Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
you can Disable SSH THrew WAN interface
System>Network>Interfaces>WAN1 or WAN2 uncheck Check box of SSH
Click ok
moving the ssh port to a non standard port is all fine and dandy but the chinese are just going to scan the whole thing anyways and find what ports are listening.
Disable SSH on the external interface or kick on 2FA and hope for the best. In the end it is about the amount of risk you are willing to accept.
Mike Pruett
PCNSE
NSE
StrongSwan
1. Configure trusted Public host address/es that are able to login
2. Disable the access on the external interface
I wonder why nobody (including me) mentioned 'local-in policies' with a geo-location as source address - usually you can block North Korea, China, Brazil without any drawbacks.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.