{"id":5581,"date":"2019-11-17T22:55:38","date_gmt":"2019-11-17T13:55:38","guid":{"rendered":"https:\/\/pandanote.info\/?p=5581"},"modified":"2020-12-31T18:10:10","modified_gmt":"2020-12-31T09:10:10","slug":"sshd%e3%81%ae%e3%83%9d%e3%83%bc%e3%83%88%e7%95%aa%e5%8f%b7%e3%82%92%e5%a4%89%e3%81%88%e3%82%8b%e3%81%ab%e8%87%b3%e3%82%8b%e9%81%93%e3%81%ae%e3%82%8a%e3%80%82","status":"publish","type":"post","link":"https:\/\/pandanote.info\/?p=5581","title":{"rendered":"sshd\u306e\u30dd\u30fc\u30c8\u756a\u53f7\u3092\u5909\u3048\u308b\u306b\u81f3\u308b\u9053\u306e\u308a\u3002"},"content":{"rendered":"<h2>\u306f\u3058\u3081\u306b<\/h2>\n<p>\u6700\u8fd1\u3001\u8a18\u4e8b\u3092\u66f8\u3044\u3066\u3044\u308b\u969b\u306b\u753b\u50cf\u30d5\u30a1\u30a4\u30eb\u304c\u6025\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3067\u304d\u306a\u304f\u306a\u308a\u3001\u539f\u56e0\u3092\u8abf\u3079\u3066\u307f\u305f\u3068\u3053\u308d\u3001\u672cWeb\u30b5\u30a4\u30c8\u306ejournal\u30ed\u30b0\u304c\u6fc0\u5897\u3057\u305f\u305b\u3044\u3067filesystem\u306e\u4f7f\u7528\u7387\u304c100%\u3068\u306a\u3063\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<p>\u3068\u3044\u3046\u3053\u3068\u3067\u3001\u3044\u308d\u3044\u308d\u3068\u5bfe\u5fdc\u7b56\u3092\u691c\u8a0e&#038;\u5b9f\u884c\u3057\u305f\u7d50\u679c\u3001sshd\u306e\u30dd\u30fc\u30c8\u756a\u53f7\u3092\u5909\u66f4\u3059\u308b\u3053\u3068\u3068\u3057\u307e\u3057\u305f\u306e\u3067\u3001\u3053\u306e\u8a18\u4e8b\u3067\u306fsshd\u306e\u30dd\u30fc\u30c8\u756a\u53f7\u3092\u5909\u3048\u308b\u306b\u81f3\u308b\u307e\u3067\u306e\u7d4c\u7def\u306b\u3064\u3044\u3066\u66f8\u304d\u307e\u3059\u3002<\/p>\n<h2>journal\u30ed\u30b0\u306e\u5185\u5bb9\u3092\u8abf\u3079\u3066\u307f\u305f\u3002<\/h2>\n<p>filesystem\u306e\u4f7f\u7528\u7387\u304c100%\u306e\u72b6\u6cc1\u304c\u7d9a\u304f\u3068\u3001\u601d\u308f\u306c\u3068\u3053\u308d\u3067\u30d5\u30a1\u30a4\u30eb\u3092\u524a\u9664\u3057\u3066\u3057\u307e\u3046(\u5b9f\u969b\u3001\u672cWeb\u30b5\u30a4\u30c8\u7528\u306b\u30ab\u30b9\u30bf\u30de\u30a4\u30ba\u3057\u305fPHP\u30d5\u30a1\u30a4\u30eb\u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u6642\u306b\u3053\u306e\u30a8\u30e9\u30fc\u304c\u767a\u751f\u3057\u3066\u30d5\u30a1\u30a4\u30eb\u304c\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u306a\u3044\u3069\u3053\u308d\u304b\u3001\u3082\u3068\u3082\u3068\u3042\u3063\u305fPHP\u30d5\u30a1\u30a4\u30eb\u3082\u524a\u9664\u3055\u308c\u3066\u3057\u307e\u3046\u3053\u3068\u304c\u3042\u308a\u307e\u3057\u305f\uff57)\u7b49\u306e\u554f\u984c\u304c\u767a\u751f\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u306e\u3067\u3001root\u6a29\u9650\u3067\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3066\u53e4\u3044journal\u30ed\u30b0\u3092\u524a\u9664\u3057\u3066filesystem\u306e\u30b9\u30da\u30fc\u30b9\u3092\u5c11\u3057\u89e3\u653e\u3057\u3001\u3044\u3063\u305f\u3093\u843d\u3061\u7740\u304d\u307e\u3059\u3002<\/p>\n<div