Change SSH port and secure access
Reduce intrusion attempts by changing the default SSH port.
What this tutorial does
The tutorial "Change SSH port and secure access" helps you achieve this goal:
Reduce intrusion attempts by changing the default SSH port.
Debian/Ubuntu
-
Edit SSH configuration: nano /etc/ssh/sshd_config - Edit: Port 2222 (choose a port between 1024 and 65535)
- Disable direct root login: PermitRootLogin no
-
Disable password authentication (if SSH key configured): PasswordAuthentication no - Limit allowed users: AllowUsers deploy
-
Allow new port in iptables: iptables -A INPUT -p tcp --dport 2222 -j ACCEPT -
Remove old SSH port from rules: iptables -D INPUT -p tcp --dport 22 -j ACCEPT -
Backup iptables: netfilter-persistent save -
Restart SSH: systemctl restart sshd - IMPORTANT: Test the connection with the new port BEFORE closing the current session.
-
Connecting with the new port: ssh -p 2222 deploy@IP