[sllug-members]: SSH question

mark.k.spute at L-3com.com mark.k.spute at L-3com.com
Thu Apr 17 07:41:15 MDT 2008


Good Morning List

<alert=newbie>

I have a server at home (FC-1) running Bind, Sendmail, Apache, procmail,
etc.  It's my mail and webserver only.  I have been getting a large
number of dictionary attacks on SSH.  In excess of 500 per day.  I'm
trying to tightenup my security.  I started by changing SSH from
listening on port 22 to listening on port 3022.  I updated both
SSH.config and SSHD.config to listen on port 3022.  I also changed the
port forwarding on my router to forward port 3022 to the server's IP
address.  After reloading SSHD I tried to log in to my server using
putty from inside the firewall, and I've tried to login using putty from
outside the firewall, but I cannot connect.

What am I doing wrong?

Also, I am aware that security by obfuscation is not a good way to lock
down a server, but it's just the first layer of what I hope will be a
multi-layer approach.

</alert>

Thanks for listening.

Mark
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://sllug.org/pipermail/sllug-members/attachments/20080417/ac7984f3/attachment.html


More information about the sllug-members mailing list