{"id":434,"date":"2026-07-26T16:00:58","date_gmt":"2026-07-26T16:00:58","guid":{"rendered":"https:\/\/networkyy.com\/how-to-secure-ssh-access-linux-servers\/"},"modified":"2026-08-23T16:12:52","modified_gmt":"2026-08-23T16:12:52","slug":"how-to-secure-ssh-access-linux-servers","status":"publish","type":"post","link":"https:\/\/networkyy.com\/fr\/how-to-secure-ssh-access-linux-servers\/","title":{"rendered":"How to Secure SSH Access on Linux Servers"},"content":{"rendered":"<figure><img decoding=\"async\" src=\"https:\/\/images.pexels.com\/photos\/19813740\/pexels-photo-19813740.jpeg?auto=compress&#038;cs=tinysrgb&#038;dpr=2&#038;h=650&#038;w=940\" alt=\"How to Secure SSH Access on Linux Servers\" style=\"width:100%;height:auto;border-radius:8px;margin-bottom:24px;\" \/><figcaption>Photo by Markus Winkler on Pexels<\/figcaption><\/figure>\n<h1>How to Secure SSH Access on Linux Servers<\/h1>\n<p>SSH (Secure Shell) is the backbone of remote server administration, but an improperly configured SSH service can become your greatest security vulnerability. Every day, automated bots scan the internet for poorly secured SSH servers, attempting to gain unauthorized access through brute force attacks and credential stuffing.<\/p>\n<p>In this comprehensive guide, you&#8217;ll learn practical steps to harden your SSH configuration and protect your Linux servers from common attack vectors. Whether you&#8217;re managing a single VPS or an entire infrastructure, these security measures are essential for maintaining a robust defense.<\/p>\n<h2>Table of Contents<\/h2>\n<ul>\n<li><a href=\"#why-ssh-security-matters\">Why SSH Security Matters<\/a><\/li>\n<li><a href=\"#change-default-ssh-port\">Change the Default SSH Port<\/a><\/li>\n<li><a href=\"#disable-root-login\">Disable Root Login<\/a><\/li>\n<li><a href=\"#implement-key-based-authentication\">Implement Key-Based Authentication<\/a><\/li>\n<li><a href=\"#configure-ssh-idle-timeout\">Configure SSH Idle Timeout<\/a><\/li>\n<li><a href=\"#limit-user-access\">Limit User Access<\/a><\/li>\n<li><a href=\"#install-fail2ban\">Install and Configure Fail2Ban<\/a><\/li>\n<li><a href=\"#use-two-factor-authentication\">Use Two-Factor Authentication<\/a><\/li>\n<li><a href=\"#monitor-ssh-logs\">Monitor SSH Logs<\/a><\/li>\n<li><a href=\"#additional-security-measures\">Additional Security Measures<\/a><\/li>\n<\/ul>\n<h2 id=\"why-ssh-security-matters\">Why SSH Security Matters<\/h2>\n<p>SSH provides encrypted communication channels for remote server management, but it&#8217;s also a primary target for attackers. A compromised SSH service grants attackers complete control over your server, allowing them to steal data, install malware, or use your resources for malicious purposes.<\/p>\n<p>The default SSH configuration prioritizes accessibility over security, which is why hardening your SSH setup should be among your first tasks after deploying a new server. If you&#8217;re running cloud instances on platforms like <a href=\"https:\/\/kamatera.sjv.io\/engON1\" target=\"_blank\" rel=\"nofollow sponsored noopener\">Kamatera<\/a>, implementing these security measures becomes even more critical due to the public-facing nature of cloud infrastructure.<\/p>\n<h2 id=\"change-default-ssh-port\">Change the Default SSH Port<\/h2>\n<p>While security through obscurity shouldn&#8217;t be your only defense, changing the default SSH port from 22 to a non-standard port significantly reduces automated attack attempts. Most bot scans target port 22 exclusively.