Why Not Use Port Knocking? (2012)
bsdly.blogspot.com
bsdly.blogspot.com
(Edit: For what it's worth, when I tried out knockd, it supported arbritrary port sequences, so you could easily have a 16 port sequence, making it as robust as you want. Timing however, was quite a pain. I had to use specific timeouts (relative to the RTT time from my network to my VPS), and manually enter each port in the sequence).
Personally, I've found that whitelisting IP's for SSH access, as well as a default block-all policy, disabled root login, and Key authentication have been enough to keep people out of my VPS.
Sure, seeing all of the denied traffic in the logs is annoying, but there's not much you can do about that (other than not log it).
Just remember that the port argument to `scp` is -P and not -p like it is for `ssh`. :p
He seems to be missing the point that this is only equivalent to a password if the attacker knows that it's there and can measure whether they've guessed correctly. Sure, if I tell someone that I've used a 48-bit password and allow them to get instantaneous feedback for each attempt, and don't block them completely after N guesses, it's not much of a barrier. On the other hand, if all they see is a non-responsive port and I make timing a factor and I do block them for guessing, it can significantly hamper their ability to make any guesses at the next (ssh) layer. Nobody's suggesting that the three-letter port knocking sequence should be the only security measure taken. It's purely an adjunct or enhancer for other measures, and for that it can be quite effective.
Yes: you can significantly reduce it by dynamically banning IP addresses which originate it.
And, of course, for any discussion of security, you need to specify what your threat environment is. Are you just locking down your home router, or are you running the first line of cyber defense for the CIA? He keeps moving the goalposts in order to knock down his opponents, which is why I can't take him seriously.
http://www.cipherdyne.org/blog/2013/10/port-knocking-why-you...
Scanning logs for intrusions and banning offending IP's deals approximately the same locus of issues that port knocking does.
Now if you absolutely must have deathly silence in your SSH logs, then only port knocking will do.
Open question -- is there any reason this is a bad idea?
It's not a bad policy overall, but of course it interferes with a legitimate use: a script which rapidly executes numerous SSH commands.
things like scp and rsync recycle connections across files though, so it hasn't been a problem in practice; ansible does too if you use openssh instead of paramiko
ps -- if someone knows iptables well, and is willing to share a similar script for failed connections, I would be grateful! But doing this across all ssh connections was easy enough that even I managed to get it working.
while whatever ; do
# hit host with a ssh command numerous times in loop
ssh user@host command ...
...
done
Banning more than X failed connection attempts from an IP in Y minutes is done with utilities like fail2ban, which wheedle that information from system logs.