Matthias Bach wrote:
Am Samstag 10 Januar 2009 schrieb Verner Kjærsgaard:
I takes a looooooooooong time to log in. Once in,
anything typed echoes
back as expected, for example "l" to get a directory listing. But - the
listing itself takes 10 - 15 seconds to emerge.
Is the server publically reachable? In my experience having SSH reachable via
port 22 can make the server pretty much stall due to the massive amount of
login attempts carried out by drones.
That is why I STRONGLY suggest moving ssh to a high port in the 5000 to 7000
range. There will be zero script kiddie login attempts from APNIC.
The process is simple:
(1) look at /etc/services and find an _open_ port where ever you want to move
(2) edit /etc/ssh/sshd_config and uncomment the port option and change the port
(3) to make the port change transparent to your users just specify the port
change in the system-wide config file '/etc/ssh/ssh_config' or if you only want
some users to have ssh access, then specify the change in the per user config
file '~/.ssh/config'. (see man ssh) The format is simply 'Host' and
separate lines like:
17:25 ecstasy:~> cat .ssh/config
Everything that uses ssh ( like fish://, scp, rsync, etc. ) will automatically
use the new port if you create the config file. As above, you need to specify
those hosts that are still on port 22 as well. Otherwise, the box will default
to trying ssh connections on its new default high port.
Now your annoying little login attempts that fill up your log files are a
thing of the past ;-)
David C. Rankin, J.D.,P.E.
Rankin Law Firm, PLLC
510 Ochiltree Street
Nacogdoches, Texas 75961
Telephone: (936) 715-9333
Facsimile: (936) 715-9339
To unsubscribe, e-mail: opensuse+unsubscribe(a)opensuse.org
For additional commands, e-mail: opensuse+help(a)opensuse.org