公网 VPS 的 22 端口时刻面临全网自动化 Bot 的爆破攻击。本篇针对算法剥离、PAM 限制以及 Fail2ban 防爆破制定生产环境防御基线。
一、 剥离弱算法与严格配置 (/etc/ssh/sshd_config)
# 更改默认端口 Port 22222 # 仅允许 SSH Protocol 2 并禁用密码与空密码 Protocol 2 PermitRootLogin no PasswordAuthentication no PermitEmptyPasswords no PubkeyAuthentication yes # 强制限制加密算法与密钥交换协议 (禁用 RSA 1024/DSA/3DES) KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512 Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com MACs hmac-sha2-512-etm@openssh.com # 会话生命周期与心跳检测 ClientAliveInterval 300 ClientAliveCountMax 2 MaxAuthTries 3 MaxStartups 10:30:100
二、 Fail2ban 自动防御配置 (/etc/fail2ban/jail.local)
[sshd] enabled = true port = 22222 filter = sshd backend = systemd maxretry = 3 findtime = 600 bantime = 86400 action = iptables-multiport[name=SSH, port="22222", protocol=tcp]