4 ms·
>Restrict SSH to your IP (optional but recommended) That's dangerous, because what if your IP changes? You'll be locked out?
by Thorrez 1y ago
>Restrict SSH to your IP (optional but recommended)
That's dangerous, because what if your IP changes? You'll be locked out?
- fabian2k 1y agoThe only thing you really need to do with SSH is to use keys with it, not passwords. That should be secure enough for almost all cases. Another layer on top is useful to remove the noise from the logs. And if you have anything aside from SSH on the server that doesn't need to be public, restricting it via a VPN or something like that is useful anyway. Most other software that listens on your server has likely much more attack surface than SSH.
- hebelehubele 1y agoAlso, change the port sshd listens to from 22 to something else. Cuts down on the noise considerably.
- dan15 1y agoThis doesn't really matter if you disable password authentication.
- justoreply 1y agomy sshd just listen on ipv6, no longer noise on the logs
- fastball 1y agoYou can always reset stuff from the Hetzner dashboard. But yes, rather than locking it down to some dynamic residential IP, it would be better to set up something like Tailscale, or to have a VPN with a dedicated static IP.
- deleted 1y ago[deleted]
- codegeek 1y agoYea agreed. Its dangerous. Lot of people have dynamic IPs at their home. Once you have setup ssh keys and disabled root login, you should be good to go.
- doublerabbit 1y agoAnd change the port from 22. I tend to use the 400 range for SSH ports. You'll be surprised how many bots get thwarted by just changing the port.
- clickety_clack 1y agoAgreed. You should assume you have a dynamic IP unless you’ve specifically arranged for a static one. It’s a “business” feature where I live at least, so personal internet connections will be dynamic.