[arm-allstar] SSH port attempts

Doug Crompton wa3dsp at gmail.com
Sun Apr 5 23:38:14 EDT 2020


Just a note before anyone gets totally carried away or overly paranoid
about ssh ports.  For the most part users DO NOT need to forward the ssh
port (222 default) on their servers. The only reason to do this is if you
want remote access to your Hamvoip. Meaning you go somewhere else outside
of your local Internet and want access back to your Hamvoip. Not port
forwarding or only port forwarding on an occasion when you need it solves
this problem!

If you do forward your ssh port change it to another random port number.
Use a 5 digit number greater than 10000 and less than 65535 and not one
that is locally being used by something else on your LAN.

In either case use a good password. If you use at least 10 characters of
mixed upper/lower/numeric/special characters and you don't share it you
won't get compromised.

Don't publish your port or password. If either are compromised change them.

Use non-hamvoip software or script recommendations at your own risk. We
will have a solution soon for protecting ssh beyond the above
recommendations in extreme situations.

*73 Doug, WA3DSP*
*http://wa3dsp.org <http://wa3dsp.org>*


More information about the ARM-allstar mailing list