<\/p>\n<h3>Steps to Change SSH Port<\/h3>\n<p>Edit the SSH configuration file:<\/p>\n<pre><code>sudo nano \/etc\/ssh\/sshd_config<\/code><\/pre>\n<p>Find the line that reads <code>#Port 22<\/code> and change it to:<\/p>\n<pre><code>Port 2849<\/code><\/pre>\n<p>Choose any port number between 1024 and 65535 that isn&#8217;t already in use. Restart the SSH service:<\/p>\n<pre><code>sudo systemctl restart sshd<\/code><\/pre>\n<p>Important: Before closing your current session, test the new configuration by opening a new terminal and connecting with the new port to ensure you don&#8217;t lock yourself out.<\/p>\n<h2 id=\"disable-root-login\">Disable Root Login<\/h2>\n<p>Allowing direct root login via SSH is one of the most dangerous misconfigurations. Attackers know the root username exists on every Linux system, so they only need to crack the password.<\/p>\n<h3>Create a Sudo User First<\/h3>\n<p>Before disabling root login, ensure you have a regular user with sudo privileges:<\/p>\n<pre><code>sudo adduser adminuser\nsudo usermod -aG sudo adminuser<\/code><\/pre>\n<h3>Disable Root Login<\/h3>\n<p>Edit the SSH configuration:<\/p>\n<pre><code>sudo nano \/etc\/ssh\/sshd_config<\/code><\/pre>\n<p>Find and modify this line:<\/p>\n<pre><code>PermitRootLogin no<\/code><\/pre>\n<p>Restart SSH to apply changes:<\/p>\n<pre><code>sudo systemctl restart sshd<\/code><\/pre>\n<h2 id=\"implement-key-based-authentication\">Implement Key-Based Authentication<\/h2>\n<p>Password-based authentication is vulnerable to brute force attacks. SSH key pairs provide a cryptographically secure alternative that&#8217;s nearly impossible to crack.<\/p>\n<h3>Generate SSH Key Pair<\/h3>\n<p>On your local machine (not the server), generate a key pair:<\/p>\n<pre><code>ssh-keygen -t rsa -b 4096 -C \"your_email@example.com\"<\/code><\/pre>\n<h3>Copy Public Key to Server<\/h3>\n<pre><code>ssh-copy-id -i ~\/.ssh\/id_rsa.pub username@server_ip<\/code><\/pre>\n<h3>Disable Password Authentication<\/h3>\n<p>After confirming key-based login works, disable password authentication entirely:<\/p>\n<pre><code>sudo nano \/etc\/ssh\/sshd_config<\/code><\/pre>\n<p>Set these parameters:<\/p>\n<pre><code>PasswordAuthentication no\nChallengeResponseAuthentication no\nUsePAM no<\/code><\/pre>\n<p>Restart SSH:<\/p>\n<pre><code>sudo systemctl restart sshd<\/code><\/pre>\n<h2 id=\"configure-ssh-idle-timeout\">Configure SSH Idle Timeout<\/h2>\n<p>Idle SSH sessions pose a security risk, especially if someone walks away from an unlocked workstation. Configure automatic disconnection for inactive sessions.<\/p>\n<p>Edit the SSH configuration:<\/p>\n<pre><code>sudo nano \/etc\/ssh\/sshd_config<\/code><\/pre>\n<p>Add or modify these lines:<\/p>\n<pre><code>ClientAliveInterval 300\nClientAliveCountMax 2<\/code><\/pre>\n<p>This configuration disconnects idle sessions after 10 minutes (300 seconds \u00d7 2).<\/p>\n<h2 id=\"limit-user-access\">Limit User Access<\/h2>\n<p>Restrict SSH access to specific users or groups rather than allowing all system users to connect remotely.<\/p>\n<p>Edit the SSH configuration:<\/p>\n<pre><code>sudo nano \/etc\/ssh\/sshd_config<\/code><\/pre>\n<p>Add one of these directives:<\/p>\n<pre><code>AllowUsers adminuser deployuser<\/code><\/pre>\n<p>Or limit by group:<\/p>\n<pre><code>AllowGroups sshusers<\/code><\/pre>\n<p>Restart SSH to apply:<\/p>\n<pre><code>sudo systemctl restart sshd<\/code><\/pre>\n<h2 id=\"install-fail2ban\">Install and Configure Fail2Ban<\/h2>\n<p>Fail2Ban monitors log files for repeated failed login attempts and automatically blocks offending IP addresses, providing excellent protection against brute force attacks.