Comment on What are your methods to harden *nix servers?
iii@mander.xyz 19 hours agoWith knockd you can execute arbitrary commands upon a port knocking sequence. So any application that is configurable via terminal is eligible. Here’s a tutorial of knockd+iptables (1). Alternativly there’s (2).
You can use it wherever, as part of security in depth. It’ll have it’s largest effect on publicly facing interfaces. It does not replace having a proper ssh setup (disabling root, keys only, etc).
Cyber@feddit.uk 9 hours ago
Thanks for the links, I’ll take a look as I’ve never actually played with port knocking.