温馨提示×

centos ssh安全怎么加固

小樊
35
2026-10-05 16:17:17
栏目: 智能运维

在 CentOS 上加固 SSH 安全,通常从配置优化、访问控制、密钥认证、防护机制几个方面入手。下面给你一套实用且可落地的加固方案(适用于 CentOS 7 / 8 / Stream)。


一、基础配置加固(最重要)

修改 SSH 配置文件:

vi /etc/ssh/sshd_config

1. 禁止 root 直接登录

PermitRootLogin no

2. 使用密钥登录,禁用密码

PasswordAuthentication no
PubkeyAuthentication yes

3. 修改默认端口(降低扫描风险)

Port 2222

记得在防火墙和 SELinux 中放行

4. 限制登录用户

AllowUsers user1 user2
# 或
AllowGroups sshusers

5. 禁止空密码

PermitEmptyPasswords no

6. 限制认证尝试次数

MaxAuthTries 3

7. 会话超时断开

ClientAliveInterval 300
ClientAliveCountMax 2

修改后重启 SSH:

systemctl restart sshd

二、使用 SSH 密钥登录(强烈推荐)

生成密钥(客户端)

ssh-keygen -t ed25519

上传公钥

ssh-copy-id user@server -p 2222

三、防火墙与 SELinux

firewalld 放行新端口

firewall-cmd --permanent --add-port=2222/tcp
firewall-cmd --reload

SELinux(如修改端口)

semanage port -a -t ssh_port_t -p tcp 2222

四、防止暴力破解

方案 1:fail2ban(推荐)

yum install epel-release -y
yum install fail2ban -y

配置:

vi /etc/fail2ban/jail.local
[sshd]
enabled = true
port = 2222
maxretry = 3
bantime = 3600

启动:

systemctl enable --now fail2ban

五、进一步安全增强

1. 使用 TCP Wrappers(CentOS 7)

vi /etc/hosts.allow
sshd: 192.168.1.0/24

vi /etc/hosts.deny
sshd: ALL

2. 禁用不安全的认证方式

GSSAPIAuthentication no
UseDNS no

3. 限制 SSH 协议版本

Protocol 2

六、审计与监控

# 查看登录情况
journalctl -u sshd
last
/var/log/secure

七、最小安全方案(快速版)

如果你只想做最低成本加固:

✅ 禁止 root 登录
✅ 改端口
✅ 密钥登录
✅ fail2ban


如果你愿意,我可以:

  • 给你一份 可直接用的 sshd_config
  • 按 等保 / 企业安全规范 给你清单
  • 针对 CentOS 7 vs 8 分别说明

你用的是 CentOS 几?服务器是公网还是内网?

0 踩