Stop opening your SSH port to the whole internet

SSH, Remote Access & Zero Trust On Linux

Stop opening your SSH port to the whole internet

Technical Briefing | 10/7/2026

You probably have port 22 open on your edge firewall because you need to reach your servers from home. That is a siren song for every script kiddie and botnet scanner on the planet. I have watched logs fill up with thousands of failed password attempts, and it only takes one misconfiguration or weak user password to turn your server into a spam relay.

The SSH port shouldn’t be a public target

Even if you force key-based authentication, leaving the port exposed is asking for trouble. CVEs in sshd pop up every so often, and you don’t want to be patching while under active exploitation. The right move is to move your access behind a tunnel or a zero-trust relay. You can use WireGuard, or if you want something that integrates better with existing auth stacks, Tailscale or Headscale are excellent ways to hide your SSH port from the public view entirely.

iptables -A INPUT -p tcp --dport 22 -s 100.64.0.0/10 -j ACCEPT
iptables -A INPUT -p tcp --dport 22 -j DROP

  • Binding your SSH listener to an internal VPN interface instead of the public IP
  • Removing password auth entirely if you have not already done so
  • Using Port Knocking if you absolutely must maintain a direct public connection

If you are worried about locking yourself out, always test your new firewall rules with a long-running tmux session and a fallback management interface like a cloud serial console. Once you verify your VPN connectivity, you’ll sleep much better knowing that a simple Nmap scan from the outside world sees absolutely nothing.

Linux Admin Automation  |  © www.ngelinux.com  |  10/7/2026

0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
Newest
Oldest Most Voted