computers:ssh_security
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| computers:ssh_security [2020/08/07 14:33] – chkuo | computers:ssh_security [2023/03/28 14:40] (current) – [Limit by IP address] chkuo | ||
|---|---|---|---|
| Line 18: | Line 18: | ||
| < | < | ||
| # / | # / | ||
| - | # allow intranet-ethernet | + | # allow intranet IPs (192.168.1.*) |
| + | # allow IPMB IPs (172.*.*.*) | ||
| # allow Academia Sinica IPs (140.109.*.*) | # allow Academia Sinica IPs (140.109.*.*) | ||
| - | sshd: 192.168.1., 140.109.: allow | + | sshd: 192.168.1., 172., 140.109.: allow |
| </ | </ | ||
| - | Other IP ranges: | + | |
| - | * Hinet: 118.160.0.0 - 118.167.255.255, | + | |
| ===== Check log files ===== | ===== Check log files ===== | ||
| Mac: | Mac: | ||
| Line 56: | Line 56: | ||
| # check client status | # check client status | ||
| sudo fail2ban-client status | sudo fail2ban-client status | ||
| + | sudo fail2ban-client status sshd | ||
| # check log | # check log | ||
| cat / | cat / | ||
| + | # unban | ||
| + | sudo fail2ban-client set sshd unbanip xxx.xxx.xxx.xxx | ||
| </ | </ | ||
computers/ssh_security.1596782007.txt.gz · Last modified: by chkuo