LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 10-12-2016, 09:42 AM   #16
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 11,258
Blog Entries: 4

Rep: Reputation: 4140Reputation: 4140Reputation: 4140Reputation: 4140Reputation: 4140Reputation: 4140Reputation: 4140Reputation: 4140Reputation: 4140Reputation: 4140Reputation: 4140

No matter what port-number you choose, a simple port-scan will quickly find whatever is the new one.

If you want to actually close your system from such attacks, you must use an entirely different strategy. I suggest that you should run OpenVPN with digital certificates and tls-auth protection, as I describe in my blog-post How to Build a 'Dwarvish Door' With OpenVPN.

The only way to access any of the services such as ssh is to successfully pass through OpenVPN first, and the only way to do that is to possess two digital certificates. The first is needed to cause OpenVPN to even respond to you: any port-scan will say that OpenVPN is not even there. The second, which is one-of-a-kind and issued only to you, is needed to actually pass through the gantlet.

There are no "passwords" (nee "PSKs = Pre-Shared Keys"). Only 1,024 or 4,096 bits of pure randomness. You either possess it, or you don't. (And, your uniquely-assigned key must not have been "revoked.")

Once you are "inside," you can use ssh and avail yourself of other services. (And these, too, should be using one-of-a-kind digital certificates. There's not a password in sight.)

To an outsider, your system is a smooth, featureless wall. The secret door and secret drawbridge is completely hid. Authorized users pass through quickly and easily. Intruders can't even begin. With these protections in place, the number of access-attempts drops to ...

... zero. And stays there.

Last edited by sundialsvcs; 10-12-2016 at 09:46 AM.
 
Old 10-12-2016, 11:22 AM   #17
linux4evr5581
Member
 
Registered: Sep 2016
Location: USA
Posts: 275

Rep: Reputation: Disabled
Something that I picked up off this site is that you can make it to allow only 1 special port with key-only ssh and having a restrictive /etc/hosts.xfile(s) Im not sure but if you do this you may need to do advanced stuff like load balancing and routing techniques. Maybe also you can even stealth this port...
 
  


Reply

Tags
ssh access


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] IPtables : ssh port forwarding one port to another port issue routers Linux - Networking 7 08-07-2018 08:41 AM
SSH is still listening on port 22 after change to a new port? boyla Linux - Server 6 04-08-2011 12:26 AM
change ssh port sandeepthug Linux - Server 9 03-11-2010 04:04 PM
Howto do Secured ssh from port https or port80(standard) to ssh d listening port 22 ? Xeratul Linux - General 4 11-23-2006 06:09 AM
iptables help! DROP ssh port, but allow to connect to ssh if from 2222 port kandzha Linux - Networking 4 09-13-2006 09:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 07:32 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration