Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,密钥交换算法优先curve25519-sha256。Compression yes(低带宽场景)。ClientAliveInterval 60,ClientAliveCountMax 3(保持连接活跃,避免超时断开)。MaxStartups 10:30:60(限制未认证连接数),MaxSessions 10(限制单个用户并发会话数)。vm.swappiness=10-30调整)。ControlMaster auto,ControlPath ~/.ssh/control-%r@%h:%p,ControlPersist 10m(复用已有连接,减少重复握手)。scp或rsync,避免SSH直接传输大文件。ping -M do -s 1472测试最佳值。sysctl -w net.ipv4.tcp_window_scaling=1。sysctl -w net.ipv4.tcp_tw_reuse=1,sysctl -w net.ipv4.tcp_fin_timeout=30。ufw deny in on eth0 from any to any port 22,再单独放行可信IP。top/htop监控SSH进程资源占用,ss -tulnp查看连接状态。/var/log/auth.log,排查异常登录或性能异常。参考来源: