Log filtering has about as much impact on security as having overseas contractors watch your security cameras.
Log filtering has about as much impact on security as having overseas contractors watch your security cameras.
Ways I've seen this go wrong:
- someone fails to copy the port while communicating it
- the new whiz-bang AI security solution detects non-standard SSH ports and "quarantines" you while you try to figure out what happened and who to talk to
- someone manually "reviews" the firewall rules and locks you out of your own boxes
- someone builds a tool that uses SSH but doesn't allow non-standard ports
> someone manually "reviews" the firewall rules
This is a feature. Allowing Unfriendly AIs or incompetent morons to dictate security policy will go horribly wrong eventually; nonstandard SSH ports help make it painful for you to allow them to gain a foothold in the first place.
I have certain hosts behind a single IP and forward SSH to them on arbitrarily chosen ports.
Do I still get random logins on those ports?
Why yes I do.
Does putting SSH on a different port make any difference?
No it doesn't.
Putting SSH on a different port is either done for a specific reason, or you're just deluding yourself that you've somehow reduced your attack surface.
On the other 20+ boxen with ssh on port xxx22 the logs and f2b rules are much smaller - which means less hassle for the admin.
And on the boxen with services behind WG there is zero noise.
Naturally we're using keys only with all this. The reduced noise in the logs/rules/firewall are very handy.
[0] https://www.youtube.com/watch?v=xkrMsPiqG6M&feature=youtu.be...
Yes. The specific reason is "it makes log files less full of crap we have to sift through".