Re: ssh brute force attacks
Chris McMahon <[email protected]> Fri, 28 Jan 2011 23:21:23 -0700
| Newsgroups | gmane.org.user-groups.nmlug |
|---|---|
| Message-ID | <[email protected]> |
--===============1534374993== Content-Type: multipart/alternative; boundary=90e6ba4fc5145719b0049af6327b --90e6ba4fc5145719b0049af6327b Content-Type: text/plain; charset=ISO-8859-1 OK, I can't believe I'm posting this on Friday night, but do you have performance issues with OpenVPN? Every VPN I've ever used has been a serious drag to getting real work done. -C On Fri, Jan 28, 2011 at 10:38 PM, Geoff Chesshire <[email protected]>wrote: > Hi Ed, > > > We recently started using OpenVPN with certificates. I'm working on > > adding a password so it takes both a certificate and a password to > > connect a remote machine to the private network. > > I've been using OpenVPN for years, and have found it extremely reliable. > In fact, not only do I use it for external access, but I use it even > within the LAN, so that all services are accessible only through OpenVPN > (even ssh, dns, nfs, samba, email, apache, cups). Laptops keep their same > VPN IP addresses wherever they connect from, making DNS administration > easy. I make WAN access to OpenVPN come in using UDP through a secure > email port such as 143 or 993, as these few are generally not blocked by > public networks e.g. at airports. I forward this port to the usual > OpenVNP port (1194) on the VPN server on the LAN. Laptops try to connect > to the server first over the LAN at port 1194, and if that fails, fall > back to the WAN address+port. I use client/server PKI certificates, with > a pre-shared key during the handshake. Passwords on the client > certificates are possible, but I haven't used them. For laptops, I think > an encrypted root partition with a boot-up passphrase may be the way to go. > > > I'm thinking that OpenVPN makes external SSH obsolete. I could turn it > > off forcing me to start a whole VPN in order to get access to the > > internal interface. Has everybody else already gotten to this > > conclusion or are there lots of people still allowing remote SSH access? > > The only time I ever enable external SSH access is temporarily to allow > guest access from an external machine that is not (yet) included in the > VPN, and even then I use an obscure port and forwarded that to port 22 on > the target machine. The only port normally left open on the WAN is the > one for the VPN connection. Heck, I can even reliably restart OpenVPN > remotely via ssh over OpenVPN, with no open sockets lost and the > connection barely misses a heartbeat. > > Thanks, > Geoff > _______________________________________________ > NMLUG mailing list > [email protected] > http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug > --90e6ba4fc5145719b0049af6327b Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable <br><br>OK, I can't believe I'm posting this on Friday night, but d= o you have performance issues with OpenVPN?=A0=A0 Every VPN I've ever u= sed has been a serious drag to getting real work done.=A0=A0 <br><br>-C<br>= <br><div class=3D"gmail_quote"> On Fri, Jan 28, 2011 at 10:38 PM, Geoff Chesshire <span dir=3D"ltr"><<a = href=3D"mailto:[email protected]">[email protected]</a>></span> wrot= e:<br><blockquote class=3D"gmail_quote" style=3D"margin: 0pt 0pt 0pt 0.8ex;= border-left: 1px solid rgb(204, 204, 204); padding-left: 1ex;"> Hi Ed,<br> <div class=3D"im"><br> > We recently started using OpenVPN with certificates. =A0I'm workin= g on<br> > adding a password so it takes both a certificate and a password to<br> > connect a remote machine to the private network.<br> <br> </div>I've been using OpenVPN for years, and have found it extremely re= liable.<br> In fact, not only do I use it for external access, but I use it even<br> within the LAN, so that all services are accessible only through OpenVPN<br= > (even ssh, dns, nfs, samba, email, apache, cups). =A0Laptops keep their sam= e<br> VPN IP addresses wherever they connect from, making DNS administration<br> easy. =A0I make WAN access to OpenVPN come in using UDP through a secure<br= > email port such as 143 or 993, as these few are generally not blocked by<br= > public networks e.g. at airports. =A0I forward this port to the usual<br> OpenVNP port (1194) on the VPN server on the LAN. =A0Laptops try to connect= <br> to the server first over the LAN at port 1194, and if that fails, fall<br> back to the WAN address+port. =A0I use client/server PKI certificates, with= <br> a pre-shared key during the handshake. =A0Passwords on the client<br> certificates are possible, but I haven't used them. =A0For laptops, I t= hink<br> an encrypted root partition with a boot-up passphrase may be the way to go.= <br> <div class=3D"im"><br> > I'm thinking that OpenVPN makes external SSH obsolete. =A0I could = turn it<br> > off forcing me to start a whole VPN in order to get access to the<br> > internal interface. =A0Has everybody else already gotten to this<br> > conclusion or are there lots of people still allowing remote SSH acces= s?<br> <br> </div>The only time I ever enable external SSH access is temporarily to all= ow<br> guest access from an external machine that is not (yet) included in the<br> VPN, and even then I use an obscure port and forwarded that to port 22 on<b= r> the target machine. =A0The only port normally left open on the WAN is the<b= r> one for the VPN connection. =A0Heck, I can even reliably restart OpenVPN<br= > remotely via ssh over OpenVPN, with no open sockets lost and the<br> connection barely misses a heartbeat.<br> <br> Thanks,<br> <font color=3D"#888888">Geoff<br> </font><div><div></div><div class=3D"h5">__________________________________= _____________<br> NMLUG mailing list<br> <a href=3D"mailto:[email protected]">[email protected]</a><br> <a href=3D"http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug" target=3D"_b= lank">http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug</a><br> </div></div></blockquote></div><br> --90e6ba4fc5145719b0049af6327b-- --===============1534374993== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ NMLUG mailing list [email protected] http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug --===============1534374993==--