class=\"code\"># journalctl &#45;&#45;vacuum-size=10M<\/div>\n<p>&nbsp;<\/p>\n<p>filesystem\u306e\u30b9\u30da\u30fc\u30b9\u304c\u3042\u3044\u3066\u843d\u3061\u7740\u3044\u305f\u3068\u3053\u308d\u3067\u3001\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<div class=\"code\"># journalctl | less<\/div>\n<p>&nbsp;<\/p>\n<p>\u4e0a\u8a18\u306e\u30b3\u30de\u30f3\u30c9\u306e\u5b9f\u884c\u7d50\u679c\u3068\u3057\u3066\u51fa\u529b\u3055\u308c\u308bjournal\u306e\u30ed\u30b0\u3092\u3088\u30fc\u304f\u89b3\u5bdf\u3059\u308b\u3068\u2026<\/p>\n<div class=\"code\">11\u6708 16 18:14:30 pandanote.info audit[13496]: USER_LOGIN pid=13496 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg=&apos;op=login acct=&quot;(unknown)&quot; exe=&quot;\/usr\/sbin\/sshd&quot; hostname=? addr=aaa.bbb.ccc.ddd terminal=ssh res=failed&apos;<\/div>\n<p>&nbsp;<\/p>\n<p>\u3063\u3066\u306a\u611f\u3058\u306e\u30ed\u30b0\u304c\u5927\u91cf\u306b\u51fa\u529b\u3055\u308c\u3066\u307e\u3057\u305f(IP\u30a2\u30c9\u30ec\u30b9\u306e\u90e8\u5206\u306f\u52a0\u5de5\u3057\u3066\u3044\u307e\u3059)\u3002<\/p>\n<p>\u3064\u307e\u308a\u3001<\/p>\n<ul>\n<li>\u591a\u6570\u306e\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u304b\u3089\u306esshd\u3078\u306e\u30a2\u30af\u30bb\u30b9\u304c\u5927\u91cf\u306b\u884c\u308f\u308c\u308b\u3002<\/li>\n<li>\u30a2\u30af\u30bb\u30b9\u81ea\u4f53\u306f\u5931\u6557\u3059\u308b\u3082\u306e\u306e\u3001\u5931\u6557\u3057\u305f\u65e8\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u304cjournal\u30ed\u30b0\u306b\u66f8\u304d\u8fbc\u307e\u308c\u308b\u3002<\/li>\n<li>journal\u30ed\u30b0\u306e\u5927\u304d\u3055\u304c\u81a8\u308c\u4e0a\u304c\u308a\u3001filesystem\u306e\u4f7f\u7528\u7387\u304c100%\u306b\u9054\u3059\u308b\u3002<\/li>\n<li>\u753b\u50cf\u30d5\u30a1\u30a4\u30eb\u304cWordpress\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3067\u304d\u306a\u304f\u306a\u308b\u3002<strong>\u2190\u4eca\u3053\u3053!!<\/strong><\/li>\n<\/ul>\n<p>\u3068\u3044\u3046\u72b6\u6cc1\u306b\u306a\u3063\u3066\u3044\u305f\u3063\u307d\u3044\u3067\u3059\u3002<\/p>\n<p>\u300c\u7b2cn\u7a2eDDoS\u653b\u6483\u306e\u3088\u3046\u306a\u3082\u306e\u300d\u304c\u6210\u7acb\u3057\u3066\u3044\u305f\u6a21\u69d8\u3067\u3059\u3002<\/p>\n<h2>\u6700\u521d\u306e\u89e3\u6c7a\u6848<\/h2>\n<p>\u307e\u305a\u306f\u3001sshd\u3078\u306e\u30a2\u30af\u30bb\u30b9\u3092\u8a66\u307f\u3066\u3044\u308b\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u306eIP\u30a2\u30c9\u30ec\u30b9\u3092\u62bd\u51fa\u3059\u3079\u304f\u3001root\u6a29\u9650\u3067\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3066IP\u30a2\u30c9\u30ec\u30b9\u3068\u30ed\u30b0\u306b\u8a18\u9332\u3055\u308c\u3066\u3044\u308b\u56de\u6570\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002<\/p>\n<div