4 ms·
I also recommend changing the default SSH port.
by vahe 14y ago
I also recommend changing the default SSH port.
- rdl 14y agoI hate it when people do that, myself. Especially when you have a lot of other tools, many of which don't take port arguments easily. IMO best practice is to firewall off everything except some bastion hosts or VPN gateway.
- plusbryan 14y agoTotally agree. If you stick to good security practices, working around a non-standard port is an unnecessary annoyance imho.
- pseudonym 14y agoI actually do this on my personal server because more than one public wifi (and one of my previous jobs, at a public high school) disallowed outbound 22 connections.
- afhof 14y agoDon't do this. It adds almost no extra security and makes it hard for routers that prioritizes port 22 traffic as interactive.
- kristofferR 14y agoSure, it'll not stop dedicated manual intrusion attempts, but it will actually prevent a ton of automated bots from even just trying to connect with common passwords through SSH.
- corin_ 14y agoWhich is irrelevant if you have any one of: strong passwords, no passwords, fail2ban
- lhnn 14y agoWhich is relevant if you're one to actually look at your login attempt logs.
- falcolas 14y agoWorth looking at: http://bsdly.blogspot.com/2013/02/theres-no-protection-in-high-ports.html http://bsdly.blogspot.com/2013/02/theres-no-protection-in-hi...
- kristofferR 14y ago2222 is a dumb choice as an alternative port, it's both obvious and quite commonly used. I'm using a port on 4XXXX-range that's normally not used for anything and therefore not scanned by the bots unless all the 65536 ports are. The automated login attempts disappeared almost immediately, except for a few that were quickly blocked. Now the logs are clean from automated login bots, the only thing left are real dedicated hacking attempts that is worth pursuing further.
- jebblue 14y agoIt's what I do, you can't break in a door that doesn't exist, only those you know exist.
- hackerboos 14y ago>Sure, it'll not stop dedicated manual intrusion attempts, but it will actually prevent a ton of automated bots Doesn't take long to port scan a server.
- brokentone 14y agoGoing back to the classics, is port knocking still a thing? (I've been out of this discussion for a while, serious question)
- robflynn 14y agoOne of my freelance projects uses port knocking, but they're the only one I've worked with that have used it in recent years.
- webosb 14y agoguess i'm going back to port 22...
- vahe 14y agoI'm convinced too. Back to 22 we go.