公网 VPS 的 22 端口时刻面临全网自动化 Bot 的爆破攻击。本篇针对算法剥离、PAM 限制以及 Fail2ban 防爆破制定生产环境防御基线。

一、 剥离弱算法与严格配置 (/etc/ssh/sshd_config)

# 更改默认端口
Port 22222

# 仅允许 SSH Protocol 2 并禁用密码与空密码
Protocol 2
PermitRootLogin no
PasswordAuthentication no
PermitEmptyPasswords no
PubkeyAuthentication yes

# 强制限制加密算法与密钥交换协议 (禁用 RSA 1024/DSA/3DES)
KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512
Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com
MACs hmac-sha2-512-etm@openssh.com

# 会话生命周期与心跳检测
ClientAliveInterval 300
ClientAliveCountMax 2
MaxAuthTries 3
MaxStartups 10:30:100

二、 Fail2ban 自动防御配置 (/etc/fail2ban/jail.local)

[sshd]
enabled = true
port = 22222
filter = sshd
backend = systemd
maxretry = 3
findtime = 600
bantime = 86400
action = iptables-multiport[name=SSH, port="22222", protocol=tcp]