Answer the question
In order to leave comments, you need to log in
Answer the question
In order to leave comments, you need to log in
If the IP is often seen on the Internet, close unused ports, or open a VPN. About fail2ban - garbage, if you have authorization by public / private key, this is already 99.9% secure.
Disable password login or use a very complex password. Put fail2ban/ If the paranoia has not let go yet, then change the port number.
This is more than enough.
Is this a vulnerability?
You need network services (obviously, ssh, web and mail), so there will be open ports anyway. You can change them to non-standard ones, but the benefits of this are a little more than zero: scanning open ports on the interface takes a few seconds.
So you need to protect already open ones: authentication, filtering by IP / mac, fail2ban, authorization by certificate, etc.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question