SSH port knocking with OpenBSD 7.9
(dgl.cx)
from cm0002@mander.xyz to openbsd@lemmy.sdf.org on 19 Jun 17:28
https://mander.xyz/post/53877095
from cm0002@mander.xyz to openbsd@lemmy.sdf.org on 19 Jun 17:28
https://mander.xyz/post/53877095
Port knocking is mostly a bad idea. But people keep wanting to do it, for some false sense of security. If you don’t consider it a security control but a way to keep garbage out of your logs, it might be valid. In my case I’m using an old USG Pro 4 running OpenBSD as my firewall and I’d prefer to avoid writing stuff to the logs, as I’d prefer the flash not to wear out sooner than needed, definitely not thanks to background radiation on the internet.
threaded - newest
Good thing there’s Single Packet Authorization then.