To mitigate the effort to maintain my personal server, I am considering to only expose ssh port to the outside and use its socks proxy to reach other services. is Portknocking enough to reduce surface of attack to the minimum?

  • aksdb@feddit.de
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 year ago

    Sure? It certainly detracts bots that now don’t discover the SSH port anymore. Against a targeted attack it’s less useful, but that is a very hard problem in any case. If someone is out to get you specifically, it will be a tough battle.

    • zaphod@lemmy.ca
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      If you’re worried about bots just use a non-standard port and move on. I did that on my own VPS just to cut down on log chatter and I get absolutely zero ssh attack attempts after the change.