Hello I am wondering if there is increased network/packet security by connecting to a server over ssh through a VPN hosted by that same server as opposed to without first tunneling by VPN. I imagine with or without tunneling through a VPN there would be latency/speed differences too?

  • Ponziani@sh.itjust.worksOP
    link
    fedilink
    arrow-up
    4
    ·
    7 months ago

    Both require opening a port but theoretically ssh going through the vpn would mean port 22 does not need to be open/forwarded right, as opposed to both port 22 and whichever for the VPN open?

    • lurch (he/him)@sh.itjust.works
      link
      fedilink
      arrow-up
      3
      ·
      7 months ago

      The SSH port can be set to just accept connections from within the VPN.

      However, what I meant is: VPN does allow for more than SSH. Let’s assume something like you allowed your girlfriends phone to use your wifi, but she uses an app with a Chinese backdoor. The Chinese hacked your network printer which is available to all using the wifi. Your linux CUPS printing service talks to the printer and gets infected with a worm, but being linux it’s confined within the things the cups user can access.

      At that point the attacker/worm has no access to your personal files yet, except for what you print. Nor does the attacker/worm know about your server.

      Now when you use just SSH it will likely stay that way.

      If you use VPN though, it will allow the worm/attacker to find out about the existence of the server and send network traffic to your server. Hopefully, that doesn’t get them far, but it’s an additional attack vector they get.

      • Ponziani@sh.itjust.worksOP
        link
        fedilink
        arrow-up
        2
        ·
        7 months ago

        This is the first that I have heard about setting the SSH port to only accept connections from the VPN, is there a term or something I can search about this online? Or is this basically just allowing port 22 open on a device and not forwarding the port on the router as when a different device tunnels into the same network through the VPN it can already talk to the first device?

        • lurch (he/him)@sh.itjust.works
          link
          fedilink
          arrow-up
          1
          ·
          edit-2
          7 months ago

          You would either configure the Linux firewall of the router or server to drop everything on the SSH port not from the VPN IP/interface or change the ListenAdress in /etc/ssh/sshd , but be careful: Don’t lock yourself out!