class=\"code\"># journalctl -r | grep disconnect | grep ssh | gawk &apos;{{ print $9 }}&apos; | sort | uniq -c<\/div>\n<p>&nbsp;<\/p>\n<p>\u4e0a\u8a18\u306e\u30b3\u30de\u30f3\u30c9\u306b\u3088\u308a\u62bd\u51fa\u3055\u308c\u305fIP\u30a2\u30c9\u30ec\u30b9\u306b\u3064\u3044\u3066root\u6a29\u9650\u3067\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3001\u30a2\u30af\u30bb\u30b9\u3092\u62d2\u5426\u3059\u308b\u3088\u3046\u8a2d\u5b9a\u3057\u307e\u3059\u3002<\/p>\n<div class=\"code\"># firewall&minus;cmd &#45;&#45;add&minus;source=aaa.bbb.ccc.ddd\/32 &#45;&#45;zone=drop &#45;&#45;permanent<br \/>\n# firewall&minus;cmd &#45;&#45;reload<\/div>\n<p>&nbsp;<\/p>\n<p>\u306a\u304a\u3001\u3044\u304f\u3064\u304b\u306eIP\u30a2\u30c9\u30ec\u30b9\u3092\u4f7f\u3044\u5206\u3051\u3066sshd\u306b\u30a2\u30af\u30bb\u30b9\u3057\u3066\u3044\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b\u3082\u306e\u306b\u3064\u3044\u3066\u306f\u3001&#8221;\/32&#8243;\u306e\u90e8\u5206\u3092&#8221;\/28&#8243;\u306e\u3088\u3046\u306b\u5c0f\u3055\u3044\u6570\u5b57\u306b\u3059\u308b\u3053\u3068\u3067\u3001\u30a2\u30af\u30bb\u30b9\u3092\u62d2\u5426\u3059\u308bIP\u30a2\u30c9\u30ec\u30b9\u306e\u7bc4\u56f2\u3092\u5e83\u3052\u3066\u8a2d\u5b9a\u3057\u307e\u3059\u3002<\/p>\n<p>\u3053\u3053\u307e\u3067\u306e\u4f5c\u696d\u3092\u884c\u3063\u305f\u5f8c\u306b1\u6642\u9593\u307b\u3069\u69d8\u5b50\u3092\u307f\u305f\u3068\u3053\u308d\u3001journal\u30ed\u30b0\u306e\u51fa\u529b\u304c\u3044\u3063\u305f\u3093\u6b62\u307e\u3063\u305f\u3088\u3046\u306b\u898b\u3048\u305f\u306e\u3067\u3001\u7fcc\u671d\u306b\u518d\u5ea6\u78ba\u8a8d\u3059\u308b\u3053\u3068\u306b\u3057\u307e\u3057\u305f\u3002<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"ja\" dir=\"ltr\">\u3053\u30532,3\u65e5\u306e\u9593\u306b\u7acb\u3066\u7d9a\u3051\u306bpanda\u5927\u5b66\u7fd2\u5e33\u306e\u30b5\u30fc\u30d0\u306ejournal\u30ed\u30b0\u306e\u51fa\u529b\u306e\u305f\u3081\u306bfilesystem\u306e\u4f7f\u7528\u7387\u304c100%\u306b\u306a\u3063\u3066\u3057\u307e\u3063\u305f\u306e\u3067\u3001\u305d\u306e\u539f\u56e0\u3068\u601d\u308f\u308c\u308bIP\u30a2\u30c9\u30ec\u30b9\u7fa4\u304b\u3089\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u62d2\u5426\u3059\u308b\u8a2d\u5b9a\u306b\u3057\u3066\u307f\u305f\u3068\u3053\u308d\u3001journal\u30ed\u30b0\u306e\u51fa\u529b\u304c\u307b\u307c\u6b62\u307e\u308a\u307e\u3057\u305f\u3002?