3 ms·
It's not even that. I have certain hosts behind a single IP and forward SSH to them on arbitrarily chosen ports. Do I still get random logins on those ports?
by opless 6y ago
It's not even that.
I have certain hosts behind a single IP and forward SSH to them on arbitrarily chosen ports.
Do I still get random logins on those ports?
Why yes I do.
Does putting SSH on a different port make any difference?
No it doesn't.
Putting SSH on a different port is either done for a specific reason, or you're just deluding yourself that you've somehow reduced your attack surface.
- p4bl0 6y agoIt clearly makes a difference for me. My servers which have SSH listening on port 22 have countless failed login attempts. Those running it on another random port have almost none.
- opless 6y agoThen you're clearly a statistical outlier :)
- edoceo 6y agoMe and @p4bl0. I've got one box with ssh on 22. Logs are very noisy and the rules from fail2ban grow and grow. On the other 20+ boxen with ssh on port xxx22 the logs and f2b rules are much smaller - which means less hassle for the admin. And on the boxen with services behind WG there is zero noise. Naturally we're using keys only with all this. The reduced noise in the logs/rules/firewall are very handy.
- crawlcrawler 6y agoI love Brian Regan but I have to say, even though I'm probably ruining one of his best jokes [0], that the plural form of "box" is not "boxen". [0] https://www.youtube.com/watch?v=xkrMsPiqG6M&feature=youtu.be&t=115 https://www.youtube.com/watch?v=xkrMsPiqG6M&feature=youtu.be...
- edoceo 6y agoOh, I'm aware it's "boxes". But, I got into the "boxen" habit in the middle 90s and now that I'm "old" I've chosen to become stubborn and stuck in my ways. Also, I think it's more fun. I've got other things to be pedantic about.
- dllthomas 6y agoI'm pretty sure "Unix boxen" predates Brian Regan's standup.
- zimpenfish 6y agoOpenSSH on port 22 gets at least one attempt a minute for me (and that's with fail2ban blocking IPs on a single failure.) Dropbear on port 2222 gets at most one an hour.
- zimpenfish 6y agoSince I cleaned out and restarted fail2ban yesterday (~1800BST), the sshd:22 filter has banned 291 IPs whilst the dropbear:2222 filter has banned 8.
- gsich 6y agoNo, that's the norm.
- a1369209993 6y ago> Putting SSH on a different port is either done for a specific reason, or [...] Yes. The specific reason is "it makes log files less full of crap we have to sift through".