官术网_书友最值得收藏!

Enabling the Secure Shell (SSH)

This recipe describes how to enable the Secure Shell (SSH) service in pfSense.

Getting ready

SSH is a networking protocol that allows encrypted communication between two devices. Enabling SSH allows secure access to the pfSense console remotely, just as if you were sitting in front of the physical console.

How to do it...

  1. Browse to System | Advanced | Secure Shell.
  2. Check Enable Secure Shell.
  3. You will be prompted for credentials when you connect (use the same username and password as the webGUI), but checking Disable password login for Secure Shell will allow you to use RSA keys instead. See the next recipe for details.
  4. Leave the SSH port blank to use the default port:
  5. Save the changes and the SSH service will be started.

How it works...

Enabling the Secure Shell turns on pfSense's built-in SSH server to listen to requests on the port you've specified (port 22 by default).

Note

Like all pfSense services (unless otherwise noted), the SSH service will listen on every available interface. Like other services, firewall's rules are used to grant or deny access to these services. See Chapter 3, General Configuration for more information on configuring firewall rules.

There's more...

Changing the SSH authentication method to use RSA keys is a great way to secure access to your system. See the following recipe for details.

Additionally, you can change the port that SSH listens on. Doing so may increase security slightly by reducing the number of unauthorized login attempts, but you will need to remember what you have changed it to, or you will be unable to connect.

See also

  • The Generating authorized RSA keys recipe
  • The Creating a firewall rule recipe in Chapter 3, General Configuration
主站蜘蛛池模板: 邯郸县| 饶阳县| 始兴县| 浦城县| 格尔木市| 新乡市| 黄梅县| 汪清县| 肇源县| 太保市| 金乡县| 兴安县| 桦川县| 闻喜县| 塔城市| 眉山市| 基隆市| 安福县| 阳江市| 辽阳市| 富锦市| 东兴市| 诸城市| 晋江市| 深水埗区| 平泉县| 阆中市| 花垣县| 青田县| 曲松县| 阿鲁科尔沁旗| 阳曲县| 临江市| 柳林县| 望都县| 米泉市| 广西| 紫金县| 陆丰市| 永定县| 乌拉特中旗|