From owner-freebsd-questions@FreeBSD.ORG Fri Dec 28 20:19:44 2007 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id B2AA816A417 for ; Fri, 28 Dec 2007 20:19:44 +0000 (UTC) (envelope-from bri@brianwhalen.net) Received: from entwistle.sonicboom.org (entwistle.sonicboom.org [66.93.34.170]) by mx1.freebsd.org (Postfix) with ESMTP id 86B4313C458 for ; Fri, 28 Dec 2007 20:19:44 +0000 (UTC) (envelope-from bri@brianwhalen.net) Received: from [127.0.0.1] (entwistle.sonicboom.org [66.93.34.170]) by entwistle.sonicboom.org (8.14.2/8.14.1) with ESMTP id lBSKJiEw067593 for ; Fri, 28 Dec 2007 12:19:44 -0800 (PST) (envelope-from bri@brianwhalen.net) Message-ID: <47755A60.6030301@brianwhalen.net> Date: Fri, 28 Dec 2007 12:19:44 -0800 From: Brian User-Agent: Thunderbird 2.0.0.9 (Windows/20071031) MIME-Version: 1.0 To: freebsd-questions@freebsd.org References: <20071218040802.GB6678@ayn.mi.celestial.com> <20071218054048.6EE7.A38C9147@seibercom.net> <20071228171733.GB89701@demeter.hydra> In-Reply-To: <20071228171733.GB89701@demeter.hydra> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Subject: Re: SSH through port forwarding X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 28 Dec 2007 20:19:44 -0000 Chad Perrin wrote: > On Tue, Dec 18, 2007 at 05:44:11AM -0500, Gerard Seibert wrote: > >>> On December 18, 2007 at 12:47AM sham khalil wrote: >>> >>> once you open port 22 to public ip, you'll get people try to bruteforce your >>> machine. >>> if you don't want that set sshd to listen to a higher number like 5522 >>> then forward port 5522 from the router to the internal machines. >>> >>> unfortunately for wrt54g, you can't forward port 5522 to 22 for internal >>> machine. >>> >> Security through obscurity is a poor substitute for security. Port scanners >> will eventually find that port also. >> > > One needs something else for security against brute-force attempts, but > changing the port number does help cut down on the amount of bandwidth > consumption on the LAN side of your router by allowing the router to > ignore/deny all incoming traffic on port 22. > > Has denyhosts been considered? Brian