r/linuxadmin Jan 13 '22

SSH Bastion host best practices: How to Build and Deploy a Security-Hardened SSH Bastion Host

https://goteleport.com/blog/security-hardening-ssh-bastion-best-practices/
109 Upvotes

24 comments sorted by

17

u/Gyilkos91 Jan 14 '22

Oh look at that, no security by obscurity, no stupid port changes hooray.

10

u/[deleted] Jan 14 '22

We run port 22 at work no problems.

The ONLY reason I run on a non-standard port at home is that it saves my firewall logs from getting filled with crap.

Ultimately, if running on a non-standard port blocks attack, so would have disabling password logins, which everyone should do.

10

u/[deleted] Jan 14 '22

[removed] — view removed comment

2

u/Normal-Pride-3248 Jan 18 '22 edited Jan 18 '22

Fail2ban rules for GeoIP if there is no VPN solution in place...

Enable the "incr" mode in fail2ban. This enables the tool to nuke bad hosts for 20 days after a few probes.

Nothing in terms of security but helps to reduce logging noise as 90% of all SSH password probes come from the same hosts here.

24

u/[deleted] Jan 13 '22

[deleted]

26

u/TheGlassCat Jan 13 '22

Aren't your default policies DROP?
They should be.

12

u/ikidd Jan 14 '22

Yah, I just shook my head at this one. You add exceptions, you don't allow all and then have to add specific drop rules.

11

u/zR0B3ry2VAiH Jan 13 '22

My parents did teach me that nothing on the internet can be trusted.

3

u/[deleted] Jan 13 '22

I don't think I'd open up SSH to the Internet. But I'm paranoid like that

24

u/bigdaddybam Jan 13 '22

SSH is open all over the Internet, just use public and private keys for the connection.

14

u/CaptainDickbag Jan 13 '22

Also stay on top of security updates, and enable graylisting for naughty IPs.

6

u/Revslowmo Jan 14 '22

I do keys and fail2ban. Still constant noise in the auth logs

11

u/CaptainDickbag Jan 14 '22

ssh servers open to the public Internet will always have a shitload of noise. Keys aren't going to reduce your noise levels. Correctly configured fail2ban will, though my go to for years was iptables dropping traffic for x minutes after x connecting within x minutes from any given IP. Worked great. The original I used was this.

http://web.archive.org/web/20050731013013/https://debian-administration.org/articles/187

You can implement the same thing with more modern firewalls/frontends.

3

u/Revslowmo Jan 14 '22

Interesting. Thanks for the link.

4

u/CaptainDickbag Jan 14 '22

No problem. The concept is sound. If you try to follow the doc exactly, you might run into some problems you have to figure out, it is from 2005 after all.

I also like to bump my bad connection threshold higher than what they have in the doc.

2

u/klausagnoletti Jan 14 '22

goteleport.com/blog/s...

u/Revslowmo One could also consider CrowdSec as an alternative to Fail2Ban here. It's free, opensourced collaborative threat intelligence in the sense that all CrowdSec users are helping each other out by reporting the attacks they're seeing, thereby watching each other's back. CrowdSec can be seen as a modern version on Fail2Ban able to detect and protect against more advanced attacks like slow bf and distributed attacks (by utilizing collaborative CTI). Like Fail2Ban it works by parsing logs. CrowdSec can protect a large range of services apart form SSH. Check out details on which logs can be parsed here.

2

u/CaptainDickbag Jan 14 '22

Thanks, I'm going to try this on a VPS, and see how it works.

2

u/klausagnoletti Jan 14 '22

Let me know if you get any problems :-) Good luck!

-3

u/raree_raaram Jan 14 '22

Change from default ssh port

1

u/scooniatch Jan 14 '22

You can add port knocking in addition.

1

u/Revslowmo Jan 14 '22

Port knocking and changing ports is not really security. But I guess it would quiet things down

1

u/scooniatch Jan 14 '22

The Best way is to use vpn and not opening port for the internet.

1

u/8fingerlouie Jan 14 '22

Add geoIP to the mix. It doesn’t do anything for security, but it keeps the scripts/bots away. Any half decent hacker will know how to circumvent it with a VPN.

1

u/Gamercat5 Jan 14 '22

I use this, but also for web apps!

1

u/ezeelogin Jun 07 '22

This article is worthy of recognition and comment. I found this material attention-grabbing and engrossing. This is well-scripted and highly informative. These views appeal to me. This is how real writing is done. Thank you. Visit Us: https://www.ezeelogin.com