Re: ssh brute force attacks

Chris McMahon <[email protected]> Fri, 28 Jan 2011 23:21:23 -0700
Newsgroups gmane.org.user-groups.nmlug
Message-ID <[email protected]>
--===============1534374993==
Content-Type: multipart/alternative; boundary=90e6ba4fc5145719b0049af6327b

--90e6ba4fc5145719b0049af6327b
Content-Type: text/plain; charset=ISO-8859-1

OK, I can't believe I'm posting this on Friday night, but do you have
performance issues with OpenVPN?   Every VPN I've ever used has been a
serious drag to getting real work done.

-C

On Fri, Jan 28, 2011 at 10:38 PM, Geoff Chesshire <[email protected]>wrote:

> Hi Ed,
>
> > We recently started using OpenVPN with certificates.  I'm working on
> > adding a password so it takes both a certificate and a password to
> > connect a remote machine to the private network.
>
> I've been using OpenVPN for years, and have found it extremely reliable.
> In fact, not only do I use it for external access, but I use it even
> within the LAN, so that all services are accessible only through OpenVPN
> (even ssh, dns, nfs, samba, email, apache, cups).  Laptops keep their same
> VPN IP addresses wherever they connect from, making DNS administration
> easy.  I make WAN access to OpenVPN come in using UDP through a secure
> email port such as 143 or 993, as these few are generally not blocked by
> public networks e.g. at airports.  I forward this port to the usual
> OpenVNP port (1194) on the VPN server on the LAN.  Laptops try to connect
> to the server first over the LAN at port 1194, and if that fails, fall
> back to the WAN address+port.  I use client/server PKI certificates, with
> a pre-shared key during the handshake.  Passwords on the client
> certificates are possible, but I haven't used them.  For laptops, I think
> an encrypted root partition with a boot-up passphrase may be the way to go.
>
> > I'm thinking that OpenVPN makes external SSH obsolete.  I could turn it
> > off forcing me to start a whole VPN in order to get access to the
> > internal interface.  Has everybody else already gotten to this
> > conclusion or are there lots of people still allowing remote SSH access?
>
> The only time I ever enable external SSH access is temporarily to allow
> guest access from an external machine that is not (yet) included in the
> VPN, and even then I use an obscure port and forwarded that to port 22 on
> the target machine.  The only port normally left open on the WAN is the
> one for the VPN connection.  Heck, I can even reliably restart OpenVPN
> remotely via ssh over OpenVPN, with no open sockets lost and the
> connection barely misses a heartbeat.
>
> Thanks,
> Geoff
> _______________________________________________
> NMLUG mailing list
> [email protected]
> http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug
>

--90e6ba4fc5145719b0049af6327b
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<br><br>OK, I can&#39;t believe I&#39;m posting this on Friday night, but d=
o you have performance issues with OpenVPN?=A0=A0 Every VPN I&#39;ve ever u=
sed has been a serious drag to getting real work done.=A0=A0 <br><br>-C<br>=
<br><div class=3D"gmail_quote">

On Fri, Jan 28, 2011 at 10:38 PM, Geoff Chesshire <span dir=3D"ltr">&lt;<a =
href=3D"mailto:[email protected]">[email protected]</a>&gt;</span> wrot=
e:<br><blockquote class=3D"gmail_quote" style=3D"margin: 0pt 0pt 0pt 0.8ex;=
 border-left: 1px solid rgb(204, 204, 204); padding-left: 1ex;">

Hi Ed,<br>
<div class=3D"im"><br>
&gt; We recently started using OpenVPN with certificates. =A0I&#39;m workin=
g on<br>
&gt; adding a password so it takes both a certificate and a password to<br>
&gt; connect a remote machine to the private network.<br>
<br>
</div>I&#39;ve been using OpenVPN for years, and have found it extremely re=
liable.<br>
In fact, not only do I use it for external access, but I use it even<br>
within the LAN, so that all services are accessible only through OpenVPN<br=
>
(even ssh, dns, nfs, samba, email, apache, cups). =A0Laptops keep their sam=
e<br>
VPN IP addresses wherever they connect from, making DNS administration<br>
easy. =A0I make WAN access to OpenVPN come in using UDP through a secure<br=
>
email port such as 143 or 993, as these few are generally not blocked by<br=
>
public networks e.g. at airports. =A0I forward this port to the usual<br>
OpenVNP port (1194) on the VPN server on the LAN. =A0Laptops try to connect=
<br>
to the server first over the LAN at port 1194, and if that fails, fall<br>
back to the WAN address+port. =A0I use client/server PKI certificates, with=
<br>
a pre-shared key during the handshake. =A0Passwords on the client<br>
certificates are possible, but I haven&#39;t used them. =A0For laptops, I t=
hink<br>
an encrypted root partition with a boot-up passphrase may be the way to go.=
<br>
<div class=3D"im"><br>
&gt; I&#39;m thinking that OpenVPN makes external SSH obsolete. =A0I could =
turn it<br>
&gt; off forcing me to start a whole VPN in order to get access to the<br>
&gt; internal interface. =A0Has everybody else already gotten to this<br>
&gt; conclusion or are there lots of people still allowing remote SSH acces=
s?<br>
<br>
</div>The only time I ever enable external SSH access is temporarily to all=
ow<br>
guest access from an external machine that is not (yet) included in the<br>
VPN, and even then I use an obscure port and forwarded that to port 22 on<b=
r>
the target machine. =A0The only port normally left open on the WAN is the<b=
r>
one for the VPN connection. =A0Heck, I can even reliably restart OpenVPN<br=
>
remotely via ssh over OpenVPN, with no open sockets lost and the<br>
connection barely misses a heartbeat.<br>
<br>
Thanks,<br>
<font color=3D"#888888">Geoff<br>
</font><div><div></div><div class=3D"h5">__________________________________=
_____________<br>
NMLUG mailing list<br>
<a href=3D"mailto:[email protected]">[email protected]</a><br>
<a href=3D"http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug" target=3D"_b=
lank">http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug</a><br>
</div></div></blockquote></div><br>

--90e6ba4fc5145719b0049af6327b--

--===============1534374993==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
NMLUG mailing list
[email protected]
http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug

--===============1534374993==--