Secure Shell (SSH) is a widely used protocol for securely accessing remote systems. However, SSH servers are common targets for brute-force attacks, where attackers repeatedly try different username and password combinations to gain unauthorized access.
In this guide, we’ll explore several effective methods to protect your SSH server from brute-force attacks.
1. Use Strong Passwords or SSH Keys
The simplest way to prevent brute-force attacks is to enforce strong passwords or, better yet, use SSH key-based authentication instead of passwords.
- Disable password authentication and rely on SSH keys:
sudo nano /etc/ssh/sshd_config
Add or modify the following lines:
PasswordAuthentication no
PubkeyAuthentication yesThen restart SSH:
sudo systemctl restart sshd2. Change the Default SSH Port
Attackers often target the default SSH port (22). Changing the port reduces automated attacks.
- Edit the SSH config file:
sudo nano /etc/ssh/sshd_configChange the port number (e.g., 2222):
Port 2222Update firewall rules (if using UFW):
sudo ufw allow 2222/tcpRestart SSH:
sudo systemctl restart sshd3. Use Fail2Ban to Block Repeated Login Attempts
Fail2Ban automatically bans IPs that show malicious behavior, such as repeated failed login attempts.
- Install Fail2Ban:
sudo apt install fail2ban # Debian/Ubuntu
sudo yum install fail2ban # RHEL/CentOS- Configure Fail2Ban for SSH:
sudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local
sudo nano /etc/fail2ban/jail.localAdjust settings under [sshd]:
enabled = true
maxretry = 3
bantime = 1hRestart Fail2Ban:
sudo systemctl restart fail2ban4. Limit SSH Access to Specific IPs
If possible, restrict SSH access to trusted IPs using firewall rules (UFW/iptables) or sshd_config.
- Edit /etc/ssh/sshd_config:
