亞波治

특정 IP만 SSH 접속 허용하기

· 2015-12-05 (토) 02:16:24 · 4181 · 2

서버관리시 Root를 사용하기 위해 특정 IP만 SSH에 접속 가능 하도록 아래 방법으로 수정해 보았습니다.

 

/etc/hosts.allow 수정

#
# hosts.allow This file describes the names of the hosts which are
# allowed to use the local INET services, as decided
# by the '/usr/sbin/tcpd' server.
#
sshd: 113.157.124.168, 135.79.246.

→ 113.157.124.168와 135.79.246.XXX 대역을 허용
위와 같이 한줄에 적어도 되지만, 아이피가 많아지면 관리가 어렵다. 아래와 같이 여러줄로 나누어 적어도 된다.
sshd: 113.157.124.168
sshd: 135.79.246.


/etc/hosts.deny 수정

#
# hosts.deny This file describes the names of the hosts which are
# *not* allowed to use the local INET services, as decided
# by the '/usr/sbin/tcpd' server.
#
# The portmap line is redundant, but it is left to remind you that
# the new secure portmap uses hosts.deny and hosts.allow. In particular
# you should know that NFS uses portmap!
sshd: ALL

ALL 적용시 나머지는 모두 ssh 접근 불가 sshd 재시작 해야 정상 적용된다.

# service sshd restart
Stopping sshd: [ OK ]
Starting sshd: [ OK ]

 

출처 : http://www.nanoomi.org/bbs/board.php?bo_table=03_2&wr_id=5&page=2 

|

댓글 2개

host 파일 수정에는 리스타트가 필요없습니다.
sshd 데몬이 읽고 막는게 아니라서요.
그런가요? 뭔가 작업하면 리스타트가 버릇이 되어서요....^^
댓글을 작성하시려면 로그인이 필요합니다.

서버관리자

663건

서버관리자 모임 게시판 입니다.

+
제목 글쓴이 날짜 조회
16-01-19 조회 3,103
16-01-19 조회 3,455
16-01-19 조회 3,186
16-01-09 조회 3,068
16-01-04 조회 3,704
15-12-31 조회 4,049
15-12-31 조회 7,802
15-12-30 조회 2,908
15-12-30 조회 2,906
15-12-29 조회 5,716
15-12-26 조회 2,953
15-12-21 조회 2,180
15-12-19 조회 3,076
15-12-18 조회 7,498
15-12-18 조회 2,400
15-12-15 조회 3,118
15-12-13 조회 2,597
15-12-12 조회 2,165
15-12-11 조회 2,450
15-12-11 조회 4,589
15-12-09 조회 2,567
15-12-08 조회 2,699
15-12-08 조회 3,100
15-12-08 조회 2,797
15-12-07 조회 2,415
15-12-07 조회 2,517
15-12-07 조회 2,584
15-12-05 조회 2,823
15-12-05 조회 4,182
15-12-05 조회 2,948