<br \/>\u4f7f\u7528\u7387\u306e\u78ba\u8a8d\u91cd\u8981\u3067\u3059\u3002<a href=\"https:\/\/twitter.com\/hashtag\/lifeinyokohama?src=hash&amp;ref_src=twsrc%5Etfw\">#lifeinyokohama<\/a><\/p>\n<p>&mdash; pandanote.info (@Pandanote_info) <a href=\"https:\/\/twitter.com\/Pandanote_info\/status\/1195687451890569216?ref_src=twsrc%5Etfw\">November 16, 2019<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<h2>2\u756a\u76ee\u306e\u89e3\u6c7a\u6848<\/h2>\n<p>\u6b21\u306e\u65e5\u306e\u671d\u306b\u3001journal\u30ed\u30b0\u306e\u30d5\u30a1\u30a4\u30eb\u30b5\u30a4\u30ba\u3092\u8abf\u3079\u3066\u307f\u305f\u3068\u3053\u308d\u300110M\u30d0\u30a4\u30c8\u306b\u3057\u305f\u306f\u305a\u306ejournal\u30ed\u30b0\u304c8\u6642\u9593\u304f\u3089\u3044\u306e\u9593\u306b\u7d04130M\u30d0\u30a4\u30c8\u306b\u306a\u3063\u3066\u3044\u307e\u3057\u305f\u3002journal\u30ed\u30b0\u306e\u5185\u5bb9\u3092\u8abf\u3079\u3066\u307f\u305f\u3068\u3053\u308d\u3001sshd\u3078\u306e\u30a2\u30af\u30bb\u30b9\u3092\u8a66\u307f\u3066\u5931\u6557\u3057\u305f\u65e8\u306e\u30ed\u30b0\u304c\u5927\u91cf\u306b\u8a18\u9332\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<p>\u3053\u308c\u3067\u306f\u6bd4\u8f03\u7684\u3059\u3050\u306bjournal\u30ed\u30b0\u306e\u305f\u3081\u306bfilesystem\u306e\u4f7f\u7528\u7387\u304c100%\u306b\u306a\u308b\u53ef\u80fd\u6027\u304c\u9ad8\u305d\u3046\u3067\u3059\u3002<\/p>\n<p>\u305d\u3053\u3067\u3001sshd\u7b49\u306e\u8a2d\u5b9a\u3092\u5909\u66f4\u3059\u308b\u3053\u3068\u306b\u3088\u308asshd\u306e\u30dd\u30fc\u30c8\u756a\u53f7\u3092\u5909\u66f4\u3059\u308b\u3053\u3068\u306b\u3057\u307e\u3057\u305f\u3002<\/p>\n<h2>\u30dd\u30fc\u30c8\u756a\u53f7\u3092\u5909\u3048\u308b\u305f\u3081\u306e\u8a2d\u5b9a<\/h2>\n<h3>SELinux\u306e\u8a2d\u5b9a\u5909\u66f4<\/h3>\n<p>\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3001SELinux\u306e\u8a2d\u5b9a\u3092\u5909\u66f4\u3057\u307e\u3059\u3002\u306a\u304a&#8221;abcde&#8221;\u306b\u306f\u5909\u66f4\u5f8c\u306e\u30dd\u30fc\u30c8\u756a\u53f7\u3092\u6307\u5b9a\u3057\u307e\u3059(\u4ee5\u4e0b\u540c\u3058\u3067\u3059)\u3002<\/p>\n<div class=\"code\"># semanage port &minus;a &minus;t ssh_port_t &minus;p tcp abcde<\/div>\n<p>&nbsp;<\/p>\n<h3>sshd\u306e\u8a2d\u5b9a\u5909\u66f4<\/h3>\n<p>\u4ee5\u4e0b\u306e\u624b\u9806\u3067sshd\u306e\u8a2d\u5b9a\u3092\u5909\u66f4\u3057\u307e\u3059\u3002<\/p>\n<ol>\n<li>\/etc\/sshd\/sshd_config\u306e\u8a2d\u5b9a\u306e\u3046\u3061\u3001\n<div class=\"code\"># Port 22<\/div>\n<p>&nbsp;<br \/>\n\u3068\u306a\u3063\u3066\u3044\u308b\u884c\u306e\u30b3\u30e1\u30f3\u30c8\u3092\u5916\u3057\u3001<\/p>\n<div class=\"code\">Port abcde<\/div>\n<p>&nbsp;<br \/>\n\u306b\u5909\u66f4\u3057\u307e\u3059\u3002<\/li>\n<li>root\u6a29\u9650\u3067\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3001sshd\u3092\u518d\u8d77\u52d5\u3057\u307e\u3059\u3002\n<div class=\"code\"># systemctl restart