-19
Source: giipv3/public/help/local-guard.en.md