Knowledge Base
Secure SSH Access on Linux Servers
SSH provides encrypted remote administration, but default access should be hardened before a server enters production.
Use SSH keys
Create a separate administrative user and test key-based login in a second session before disabling password authentication.
Restrict exposure
Allow SSH through the firewall only where required. A custom port reduces background noise but does not replace keys and access controls.
Disable direct root login
Use a sudo-enabled user and keep an emergency recovery path. Review authentication logs and use rate limiting or tools such as Fail2Ban where appropriate.