sshd<\/div>\n<p>&nbsp;\n<\/li>\n<\/ol>\n<h3>firewalld\u306e\u8a2d\u5b9a\u5909\u66f4<\/h3>\n<p>\u6700\u5f8c\u306bfirewalld\u306e\u8a2d\u5b9a\u3092\u5909\u66f4\u3057\u307e\u3059\u3002<\/p>\n<p>\u4ee5\u4e0b\u306e2\u901a\u308a\u306e\u65b9\u6cd5\u304c\u8003\u3048\u3089\u308c\u307e\u3059\u304c\u3001\u3069\u3061\u3089\u3067\u3082\u826f\u3044\u3068\u601d\u3044\u307e\u3059(\u203b\u500b\u4eba\u306e\u610f\u898b\u3067\u3059)\u3002<\/p>\n<h4>port\u306e\u8a2d\u5b9a\u3092\u8ffd\u52a0\u3059\u308b\u65b9\u6cd5<\/h4>\n<p>root\u6a29\u9650\u3067\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3001abcde\u756aport\u3078\u306e\u30a2\u30af\u30bb\u30b9\u3092\u8a31\u53ef\u3057\u307e\u3059\u3002\u306a\u304a\u3001zone\u540d\u306b\u306f\u5916\u90e8\u304b\u3089\u306e\u30a2\u30af\u30bb\u30b9\u306e\u8a2d\u5b9a\u3092\u884c\u3063\u3066\u3044\u308b\u3082\u306e\u3092\u6307\u5b9a\u3057\u307e\u3059\u3002<\/p>\n<div class=\"code\"># firewall&minus;cmd &#45;&#45;zone=&lt;zone\u540d> &#45;&#45;add&minus;port=abcde\/tcp &#45;&#45;permanent<br \/>\n# firewall&minus;cmd &#45;&#45;reload<\/div>\n<p>&nbsp;<\/p>\n<p>\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3001ports\u306b&#8221;abcde\/tcp&#8221;\u3068\u8868\u793a\u3055\u308c\u3066\u3044\u308c\u3070\u3001\u8a2d\u5b9a\u5b8c\u4e86\u3067\u3059\u3002<\/p>\n<div class=\"code\"># firewall&minus;cmd &#45;&#45;list&minus;all &#45;&#45;zone=&lt;zone\u540d><br \/>\n&lt;zone\u540d> (active)<br \/>\n(\u4e2d\u7565)<br \/>\n  ports: abcde\/tcp<br \/>\n(\u5f8c\u7565)\n<\/div>\n<p>&nbsp;<\/p>\n<h4>\u5c02\u7528\u306e\u30b5\u30fc\u30d3\u30b9\u3092\u4f5c\u308b\u65b9\u6cd5<\/h4>\n<p>firewalld\u306esshd\u7528\u306e\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u3092\u30b3\u30d4\u30fc\u3057\u3066\u66f8\u304d\u63db\u3048\u3066abcde\u756aport\u7528\u3067\u63a5\u7d9a\u3092\u5f85\u3061\u53d7\u3051\u308bsshd\u7528\u306e\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u3092\u4f5c\u6210\u3059\u308b\u65b9\u6cd5\u3067\u3059\u3002<\/p>\n<p>\u4ee5\u4e0b\u306e\u624b\u9806\u3067\u8a2d\u5b9a\u3057\u307e\u3059\u3002<\/p>\n<ol>\n<li>root\u6a29\u9650\u3067\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3001\u30b3\u30d4\u30fc\u5143\u3068\u306a\u308b\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u3092\u30ab\u30b9\u30bf\u30de\u30a4\u30ba\u3092\u3057\u305f\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u7528\u306e\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306b\u30b3\u30d4\u30fc\u3057\u307e\u3059\u3002\n<div class=\"code\"># cp \/usr\/lib\/firewalld\/services\/ssh.xml \\<br \/>\n\/etc\/firewalld\/services\/ssh-abcde.xml<\/div>\n<p>&nbsp;\n<\/li>\n<li>\/etc\/firewalld\/services\/ssh-abcde.xml\u3092\u9069\u5f53\u306a\u30a8\u30c7\u30a3\u30bf\u3067\u958b\u304d\u3001port\u30bf\u30b0\u306eport\u5c5e\u6027\u3092\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u5909\u66f4\u3057\u3001\u4fdd\u5b58\u3057\u307e\u3059\u3002\n<div