-
Notifications
You must be signed in to change notification settings - Fork 1
/
10 ¿Cómo cambiar el puerto de acceso ssh para protegernos de ataques a nuestro VPS Ubuntu 20.04 LTS?
135 lines (115 loc) · 4.91 KB
/
10 ¿Cómo cambiar el puerto de acceso ssh para protegernos de ataques a nuestro VPS Ubuntu 20.04 LTS?
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
¿Cómo cambiar el puerto de acceso ssh para protegernos de ataques a nuestro VPS Ubuntu 20.04 LTS?
Ahora vamos al archivo de configuración de sshd, para así modificar el puerto de acceso:
nano /etc/ssh/sshd_config
#Port 22
Lo activamos (quitando la hastag o almoadilla)
Y cambiamos el 22 por 25472
Port 25472
o
Port XXXXX si hemos puesto el puerto de cloudflare!
Que es en definitva un puerto que hemos abierto antes.
Y ejecutamos el proceso de guardado ya mencionado al principio de la guía.
Reiniciamos el servicio de ssh
service ssh restart
Y reiniciamos el servidor:
reboot
A estas alturas, la consola nos quedaría tal que así:
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
root@nombredelamaquina:~# ufw allow ssh
Rules updated
Rules updated (v6)
root@nombredelamaquina:~# ufw allow 25472
Rules updated
Rules updated (v6)
root@nombredelamaquina:~# ufw allow 53
Rules updated
Rules updated (v6)
root@nombredelamaquina:~# ufw allow http
Rules updated
Rules updated (v6)
root@nombredelamaquina:~# ufw allow https
Rules updated
Rules updated (v6)
root@nombredelamaquina:~# ufw enable
Command may disrupt existing ssh connections. Proceed with operation (y|n)? y
Firewall is active and enabled on system startup
root@nombredelamaquina:~# ufw status numbered
Status: active
To Action From
-- ------ ----
[ 1] 22/tcp ALLOW IN Anywhere
[ 2] 25472 ALLOW IN Anywhere
[ 3] 53 ALLOW IN Anywhere
[ 4] 80/tcp ALLOW IN Anywhere
[ 5] 443/tcp ALLOW IN Anywhere
[ 6] 22/tcp (v6) ALLOW IN Anywhere (v6)
[ 7] 25472 (v6) ALLOW IN Anywhere (v6)
[ 8] 53 (v6) ALLOW IN Anywhere (v6)
[ 9] 80/tcp (v6) ALLOW IN Anywhere (v6)
[10] 443/tcp (v6) ALLOW IN Anywhere (v6)
root@nombredelamaquina:~# ufw delete 1
Deleting:
allow 22/tcp
Proceed with operation (y|n)? y
Rule deleted
root@nombredelamaquina:~# ufw status numbered
Status: active
To Action From
-- ------ ----
[ 1] 25472 ALLOW IN Anywhere
[ 2] 53 ALLOW IN Anywhere
[ 3] 80/tcp ALLOW IN Anywhere
[ 4] 443/tcp ALLOW IN Anywhere
[ 5] 22/tcp (v6) ALLOW IN Anywhere (v6)
[ 6] 25472 (v6) ALLOW IN Anywhere (v6)
[ 7] 53 (v6) ALLOW IN Anywhere (v6)
[ 8] 80/tcp (v6) ALLOW IN Anywhere (v6)
[ 9] 443/tcp (v6) ALLOW IN Anywhere (v6)
root@nombredelamaquina:~# Status: active
To Action From
-- ------ ----
[ 1] 25472 ALLOW IN Anywhere
[ 2] 53 ALLOW IN Anywhere
[ 3] 80/tcp ALLOW IN Anywhere
[ 4] 443/tcp ALLOW IN Anywhere
[ 5] 22/tcp (v6) ALLOW IN Anywhere (v6)
[ 6] 25472 (v6) ALLOW IN Anywhere (v6)
[ 7] 53 (v6) ALLOW IN Anywhere (v6)
[ 8] 80/tcp (v6) ALLOW IN Anywhere (v6)
[ 9] 443/tcp (v6) ALLOW IN Anywhere (v6)
root@nombredelamaquina:~# ufw status numbered
Status: active
To Action From
-- ------ ----
[ 1] 25472 ALLOW IN Anywhere
[ 2] 53 ALLOW IN Anywhere
[ 3] 80/tcp ALLOW IN Anywhere
[ 4] 443/tcp ALLOW IN Anywhere
[ 5] 22/tcp (v6) ALLOW IN Anywhere (v6)
[ 6] 25472 (v6) ALLOW IN Anywhere (v6)
[ 7] 53 (v6) ALLOW IN Anywhere (v6)
[ 8] 80/tcp (v6) ALLOW IN Anywhere (v6)
[ 9] 443/tcp (v6) ALLOW IN Anywhere (v6)
root@nombredelamaquina:~# ufw delete 5
Deleting:
allow 22/tcp
Proceed with operation (y|n)? y
Rule deleted (v6)
root@nombredelamaquina:~# ufw status numbered
Status: active
To Action From
-- ------ ----
[ 1] 25472 ALLOW IN Anywhere
[ 2] 53 ALLOW IN Anywhere
[ 3] 80/tcp ALLOW IN Anywhere
[ 4] 443/tcp ALLOW IN Anywhere
[ 5] 25472 (v6) ALLOW IN Anywhere (v6)
[ 6] 53 (v6) ALLOW IN Anywhere (v6)
[ 7] 80/tcp (v6) ALLOW IN Anywhere (v6)
[ 8] 443/tcp (v6) ALLOW IN Anywhere (v6)
nano /etc/ssh/sshd_config
service ssh restart
reboot
root@nombredelamaquina:~# Connection to 123.456.789.10 closed by remote host.
Connection to 123.456.789.10 closed.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -