Guides · RDP-FIDO-GATE

How to keep SSH closed until a FIDO2 key is touched

Key-only logins stop password guessing, but the SSH port still answers everyone on the internet — and an answering port is all a pre-authentication bug needs. This guide sets up a server where port 22 does not answer at all until you touch a security key, and then answers only you.

Updated

Why hide a port that already demands a key

A port that drops every packet removes all three at once. The question is how to open it for yourself without a VPN and without a fixed IP address.

How the gate works

RDP-FIDO-GATE installs a small service on the server. It adds its own nftables table — or, where nftables is absent, an iptables chain kept first in INPUT — that drops new connections to the guarded ports. Established connections are accepted, so nothing that is running gets cut.

The service listens on TCP 7440 over TLS and accepts one thing: a signed FIDO2 / WebAuthn confirmation from a key enrolled on this server. After a valid one it adds a rule for the caller's IP address, keeps it for 90 seconds — enough to start ssh — and removes it. Every 30 seconds it checks that its rules are still in place, and after a reboot a guard unit installs them before the network comes up.

The service runs under a systemd sandbox: a short list of capabilities for driving the packet filter, a read-only file system outside its own state directory, a memory limit.

What you need

Set it up

  1. On the server, download the gate package and install it. It is the only package apt adds: no xrdp and no X libraries come with it. File names for other distributions are in the Linux guide.
  2. Run sudo rdpfido-gate setup. It creates the gate's certificate, installs the service and prints a one-time enrollment code (valid for 15 minutes) and the certificate fingerprint. On a server without a desktop it also notes that no RDP server was found — which is fine when SSH is all you want to guard.
  3. On your computer, install the client and add a session on the SSH tab: the server address, your login, the “SSH console” protocol, gate port 7440. Enroll your key with the code from step 2 and touch it.
  4. Back on the server, run sudo rdpfido-gate ports add 22. From this moment port 22 is closed to everyone the gate has not let in. The session you are typing in stays open.
  5. To connect, click the session tile and touch the key: the gate opens the port for your address and the console starts ssh.
# on the server (Ubuntu / Debian)
wget https://new-imobile.com/download/rdp-fido-gate/linux/rdpfido-gate_1.25.2_amd64.deb
sudo apt install ./rdpfido-gate_1.25.2_amd64.deb
sudo rdpfido-gate setup            # prints the enrollment code and the fingerprint

# on a Linux workstation, instead of the Windows client
rdpfido add --name web1 --host 203.0.113.10 --user admin
rdpfido enroll web1 6NGQ-MEMG-34M4 --fingerprint 273CE04D...

# on the server again, once the key is enrolled
sudo rdpfido-gate ports add 22

# on the workstation
rdpfido ssh web1                   # touch the key -> ssh

Enroll the key before you add port 22: that way you know the key works before SSH closes. The session you are typing in stays open — the gate does not cut established connections. Before you close that session, check from a second terminal that the key lets you in. If it does not, run sudo rdpfido-gate ports remove 22 in the session you still have, or sudo rdpfido-gate unlock on the machine's own console.

Check it from outside

From a machine that has not touched a key:

nc -vz -w 3 203.0.113.10 22      # times out: the port does not answer
nc -vz -w 3 203.0.113.10 7440    # succeeds: the gate is reachable

# on the server
sudo rdpfido-gate status           # service, keys, rules, active grants
sudo nft list table inet rdpfido   # the rules themselves

Then run rdpfido open web1 (or click the tile), touch the key and repeat the first line within 90 seconds from the same address: now it connects.

More than SSH

The same command guards up to 16 TCP ports that the host itself listens on — a web admin panel, a database port, a monitoring UI: sudo rdpfido-gate ports add 22 8443 5432. One key touch opens all of them for your address for the same 90 seconds.

On a Linux workstation, rdpfido ssh web1 -- -L 8443:127.0.0.1:8443 passes everything after -- to ssh, so tunnels and jump hosts work as usual. In the Windows client the same options go into the session's ssh options field.

What to know before you rely on it

RDP-FIDO-GATE

RDP-FIDO-GATE keeps SSH and other admin ports closed and opens them for one IP, for about 90 seconds, only after a FIDO2 key touch or an authenticator code. Its client includes an SSH console with saved passwords, saved commands and an AI assistant that works with Claude or with your own local model. The Free edition covers 10 saved sessions.

Frequently asked questions

Does this replace SSH keys or fail2ban?

It does not replace keys: sshd authenticates you exactly as before. It does leave fail2ban with nothing to do, because strangers can no longer reach the port to fail a login.

Is port 7440 not just another exposed port?

It is exposed, but it offers no login and no shell. Over TLS the gate accepts a signed WebAuthn assertion from an enrolled key — or, in code mode, a one-time code — and nothing else. Compare that with port 22, which runs the whole SSH pre-authentication exchange for anyone.

What if I lose the key?

Enroll two keys from the start. A lost key is removed with sudo rdpfido-gate remove-key N, and a new enrollment code is printed with sudo rdpfido-gate code — from a session you still have or from the server's console.

Does it work together with ufw or firewalld?

Yes. The gate keeps its own nftables table, or its own iptables chain placed first in INPUT, and a drop there is final whatever other tools allow. Port 22 must already be allowed in ufw or firewalld, as it is on any server you administer over SSH.

Can I use it without a hardware key?

Yes. sudo rdpfido-gate setup --auth totp makes the gate accept 6-digit codes from any authenticator app instead of keys. A gate works in one mode at a time.

Does my SSH session drop after 90 seconds?

No. The window limits when a new connection may start. An established session keeps running; the next one needs the key again.

Related guides