在 CentOS 上加固 SSH 安全,通常从配置优化、访问控制、密钥认证、防护机制几个方面入手。下面给你一套实用且可落地的加固方案(适用于 CentOS 7 / 8 / Stream)。
修改 SSH 配置文件:
vi /etc/ssh/sshd_config
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
Port 2222
记得在防火墙和 SELinux 中放行
AllowUsers user1 user2
# 或
AllowGroups sshusers
PermitEmptyPasswords no
MaxAuthTries 3
ClientAliveInterval 300
ClientAliveCountMax 2
修改后重启 SSH:
systemctl restart sshd
ssh-keygen -t ed25519
ssh-copy-id user@server -p 2222
firewall-cmd --permanent --add-port=2222/tcp
firewall-cmd --reload
semanage port -a -t ssh_port_t -p tcp 2222
yum install epel-release -y
yum install fail2ban -y
配置:
vi /etc/fail2ban/jail.local
[sshd]
enabled = true
port = 2222
maxretry = 3
bantime = 3600
启动:
systemctl enable --now fail2ban
vi /etc/hosts.allow
sshd: 192.168.1.0/24
vi /etc/hosts.deny
sshd: ALL
GSSAPIAuthentication no
UseDNS no
Protocol 2
# 查看登录情况
journalctl -u sshd
last
/var/log/secure
如果你只想做最低成本加固:
✅ 禁止 root 登录
✅ 改端口
✅ 密钥登录
✅ fail2ban
如果你愿意,我可以:
你用的是 CentOS 几?服务器是公网还是内网?