<\/p>\n<h3>Install Fail2Ban<\/h3>\n<pre><code>sudo apt update\nsudo apt install fail2ban -y<\/code><\/pre>\n<h3>Configure SSH Protection<\/h3>\n<p>Create a local configuration file:<\/p>\n<pre><code>sudo nano \/etc\/fail2ban\/jail.local<\/code><\/pre>\n<p>Add this configuration:<\/p>\n<pre><code>[sshd]\nenabled = true\nport = 2849\nfilter = sshd\nlogpath = \/var\/log\/auth.log\nmaxretry = 3\nbantime = 3600<\/code><\/pre>\n<p>Start and enable Fail2Ban:<\/p>\n<pre><code>sudo systemctl start fail2ban\nsudo systemctl enable fail2ban<\/code><\/pre>\n<h2 id=\"use-two-factor-authentication\">Use Two-Factor Authentication<\/h2>\n<p>Adding two-factor authentication (2FA) creates an additional security layer beyond SSH keys. Google Authenticator provides a free, reliable solution for Linux servers.<\/p>\n<h3>Install Google Authenticator<\/h3>\n<pre><code>sudo apt install libpam-google-authenticator -y<\/code><\/pre>\n<h3>Configure for Your User<\/h3>\n<p>Run the initialization:<\/p>\n<pre><code>google-authenticator<\/code><\/pre>\n<p>Follow the prompts and scan the QR code with your authenticator app. Edit PAM configuration:<\/p>\n<pre><code>sudo nano \/etc\/pam.d\/sshd<\/code><\/pre>\n<p>Add this line at the top:<\/p>\n<pre><code>auth required pam_google_authenticator.so<\/code><\/pre>\n<p>Edit SSH configuration to enable challenge-response:<\/p>\n<pre><code>sudo nano \/etc\/ssh\/sshd_config<\/code><\/pre>\n<pre><code>ChallengeResponseAuthentication yes<\/code><\/pre>\n<p>Restart SSH:<\/p>\n<pre><code>sudo systemctl restart sshd<\/code><\/pre>\n<h2 id=\"monitor-ssh-logs\">Monitor SSH Logs<\/h2>\n<p>Regular log monitoring helps you identify attack patterns and potential security breaches. SSH authentication attempts are logged in <code>\/var\/log\/auth.log<\/code> on Debian-based systems.<\/p>\n<p>View recent SSH login attempts:<\/p>\n<pre><code>sudo grep 'sshd' \/var\/log\/auth.log | tail -50<\/code><\/pre>\n<p>Check for failed login attempts:<\/p>\n<pre><code>sudo grep 'Failed password' \/var\/log\/auth.log<\/code><\/pre>\n<p>Consider implementing centralized logging solutions for easier monitoring across multiple servers.<\/p>\n<h2 id=\"additional-security-measures\">Additional Security Measures<\/h2>\n<h3>Use a VPN for Additional Protection<\/h3>\n<p>For enhanced security, especially when accessing servers from untrusted networks, consider routing your SSH connections through a VPN service like <a href=\"https:\/\/nordvpn.sjv.io\/0ZoZWP\" target=\"_blank\" rel=\"nofollow sponsored noopener\">NordVPN<\/a>. This adds encryption and masks your actual IP address, providing an additional security layer.<\/p>\n<h3>Implement IP Whitelisting<\/h3>\n<p>If you access your server from known IP addresses, implement firewall rules to allow SSH connections only from those addresses:<\/p>\n<pre><code>sudo ufw allow from 203.0.113.5 to any port 2849\nsudo ufw enable<\/code><\/pre>\n<h3>Keep Your System Updated<\/h3>\n<p>Regularly update your system to patch security vulnerabilities:<\/p>\n<pre><code>sudo apt update && sudo apt upgrade -y<\/code><\/pre>\n<h3>Use SSH Protocol 2 Only<\/h3>\n<p>Ensure you&#8217;re using only SSH protocol 2, as protocol 1 has known vulnerabilities:<\/p>\n<pre><code>Protocol 2<\/code><\/pre>\n<p>This should already be the default on modern systems, but verification never hurts.