3 ms·
Why do you run ssh on a non-default port?
by deoxxa 12y ago
Why do you run ssh on a non-default port?
- rurounijones 12y agoBrute-forcers only hit the default port. If there is no response on the default port then they just move on to greener servers. Moving off the default port is a good way to avoid your logs getting filled up with failed login attempt messages.
- tacticus 12y agoThough something like fwknop would be a nicer way of resolving that.
- thejosh 12y agoWhy not? You can always create an entry in .ssh/config for the host with the port if needed. Host example.com IdentityFile ~/.ssh/id_rsa_example User foobar Hostname 127.0.0.1 Port 1234
- kawsper 12y agoAlways run SSH on a privileged port. An attacker could potentially run a rogue SSH instance on a non-privileged port and capture logins for other accounts. If you run it on a privileged port (1024, or lower), it means that it can be trusted to root-level.
- buro9 12y agoTo reduce noise in the logs so that I can focus on the more determined attackers rather than script kiddies just hitting the default ports on every IP. It does nothing for security, but does help to reduce noise which in turn helps to reduce the time it takes to manage this stuff.