3 ms·
Related question that has crossed my mind: what is this risk exposure of a linux server that is accessible via the internet that has port 22 enabled, and only h
by slap_shot 7y ago
Related question that has crossed my mind: what is this risk exposure of a linux server that is accessible via the internet that has port 22 enabled, and only has users with --disabled-password set (requiring ssh connection)?
As a follow up, what is increased benefit (if any) if port 22 is only accessible by a certain IP address (e.g. my home address)?
- jmngomes 7y agoIt's hard to quantify that "risk" in simple terms, but --disabled-password is a basic must as it seriously mitigates popular attack vectors like brute forcing. Filtering ssh connections at firewall level helps, and certainly reduces log entries for port scans and can halt less sophisticated attackers, but it doesn't mitigate attack vectors like a DDoS or a well funded actor.
- MrLabCoat 7y agoI do something similar but added a knock daemon and changed the default ssh port 22 to something else. So far I haven’t had any issues, fail2ban works, and it seems safe. I do have my home IP added to the whitelist and others set to drop. I was told in a networking class this is the second best way to protect ssh other than not running ssh. Any thoughts on this setup as well? Maybe oversights that I’m not seeing?