SSH port knocking with OpenBSD 7.9 (dgl.cx)
from cm0002@mander.xyz to openbsd@lemmy.sdf.org on 19 Jun 17:28
https://mander.xyz/post/53877095

Port knocking is mostly a bad idea. But people keep wanting to do it, for some false sense of security. If you don’t consider it a security control but a way to keep garbage out of your logs, it might be valid. In my case I’m using an old USG Pro 4 running OpenBSD as my firewall and I’d prefer to avoid writing stuff to the logs, as I’d prefer the flash not to wear out sooner than needed, definitely not thanks to background radiation on the internet.

#openbsd

threaded - newest

ThorrJo@lemmy.sdf.org on 19 Jun 18:53 collapse

Port knocking is mostly a bad idea.

Good thing there’s Single Packet Authorization then.