3 ms·
I do something similar but added a knock daemon and changed the default ssh port 22 to something else. So far I haven’t had any issues, fail2ban works, and it
by MrLabCoat 7y ago
I do something similar but added a knock daemon and changed the default ssh port 22 to something else.
So far I haven’t had any issues, fail2ban works, and it seems safe.
I do have my home IP added to the whitelist and others set to drop.
I was told in a networking class this is the second best way to protect ssh other than not running ssh.
Any thoughts on this setup as well? Maybe oversights that I’m not seeing?