<\/p>\n<h2>Conclusion<\/h2>\n<p>Securing SSH access on your Linux servers is not optional\u2014it&#8217;s a fundamental requirement for responsible server administration. By implementing these security measures, you&#8217;ve significantly hardened your server against common attack vectors and reduced the risk of unauthorized access.<\/p>\n<p>Remember that security is an ongoing process, not a one-time setup. Regularly review your security configurations, monitor logs for suspicious activity, and stay informed about emerging threats and best practices. The time you invest in properly securing SSH access today will save you from potentially devastating security breaches tomorrow.<\/p>\n<p>Start with the basics like disabling root login and implementing key-based authentication, then progressively add layers like Fail2Ban, two-factor authentication, and IP whitelisting. Each additional measure strengthens your security posture and makes your servers increasingly resilient against attacks.<\/p>\n<div style=\"background:#1a1a2e;color:#fff;padding:24px;border-radius:10px;margin-top:32px;border-left:4px solid #00ff88;\">\n<h3 style=\"color:#00ff88;margin-top:0;\">Follow Networkyy<\/h3>\n<p>Join 125,000+ IT professionals:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.instagram.com\/networkyy\" target=\"_blank\" style=\"color:#00ff88;\" rel=\"noopener\">Instagram @networkyy<\/a><\/li>\n<li><a href=\"https:\/\/www.facebook.com\/ITnetworkyy\/\" target=\"_blank\" style=\"color:#00ff88;\" rel=\"noopener\">Facebook Networkyy<\/a><\/li>\n<li><a href=\"https:\/\/www.threads.com\/@networkyy\" target=\"_blank\" style=\"color:#00ff88;\" rel=\"noopener\">Threads @networkyy<\/a><\/li>\n<li><a href=\"https:\/\/medium.com\/@mattouchi6\" target=\"_blank\" style=\"color:#00ff88;\" rel=\"noopener\">Medium<\/a><\/li>\n<\/ul>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Learn essential techniques to secure SSH access on your Linux servers. Protect against unauthorized access with these proven security practices.<\/p>","protected":false},"author":2,"featured_media":433,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":"","_yoast_wpseo_title":"","_yoast_wpseo_metadesc":"","_yoast_wpseo_focuskw":"","rank_math_title":"","rank_math_description":"","rank_math_focus_keyword":""},"categories":[9],"tags":[],"class_list":["post-434","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-linux-sysadmin"],"contentshake_article_id":"","brizy_media":[],"_links":{"self":[{"href":"https:\/\/networkyy.com\/fr\/wp-json\/wp\/v2\/posts\/434","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/networkyy.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/networkyy.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/networkyy.com\/fr\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/networkyy.com\/fr\/wp-json\/wp\/v2\/comments?post=434"}],"version-history":[{"count":1,"href":"https:\/\/networkyy.com\/fr\/wp-json\/wp\/v2\/posts\/434\/revisions"}],"predecessor-version":[{"id":599,"href":"https:\/\/networkyy.com\/fr\/wp-json\/wp\/v2\/posts\/434\/revisions\/599"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/networkyy.com\/fr\/wp-json\/wp\/v2\/media\/433"}],"wp:attachment":[{"href":"https:\/\/networkyy.com\/fr\/wp-json\/wp\/v2\/media?parent=434"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/networkyy.com\/fr\/wp-json\/wp\/v2\/categories?post=434"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/networkyy.com\/fr\/wp-json\/wp\/v2\/tags?post=434"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}