class=\"code\">&lt;port protocol=&quot;tcp&quot; port=&quot;abcde&quot;\/><\/div>\n<p>&nbsp;\n<\/li>\n<li>root\u6a29\u9650\u3067\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3001ssh-abcde.xml\u3092\u30b5\u30fc\u30d3\u30b9\u3068\u3057\u3066\u8ffd\u52a0\u3057\u3001ssh\u3092\u524a\u9664\u3057\u307e\u3059\u3002\n<div class=\"code\"># firewall&minus;cmd &#45;&#45;zone=&lt;zone\u540d> &#45;&#45;add&minus;service=ssh-abcde &#45;&#45;permanent<br \/>\n# firewall&minus;cmd &#45;&#45;zone=&lt;zone\u540d> &#45;&#45;remove&minus;service=ssh &#45;&#45;permanent<br \/>\n# firewall&minus;cmd &#45;&#45;reload<\/div>\n<p>&nbsp;\n<\/li>\n<li>root\u6a29\u9650\u3067\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3001services\u306e\u9805\u306bssh-abcde\u304c\u542b\u307e\u308c\u3066\u3044\u3066\u3001\u304b\u3064ssh\u304c\u542b\u307e\u308c\u3066\u3044\u306a\u3051\u308c\u3070\u8a2d\u5b9a\u5b8c\u4e86\u3067\u3059\u3002\n<div class=\"code\"># firewall&minus;cmd &#45;&#45;list&minus;all &#45;&#45;zone=&lt;zone\u540d><br \/>\n&lt;zone\u540d> (active)<br \/>\n(\u4e2d\u7565)<br \/>\n  services: ssh-abcde<br \/>\n(\u5f8c\u7565)<\/div>\n<p>&nbsp;\n<\/li>\n<\/ol>\n<h3>\u52d5\u4f5c\u306e\u78ba\u8a8d<\/h3>\n<p>\u9069\u5f53\u306a\u7aef\u672b\u304b\u3089\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3001\u30ed\u30b0\u30a4\u30f3\u306b\u6210\u529f\u3057\u305f\u3089\u52d5\u4f5c\u78ba\u8a8d\u5b8c\u4e86\u3067\u3059\u3002<\/p>\n<div class=\"code\">$ ssh -p abcde &lt;server name><\/div>\n<p>&nbsp;<br \/>\n\u304a\u75b2\u308c\u69d8\u3067\u3057\u305f\u3002<\/p>\n<h2>sshd\u306eport\u756a\u53f7\u5909\u66f4\u5f8c\u306ejournal\u30ed\u30b0\u306e\u51fa\u529b\u72b6\u6cc1<\/h2>\n<p>sshd\u306eport\u756a\u53f7\u306e\u5909\u66f4\u5f8c\u306f\u3001journal\u30ed\u30b0\u306b\u306fsshd\u3078\u306e\u30a2\u30af\u30bb\u30b9\u304c\u539f\u56e0\u3068\u601d\u308f\u308c\u308b\u30e1\u30c3\u30bb\u30fc\u30b8\u304c\u51fa\u529b\u3055\u308c\u306a\u304f\u306a\u308a\u307e\u3057\u305f\u3002<\/p>\n<p>\u4ed6\u306b\u3082NetworkManager\u304c\u5927\u91cf\u306b\u51fa\u529b\u3057\u3066\u3044\u308bjournal\u30ed\u30b0\u304c\u3042\u308b\u3053\u3068\u304c\u308f\u304b\u3063\u305f\u306e\u3067\u3001journal\u30ed\u30b0\u306e\u51fa\u529b\u304c\u672c\u5f53\u306b\u5fc5\u8981\u306a\u30e1\u30c3\u30bb\u30fc\u30b8\u3060\u3051\u306b\u306a\u308b\u3068\u3044\u3046\u72b6\u614b\u306b\u306f\u306a\u3063\u3066\u3044\u307e\u305b\u3093\u304c\u3001\u51fa\u529b\u91cf\u306f1\/4\u7a0b\u5ea6\u306b\u6e1b\u3063\u3066\u3044\u308b\u3088\u3046\u3067\u3059\u3002<\/p>\n<h2>\u307e\u3068\u3081<\/h2>\n<p>ssh\u306e\u30dd\u30fc\u30c8\u756a\u53f7\u3092\u5909\u3048\u308b