i want to remotely ssh to my home server, and I was wondering if I could just forward port 22 with disabling password login and use pubkey authentication will be safe enough?

  • Sekhen@alien.topB
    link
    fedilink
    English
    arrow-up
    1
    ·
    10 months ago

    Wireguard doesn’t answer unless you hand shake with a valid package.

    There are three 512 bit keys.

    And you can put ssh behind it with ssh keys.

    The extra later of defence is quite significant.

    No “actual user” is blocked by fail2ban. They auth with keys, can’t really fail.

    Blocking after three fail is very reasonable and effective. It also keeps the logs noise down.