Skip to main content

Command Palette

Search for a command to run...

SSH Security Best Practices: Hardening Linux Remote Access

Updated
•6 min read•View as Markdown
M
Hi, I'm Marek "Netbe" Lampart, a cybersecurity engineer with 25+ years of IT experience. I write about cybersecurity, Linux, networking, DevOps, system hardening, and secure infrastructure. CCNP Enterprise, SC-100, OSCP. Author of https://netbe.pl.

Update OpenSSH on Debian and Ubuntu:

sudo apt update
sudo apt upgrade openssh-server

Security updates often include:

  • vulnerability fixes

  • cryptographic improvements

  • bug fixes

  • compatibility improvements

Running outdated SSH software increases the risk of exploitation.


Disable Direct Root Login

The root account has unlimited privileges.

Allowing direct root SSH access creates a high-value target for attackers.

Edit the SSH configuration:

sudo nano /etc/ssh/sshd_config

Disable root login:

PermitRootLogin no

Restart SSH:

sudo systemctl restart ssh

Instead of logging in as root:

root

use a normal account with sudo privileges:

admin

This creates an additional security layer and improves accountability.


Use SSH Keys Instead of Passwords

Passwords are one of the weakest authentication methods because they can be attacked through:

  • brute force attempts

  • leaked credentials

  • password reuse

  • credential stuffing

SSH keys provide stronger authentication based on cryptographic principles.

Generate an SSH key pair:

ssh-keygen -t ed25519

Copy the public key to the server:

ssh-copy-id username@server-ip

Disable password authentication:

PasswordAuthentication no

Restart SSH:

sudo systemctl restart ssh

Benefits of SSH keys:

  • stronger authentication

  • resistance against brute-force attacks

  • no password transmission

  • better automation support


Use Modern Cryptographic Algorithms

SSH supports multiple cryptographic algorithms.

Older algorithms may have security weaknesses or compatibility concerns.

Check supported algorithms:

ssh -Q cipher

Modern recommendations:

  • Ed25519 keys

  • AES encryption

  • ChaCha20-Poly1305

  • SHA-2 based message authentication

Avoid outdated algorithms whenever possible.


Change the Default SSH Port

The default SSH port is:

22

Attackers automatically scan this port.

Changing the port does not replace proper security controls, but it can reduce automated scanning noise.

Edit:

sudo nano /etc/ssh/sshd_config

Example:

Port 2222

Restart SSH:

sudo systemctl restart ssh

Important:

Changing the port is only an additional measure. Strong authentication and proper configuration remain the primary defenses.


Limit SSH Users

Not every Linux user needs remote access.

Restrict SSH access:

AllowUsers admin securityuser

Or restrict groups:

AllowGroups sshusers

This reduces the number of accounts that attackers can target.

Check users:

cat /etc/passwd

Apply the principle of least privilege:

Only users who require SSH access should have it.


Disable Empty Passwords

Accounts without passwords should never be allowed to access a server.

In SSH configuration:

PermitEmptyPasswords no

This prevents authentication using empty passwords.


Configure SSH Login Protection

Attackers often perform automated login attempts.

Useful protections include:

  • firewall rules

  • fail2ban

  • rate limiting

  • IP allow lists

Install fail2ban:

sudo apt install fail2ban

Check status:

systemctl status fail2ban

Fail2ban monitors authentication logs and can automatically block suspicious IP addresses.


Use Firewall Restrictions

SSH should not be available from everywhere.

With nftables:

sudo nft add rule inet filter input tcp dport 22 accept

A stronger approach is allowing SSH only from trusted networks:

Office Network → SSH Allowed
Internet → Blocked

For production environments, consider:

  • VPN-only SSH access

  • bastion hosts

  • zero trust access solutions


Configure SSH Timeout Settings

Idle SSH sessions can remain open longer than necessary.

Example configuration:

ClientAliveInterval 300
ClientAliveCountMax 2

This disconnects inactive sessions after a defined period.

Benefits:

  • reduces session hijacking risk

  • improves resource management

  • limits exposure of unattended sessions


Disable Unnecessary SSH Features

SSH provides many features that may not be required.

Disable X11 forwarding:

X11Forwarding no

Disable TCP forwarding if unnecessary:

AllowTcpForwarding no

Disable agent forwarding:

AllowAgentForwarding no

Every enabled feature increases complexity and potential attack surface.


Monitor SSH Logs

Security requires visibility.

View SSH authentication logs:

journalctl -u ssh

On some systems:

cat /var/log/auth.log

Look for:

  • repeated failed logins

  • unknown usernames

  • unusual login times

  • unexpected source addresses

Logs are essential for detecting attacks and investigating incidents.


Audit SSH Configuration

Regularly review SSH configuration:

sshd -T

This displays the effective SSH configuration.

Check:

  • authentication methods

  • allowed users

  • enabled features

  • cryptographic settings

Security configurations should be reviewed periodically, not only after incidents.


SSH Hardening Checklist

Before exposing SSH on a production server:

✅ OpenSSH updated ✅ Root login disabled ✅ SSH keys enabled ✅ Password authentication disabled ✅ Users restricted ✅ Firewall configured ✅ Login monitoring enabled ✅ Fail2ban or equivalent protection enabled ✅ Strong cryptographic algorithms configured ✅ Unnecessary SSH features disabled


SSH Security in Modern Infrastructure

SSH remains a critical technology in:

  • Linux server administration

  • cloud infrastructure

  • DevOps environments

  • cybersecurity operations

  • network engineering

However, modern security strategies increasingly combine SSH with additional controls:

  • VPN access

  • multi-factor authentication

  • identity management

  • privileged access management

  • zero trust architecture

SSH should be treated as a highly privileged service that requires continuous protection.


Conclusion

SSH is one of the most important tools in Linux administration, but it is also one of the most attacked services.

A secure SSH configuration requires more than changing the default port or installing a security tool.

Effective SSH hardening includes:

  • strong authentication

  • minimal exposure

  • restricted access

  • secure cryptography

  • continuous monitoring

By implementing these security practices, administrators can significantly reduce the risk of unauthorized access and create a stronger foundation for protecting Linux infrastructure.


About the Author

Marek "Netbe" Lampart is a cybersecurity engineer with 25+ years of IT experience. He specializes in cybersecurity, Linux, networking, and secure infrastructure.

Certifications:

  • CCNP Enterprise

  • Microsoft Certified Cybersecurity Architect Expert (SC-100)

  • OSCP

More cybersecurity articles:

https://netbe.pl

2 views

More from this blog

M

Marek Netbe Lampart - Cybersecurity

26 posts