\u3053\u3068\u306b\u3088\u308a\u3001journal\u30ed\u30b0\u304c\u6fc0\u5897\u3059\u308b\u611f\u3058\u3067\u306f\u306a\u304f\u306a\u308a\u307e\u3057\u305f\u306e\u3067\u3001journal\u30ed\u30b0\u3092\u5927\u91cf\u306b\u51fa\u529b\u3059\u308b\u3053\u3068\u306b\u3088\u308b\u30b5\u30fc\u30d0\u306e\u30d1\u30d5\u30a9\u30fc\u30de\u30f3\u30b9\u306e\u4f4e\u4e0b\u3082\u9632\u3052\u305d\u3046\u3067\u3059\u3002<\/p>\n<p>\u307e\u305f\u3001NetworkManager\u304cjournal\u30ed\u30b0\u3092\u51fa\u529b\u3059\u308b\u539f\u56e0\u306f\u4e0d\u8981\u306a\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30fc\u30b9\u3092\u77ed\u3044\u5468\u671f\u3067enable\u306b\u4f7f\u7528\u3057\u3066\u5931\u6557\u3057\u3066\u3044\u308b\u65e8\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u304c\u51fa\u529b\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u539f\u56e0\u306e\u3088\u3046\u3067\u3059\u306e\u3067\u3001\u305d\u306e\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30fc\u30b9\u3092down\u3055\u305b\u308b\u3053\u3068\u306b\u3088\u308a\u3001journal\u30ed\u30b0\u306e\u51fa\u529b\u306b\u3064\u3044\u3066\u3082\u4f55\u3068\u304b\u9069\u6b63\u5316\u3067\u304d\u305d\u3046\u3067\u3059\u3002<\/p>\n<p>\u306a\u304a\u3001sshd\u306e\u8a2d\u5b9a(sshd_config)\u3067\u3059\u304c\u3001\u30dd\u30fc\u30c8\u756a\u53f7\u3092\u5909\u66f4\u3057\u3066\u3082\u30a2\u30af\u30bb\u30b9\u304c\u3055\u308c\u308b(\u30ed\u30b0\u30a4\u30f3\u306b\u5931\u6557\u3057\u305f\u65e8\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u304c\u8868\u793a\u3055\u308c\u308b)\u5834\u5408\u306b\u306f\u30d1\u30b9\u30ef\u30fc\u30c9\u8a8d\u8a3c\u306fno\u306b\u3057\u3066\u304a\u304d\u307e\u3057\u3087\u3046\u3002<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"ja\" dir=\"ltr\">SSH\u306e\u30dd\u30fc\u30c8\u756a\u53f7\u309222\u3068\u306f\u307e\u3063\u305f\u304f\u7121\u95a2\u4fc2\u306a\u3082\u306e\u306b\u5909\u3048\u3066\u307f\u305f\u306e\u3067\u3059\u304c\u3001\u305d\u308c\u3067\u3082\u653b\u6483\u7684\u306a\u30a2\u30af\u30bb\u30b9\u304c\u6765\u3066\u3044\u308b\u3088\u3046\u306a\u306e\u3067\u3001PasswordAuthentication \u3092 no \u306b\u8a2d\u5b9a\u3057\u3066\u307f\u305f\u3002<a href=\"https:\/\/twitter.com\/hashtag\/%E3%81%AA%E3%81%A9%E3%81%A9?src=hash&amp;ref_src=twsrc%5Etfw\">#\u306a\u3069\u3069<\/a><a href=\"https:\/\/twitter.com\/hashtag\/lifeinyokohama?src=hash&amp;ref_src=twsrc%5Etfw\">#lifeinyokohama<\/a><\/p>\n<p>&mdash; pandanote.info (@Pandanote_info) <a href=\"https:\/\/twitter.com\/Pandanote_info\/status\/1298024430593929216?ref_src=twsrc%5Etfw\">August 24, 2020<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>\u3053\u306e\u8a18\u4e8b\u306f\u4ee5\u4e0a\u3067\u3059\u3002<\/p>\n<h2>References \/ \u53c2\u8003\u6587\u732e<\/h2>\n<ul>\n<li><a