FreeBSD Sistemlerde SSH Portu Değiştirme ve Root Erişim Kontrolü
FreeBSD, Metin2 sunucularının barındırıldığı güçlü ve güvenli sistemlerden biridir. Özellikle Metin2 geliştiricileri ve sunucu yöneticileri tarafından tercih edilir. Ancak, güvenlik önlemleri alınmadığında sistemler hedef alabilir. Bu nedenle, SSH erişim portunu değiştirmek ve root kullanıcıya erişimi sınırlamak kritik önem taşır.
SSH Nedir?
SSH (Secure Shell), uzaktan sunucu yönetim protokolüdür. Varsayılan olarak port 22 üzerinden çalışır. Bu port, saldırganlar tarafından sıklıkla hedef alınır. Bu yüzden SSH portunu değiştirmek, sisteminiz için önemli bir güvenlik adımıdır.
SSH Portu Nasıl Değiştirilir?
1. SSH Yapılandırma Dosyasını Açın
FreeBSD terminal arayüzüne erişim sağladıktan sonra aşağıdaki komutu kullanarak SSH yapılandırma dosyasını açın:
Kod:
sudo nano /etc/ssh/sshd_config
2. Port Numarasını Değiştirin
Dosya içinde şu satırı bulun:
Kod:
#Port 22
Bu satırı düzenleyerek yeni bir port numarası belirtin. Örneğin:
Kod:
Port 2222
3. Dosyayı Kaydedin ve SSH Servisini Yeniden Başlatın
Kod:
sudo service sshd restart
4. Güvenlik Duvarını Ayarlayın
Yeni portunuzun açık olduğundan emin olun. FreeBSD üzerinde PF (Packet Filter) kullanıyorsanız, yeni portun trafiğe açık olması için kurallar eklemelisiniz. Örnek PF kuralı:
Kod:
pass in on egress proto tcp from any to any port 2222
Root Kullanıcı Erişimi
Varsayılan olarak, birçok sistemde root kullanıcısı doğrudan SSH üzerinden giriş yapmaya izin verir. Bu, ciddi güvenlik riskleri doğurur. Bu nedenle, root kullanıcısının doğrudan SSH erişimini devre dışı bırakmanız önerilir.
1. SSH Yapılandırma Dosyasını Düzenleyin
Tekrar /etc/ssh/sshd_config dosyasını açın ve şu satırı bulun:
Kod:
PermitRootLogin yes
Değerini şu şekilde değiştirin:
Kod:
PermitRootLogin no
2. SSH Servisini Yeniden Başlatın
Kod:
sudo service sshd restart
SSH Anahtarları ile Güvenlik Arttırma
Root erişimini kısıtladıktan sonra, özel kullanıcılarla erişim sağlayabilirsiniz. Daha güvenli bir yöntem olan SSH anahtarları ile oturum açmayı kullanabilirsiniz.
1. SSH Anahtarı Oluşturun
İstemci bilgisayarınızda şu komutu çalıştırın:
Kod:
ssh-keygen -t rsa -b 4096
2. Ortak Anahtarı Sunucuya Yükleyin
Kod:
ssh-copy-id -p 2222 kullanıcı_adı@sunucu_ip
3. Şifresiz Oturum Açmayı Etkinleştirin
Yapılandırma dosyasında şu satırı kontrol edin:
Kod:
PasswordAuthentication no
Bu ayar sayesinde şifreyle oturum açma devre dışı bırakılır, sadece anahtarlarla giriş yapılabilir.
Sonuç
FreeBSD tabanlı Metin2 sunucularında SSH portunu değiştirmek ve root erişimini kısıtlamak, sisteminizi dış tehditlere karşı korumanın etkili yollarındandır. Bu yapılandırmaları doğru şekilde uyguladığınızda, sisteminiz daha güvenli bir yapıya kavuşur. Güvenlik, sürekli bir süreçtir ve düzenli olarak gözden geçirilmelidir.
Changing SSH Port and Root Access on FreeBSD Systems
FreeBSD is one of the powerful and secure systems used for hosting Metin2 servers. It is widely preferred by Metin2 developers and server administrators. However, without proper security measures, these systems can become targets. Therefore, changing the SSH access port and limiting root user access are critical steps.
What is SSH?
SSH (Secure Shell) is a remote server management protocol. By default, it operates on port 22. This port is frequently targeted by attackers. Changing the SSH port is an important security step for your system.
How to Change the SSH Port?
1. Open the SSH Configuration File
After accessing the FreeBSD terminal interface, use the following command to open the SSH configuration file:
Kod:
sudo nano /etc/ssh/sshd_config
2. Change the Port Number
Find the following line in the file:
Kod:
#Port 22
Edit this line to specify a new port number, for example:
Kod:
Port 2222
3. Save the File and Restart the SSH Service
Kod:
sudo service sshd restart
4. Configure Your Firewall
Ensure that your new port is open. If you are using PF (Packet Filter) on FreeBSD, add rules to allow traffic on the new port. Example PF rule:
Kod:
pass in on egress proto tcp from any to any port 2222
Root User Access
By default, many systems allow direct SSH login for the root user. This poses serious security risks. It is recommended to disable direct SSH access for the root user.
1. Edit the SSH Configuration File
Open the /etc/ssh/sshd_config file again and find the following line:
Kod:
PermitRootLogin yes
Change its value to:
Kod:
PermitRootLogin no
2. Restart the SSH Service
Kod:
sudo service sshd restart
Enhancing Security with SSH Keys
After restricting root access, you can allow access through specific users. You can also use SSH key-based authentication, which is a more secure method.
1. Generate an SSH Key
On your client computer, run the following command:
Kod:
ssh-keygen -t rsa -b 4096
2. Upload the Public Key to the Server
Kod:
ssh-copy-id -p 2222 username@server_ip
3. Enable Passwordless Login
Check the following line in the configuration file:
Kod:
PasswordAuthentication no
With this setting, password-based logins will be disabled, allowing only key-based access.
Conclusion
Changing the SSH port and restricting root access on FreeBSD-based Metin2 servers are effective ways to protect your system against external threats. When properly implemented, these configurations make your system more secure. Security is an ongoing process and should be reviewed regularly.
