Guides · RDP-FIDO-GATE

How to hide the SSH port from scanners and brute-force bots

A new server with SSH on a public address gets its first login attempt within minutes. The usual advice — move the port, install fail2ban — makes the logs quieter. It does not make the port unreachable. Here is what each measure really does.

Updated

What each measure does

MeasureWhat it doesWhat it leaves
Move SSH to another portRemoves most of the noise from bots that only try 22Internet-wide scanners index every port; the service is just as reachable
fail2ban, sshguardBans an address after several failed loginsThe port still answers; botnets rotate addresses; no help against a pre-auth bug
Keys only, passwords offEnds password guessing for goodThe port still answers and runs sshd's pre-authentication code for everyone
IP allow-listCloses the port to everyone else — the best fix when your address is fixedBreaks for home, mobile and travelling admins with changing addresses
Port knocking (knockd)Keeps the port closed until a secret sequence of packets arrivesThe sequence is sent in the clear and can be replayed
Single packet authorization (fwknop)One encrypted, non-replayable packet opens the portA key file and a dedicated client; UDP may be blocked on guest networks
VPNSSH is reachable only inside the tunnelA network to run; no second factor by itself
Key-gated portOpens the port for your IP after a FIDO2 key touch or a one-time codeA gate service on the server and a client on your computer

Less noise is not less exposure

The first three rows are about logins. They make guessing harder or quieter, and you should do them: PasswordAuthentication no, PermitRootLogin prohibit-password, a ban tool if you like.

But the worst SSH incidents of recent years were not logins. regreSSHion (CVE-2024-6387) was remote code execution in sshd before authentication; the xz backdoor (CVE-2024-3094) hid in a library that sshd loaded. On the day each was disclosed, servers whose port strangers could not reach had nothing to rush.

Default-deny, opened on proof

The last four rows share one idea: the firewall drops everything, and the port opens only for someone who has proved something first. They differ in what is proved. A knock proves you know a sequence. Single packet authorization and a VPN prove you hold a key file. A key-gated port proves you are holding a hardware key right now — with a PIN or a fingerprint if you require it.

Set up a key-gated SSH port

  1. Install the RDP-FIDO-GATE package on the server — one package, nothing else comes with it — and run its setup: it prints a one-time enrollment code.
  2. Install the client on your computer, add the server and enroll your security key with the code.
  3. Back on the server, add port 22 to the guarded ports. The port closes at that moment; the session you are in stays open.
  4. Connect by touching the key: the gate opens port 22 for your address for 90 seconds and the client starts ssh.
sudo apt install ./rdpfido-gate_1.25.2_amd64.deb
sudo rdpfido-gate setup            # prints a one-time enrollment code
# enroll a key from the client, then:
sudo rdpfido-gate ports add 22

# from a machine that has not touched a key:
nc -vz -w 3 your-server 22         # times out

The complete walk-through, including how not to lock yourself out, is in Keep the SSH port closed until you touch a FIDO2 key.

Keep doing the basics

RDP-FIDO-GATE

RDP-FIDO-GATE keeps SSH and other admin ports closed and opens them for one IP, for about 90 seconds, only after a FIDO2 key touch or an authenticator code. Its client includes an SSH console with saved passwords, saved commands and an AI assistant that works with Claude or with your own local model. The Free edition covers 10 saved sessions.

Frequently asked questions

Is changing the SSH port useless?

Not useless: the logs get shorter, and bots that only try port 22 go away. It is not protection, though — scanning services index all 65,535 ports, and a targeted attacker scans them too.

Is hiding a port security through obscurity?

Hiding a service on an unusual port number is obscurity. Dropping packets until a cryptographic proof arrives is access control: nothing about it depends on a secret location.

What happens if the gate service stops?

The firewall rules live in the kernel, so the port stays closed rather than open, and systemd restarts the service. If you need to get in regardless, sudo rdpfido-gate unlock on the machine's console lifts the protection.

Do I still need fail2ban behind a closed port?

It has nothing to do while strangers cannot connect. Leaving it installed costs nothing and covers the moments when you remove the port from the gate.

Related guides