href=\"https:\/\/weblabo.oscasierra.net\/openssh-sshd-centos7-change-port\/\">CentOS 7 \u3067 sshd \u306e\u30dd\u30fc\u30c8\u756a\u53f7\u3092\u5909\u66f4\u3059\u308b\u65b9\u6cd5<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\u306f\u3058\u3081\u306b \u6700\u8fd1\u3001\u8a18\u4e8b\u3092\u66f8\u3044\u3066\u3044\u308b\u969b\u306b\u753b\u50cf\u30d5\u30a1\u30a4\u30eb\u304c\u6025\u306b\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3067\u304d\u306a\u304f\u306a\u308a\u3001\u539f\u56e0\u3092\u8abf\u3079\u3066\u307f\u305f\u3068\u3053\u308d\u3001\u672cWeb\u30b5\u30a4\u30c8\u306ejournal\u30ed\u30b0\u304c\u6fc0\u5897\u3057\u305f\u305b\u3044\u3067filesystem\u306e\u4f7f\u7528\u7387\u304c100%\u3068\u306a\u3063\u3066\u3044\u307e\u3057\u305f\u3002 \u3068\u3044\u3046\u3053\u3068\u3067\u3001\u3044\u308d\u3044\u308d\u3068\u5bfe\u5fdc\u7b56\u3092\u691c\u8a0e&#038;\u5b9f\u884c\u3057\u305f\u7d50\u679c\u3001sshd\u306e\u30dd\u30fc\u30c8\u756a\u53f7\u3092\u5909\u66f4\u3059\u308b\u3053\u3068\u3068\u3057\u307e\u3057\u305f\u306e\u3067\u3001\u3053\u306e\u8a18\u4e8b\u3067\u306fsshd\u306e\u30dd\u30fc\u30c8\u756a\u53f7\u3092\u5909\u3048\u308b\u306b\u81f3\u308b\u307e\u3067\u306e\u7d4c\u7def\u306b\u3064\u3044\u3066\u66f8\u304d\u307e\u3059\u3002 \u2026 <span class=\"read-more\"><a href=\"https:\/\/pandanote.info\/?p=5581\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":5592,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8,3],"tags":[],"class_list":["post-5581","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-fedora","category-website-2"],"_links":{"self":[{"href":"https:\/\/pandanote.info\/index.php?rest_route=\/wp\/v2\/posts\/5581","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pandanote.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pandanote.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pandanote.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pandanote.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5581"}],"version-history":[{"count":14,"href":"https:\/\/pandanote.info\/index.php?rest_route=\/wp\/v2\/posts\/5581\/revisions"}],"predecessor-version":[{"id":7155,"href":"https:\/\/pandanote.info\/index.php?rest_route=\/wp\/v2\/posts\/5581\/revisions\/7155"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pandanote.info\/index.php?rest_route=\/wp\/v2\/media\/5592"}],"wp:attachment":[{"href":"https:\/\/pandanote.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5581"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pandanote.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5581"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pandanote.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5581"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}