@haruna_adoga: 89% of Linux attacks target SSH. Spin up a fresh server and check the auth log 90 seconds later. Hundreds of failed login attempts before the deployment script has even finished. Here are the 8 directives that lock SSH down properly. Every sysadmin needs this saved. Part 2 drops Sunday 🐧 Free Linux and RHCSA course on YouTube - link in bio 🐧 ssh hardening linux | harden ssh linux | sshd_config hardening | linux ssh security | openssh hardening | ssh brute force protection | linux server security | permitrootlogin no | passwordauthentication no | ssh ed25519 | allowusers sshd | linux hardening checklist | rhcsa ssh | linux cybersecurity | sshd config explained #linux #ssh #cybersecurity #sysadmin #devops
I dont use ssh. nothing to harden if it doesn't exist
2026-08-24 00:36:54
3
Alex Morgan :
Maybe just stop opening of SSH for entire world? It's should be available only from LAN, and if you need, you can connect to that LAN from remote, using VPN.
2026-08-22 14:55:48
5
christophel77 :
Change the SSH port. Add Fail2ban to SSH with a configuration that allows three login attempts and permanently bans the IP address. And to add an extra layer of security, use iptables or nftables to allow specific IP addresses to connect
2026-08-22 15:34:15
3
user4545619372411 :
loglevel verbose destroys your SSDs with useless log writes.
2026-08-22 09:29:28
3
lnnsntg379 :
But the most important part of that configuration is missing: AuthenticationMethods publickey
This rule requires authentication only by key pairs.
Also check for include files that overwrite the configuration. These are usually other files that are loaded in the background in addition to the initial configuration file.
Include /etc/ssh/sshd_config.d/*.conf
2026-08-22 13:39:47
2
feras alzarouq :
Changing the default SSH port is also useful.
2026-08-22 14:58:39
2
kaake :
nobody talking about `knockd`
2026-08-22 23:39:18
1
toxovi9948 :
I added my VPS to my tailscale network and allowed ssh only from the tailscale0 network in UFW 😉
2026-08-22 14:29:31
3
Tetrawhopper :
89% fanatasy number. Most attacks are on web interfaces, phishing and Active Directory.
2026-08-23 08:47:25
1
Krzysztof :
iptables ratelimit and sshguard
2026-08-22 09:22:31
1
PhoenixRider💚 :
we deploy a temporary firewall rule that only allows access to ssh ports from the one operator IP address while the system isn't even online yet. Faster, safer and easier overall
2026-08-22 12:09:46
1
i6tim :
Install crowdsec trust me. way more secure than fail2ban itself
2026-08-22 23:34:23
1
Carlo :
Or just use a strong password?
2026-08-23 09:37:17
1
Viktor :
Useful to study to CompTIA Security+ thanks you
2026-08-23 06:28:30
1
Frank Neumeister (Fritz) :
I don't run sshd......
2026-08-22 14:13:13
1
_jodi33 :
i have my ssh port changed to a diffrent port outside the 3000 range that most scanners go for
2026-08-22 13:37:59
1
xavz :
Beginner with Linux, but the wealth of knowledge here, wow!!!
2026-08-22 18:18:57
1
Tío Vik :
...you're missing the cherry on top: fail2ban. three bad attempt and you're out, ip banned for 15 days or more...😉😉😉
2026-08-22 13:26:25
1
user6990412909009 :
fail2ban
2026-08-22 11:24:59
2
User828648376373829 :
👍👍👍
2026-08-23 06:54:19
1
To see more videos from user @haruna_adoga, please go to the Tikwm
homepage.