1.修改端口号,设置登录输入密码等待过期时间,拒绝远程登录root,密码为空,密码登录,


[root@zzp124 ~]# vim /etc/ssh/sshd_config

SSH配置文件解析_ssh

SSH配置文件解析_ssh_02

SSH配置文件解析_服务器_03

SSH配置文件解析_服务器_04


[root@zzp124 ~]# systemctl restart sshd.service 
[root@zzp124 ~]# lsof -i :22
[root@zzp124 ~]# lsof -i :66
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
sshd 3476 root 3u IPv4 39248 0t0 TCP *:sql*net (LISTEN)
sshd 3476 root 4u IPv6 39250 0t0 TCP *:sql*net (LISTEN)


2.设置开机自启


systemctl enable sshd 设置开机自启


3.计算机私人密钥文件


[root@zzp124 ~]# head -3 /etc/ssh/ssh_host_rsa_key
-----BEGIN RSA PRIVATE KEY-----
MIIEowIBAAKCAQEAo3lCTvgoQXzO55VtFM5KhL6ylvfF8LIAldml144G7pnDm7oX
Myt55ScUbvZLKv6nYVkBnD+JqXhUyvZB/zUzKUA8hUMdq/48brRjXY0wwRgerfyM


4.登录日志存放文件


[root@zzp124 ~]# head -3 /var/log/secure 
Nov 9 00:00:21 localhost polkitd[700]: Loading rules from directory /etc/polkit-1/rules.d
Nov 9 00:00:21 localhost polkitd[700]: Loading rules from directory /usr/share/polkit-1/rules.d
Nov 9 00:00:22 localhost polkitd[700]: Finished loading, compiling and executing 8 rules


5.设置登录提示

SSH配置文件解析_IP_05

6.控制外界服务器IP是否可以访问本机


[root@zzp124 ~]# vim /etc/hosts.allow       #设置允许访问的IP,优先级高于deny

[root@zzp124 ~]# vim /etc/hosts.deny #设置拒绝访问的IP


SSH配置文件解析_vim_06

SSH配置文件解析_IP_07

SSH配置文件解析_ssh_08