8 ms·
Have you tried/are you interested in setting a different port number on the server? Setting a different port number and using ssh_config on your clients (so you
by andrewSC 9y ago
Have you tried/are you interested in setting a different port number on the server? Setting a different port number and using ssh_config on your clients (so you don't have to keep specifying the different port) helps a ton. I've done this with a Google 2FA solution[1] and honestly haven't seen a single rogue attempt.
-----
[1] https://www.digitalocean.com/community/tutorials/how-to-set-up-multi-factor-authentication-for-ssh-on-ubuntu-16-04 https://www.digitalocean.com/community/tutorials/how-to-set-...
- techcode 9y agoWhile most guides/books on initial setting up sshd explain the usual stuff - e.g.: allow only key auth, no root ...etc. Changing ssh port from standard (I literally forgot, is it 22?) to something else is one of those things you pick up in the field. Usually only once you actually had to maintain production servers. And hopefully before some of the fancy things (e.g.: port-knockers) failed and locked you out :) Changing port is super simple to configure and yet it cuts out 99.9% of noise (if not 100%) from brute-force attempts that otherwise might make you ignore alarms ...
- ganeshkrishnan 9y agoI will have to do this. Running a startup means some tasks are forever in the "todo" area