ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Secure Meshcentral server on Vultr

    IT Discussion
    meshcentral mc ssh keys
    8
    40
    2.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller @pmoncho
      last edited by

      @pmoncho said in Secure Meshcentral server on Vultr:

      --Change SSH to different port (is it worth it?)

      Personally I don't think so. Use keys, use fail2ban, if you change the port, do it because it makes your logs cleaner, not for security.

      1 Reply Last reply Reply Quote 3
      • scottalanmillerS
        scottalanmiller @JaredBusch
        last edited by

        @JaredBusch said in Secure Meshcentral server on Vultr:

        @pmoncho said in Secure Meshcentral server on Vultr:

        Based on my setup below, the two possible changes I can think of based on my reading,
        --Change SSH to different port (is it worth it?)
        --Change port in MC to 4433 instead of 443

        This serves zero purpose except to complicate your life.

        I agree. Makes things harder for you, not harder for hackers.

        pmonchoP 1 Reply Last reply Reply Quote 0
        • JaredBuschJ
          JaredBusch @pmoncho
          last edited by

          @pmoncho said in Secure Meshcentral server on Vultr:

          @JaredBusch
          Thanks. That is what I was thinking. I just read read and read more but I have not been a security through obscurity kinda person.

          When it comes to the internet, there is no such thing as security through obscurity.

          No one is looking at this shit. It is bots and they don't care WTF port they find open.

          There absolutely are bots out there attempting to open connections to every port on every IP.

          There are exactly 2 things that changing the port does.

          1. It reduces the hits, so you will have smaller logs of hits, but it is only a reduction. Once one of the bots finds it, your IP goes on a list and is resold.
          2. It causes you to fucking cuss at yourself everytime you forget to use the "random" port you selected.
          1 Reply Last reply Reply Quote 5
          • pmonchoP
            pmoncho @scottalanmiller
            last edited by

            @scottalanmiller said in Secure Meshcentral server on Vultr:

            @JaredBusch said in Secure Meshcentral server on Vultr:

            @pmoncho said in Secure Meshcentral server on Vultr:

            Based on my setup below, the two possible changes I can think of based on my reading,
            --Change SSH to different port (is it worth it?)
            --Change port in MC to 4433 instead of 443

            This serves zero purpose except to complicate your life.

            I agree. Makes things harder for you, not harder for hackers.

            I am of the belief that to hackers, they will scan as many ports for as many protocols as they can. If they can't find SSH on 22, they will search all the way up to 65543 to find it.

            scottalanmillerS 1 Reply Last reply Reply Quote 1
            • scottalanmillerS
              scottalanmiller @pmoncho
              last edited by

              @pmoncho said in Secure Meshcentral server on Vultr:

              @scottalanmiller said in Secure Meshcentral server on Vultr:

              @JaredBusch said in Secure Meshcentral server on Vultr:

              @pmoncho said in Secure Meshcentral server on Vultr:

              Based on my setup below, the two possible changes I can think of based on my reading,
              --Change SSH to different port (is it worth it?)
              --Change port in MC to 4433 instead of 443

              This serves zero purpose except to complicate your life.

              I agree. Makes things harder for you, not harder for hackers.

              I am of the belief that to hackers, they will scan as many ports for as many protocols as they can. If they can't find SSH on 22, they will search all the way up to 65543 to find it.

              Absolutely. They will look for all open ports, regardless of protocol, too.

              1 Reply Last reply Reply Quote 1
              • Reid CooperR
                Reid Cooper @pmoncho
                last edited by

                @pmoncho said in Secure Meshcentral server on Vultr:

                Ubuntu 18.04.2 (I know others like Fedora and Ubuntu current)

                Why the older release? Likely to be faster and more stable on the newer release and MeshCentral is being used there.

                1 Reply Last reply Reply Quote 0
                • Reid CooperR
                  Reid Cooper @pmoncho
                  last edited by

                  @pmoncho said in Secure Meshcentral server on Vultr:

                  Vultr Firewall setup (I don't believe I need this as UFW is setup on Ubuntu)

                  Less portable that way. Why not do it the normal way?

                  pmonchoP 2 Replies Last reply Reply Quote 0
                  • Reid CooperR
                    Reid Cooper @pmoncho
                    last edited by

                    @pmoncho said in Secure Meshcentral server on Vultr:

                    UFW
                    --Allow SSH port 22 from Home and Work IP only
                    --Allow 80 and 443 from anywhere

                    Is port 80 needed?

                    black3dynamiteB 1 Reply Last reply Reply Quote 0
                    • black3dynamiteB
                      black3dynamite @Reid Cooper
                      last edited by

                      @Reid-Cooper said in Secure Meshcentral server on Vultr:

                      @pmoncho said in Secure Meshcentral server on Vultr:

                      UFW
                      --Allow SSH port 22 from Home and Work IP only
                      --Allow 80 and 443 from anywhere

                      Is port 80 needed?

                      Maybe if nginx is acting as a reverse proxy server.
                      User > nginx {80 and 443} > meshcentral {443}

                      scottalanmillerS 1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller @black3dynamite
                        last edited by

                        @black3dynamite wouldnt that take the secure meshcentral and expose it as unencrypted?

                        black3dynamiteB 1 Reply Last reply Reply Quote 0
                        • black3dynamiteB
                          black3dynamite @scottalanmiller
                          last edited by

                          @scottalanmiller said in Secure Meshcentral server on Vultr:

                          @black3dynamite wouldnt that take the secure meshcentral and expose it as unencrypted?

                          Now I'm only assuming if Nginx and MeshCentral are on separate VM
                          You are have nginx listening on port 80 and then redirect to 443. Proxy pass is set to the MeshCentral VM address and port 443.

                          Now if nginx and MeshCentral is on the same VM, I would do something like the example on page 30, 31, and 32.
                          http://info.meshcentral.com/downloads/MeshCentral2/MeshCentral2UserGuide-0.2.2.pdf

                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @black3dynamite
                            last edited by

                            @black3dynamite said in Secure Meshcentral server on Vultr:

                            @scottalanmiller said in Secure Meshcentral server on Vultr:

                            @black3dynamite wouldnt that take the secure meshcentral and expose it as unencrypted?

                            Now I'm only assuming if Nginx and MeshCentral are on separate VM
                            You are have nginx listening on port 80 and then redirect to 443. Proxy pass is set to the MeshCentral VM address and port 443.

                            If Nginx listens on port 80, that would make MC think it was secure, but have the encryption removed before going over the Internet. It's the other way that you'd want to do it. MC on 80, Nginx listening on 443.

                            1 Reply Last reply Reply Quote 0
                            • JaredBuschJ
                              JaredBusch
                              last edited by

                              Mesh Central has to listen on 80 i order to get the LE cert.

                              Other than that, instance, I believe it force edirects traffic to 443

                              1 Reply Last reply Reply Quote 1
                              • pmonchoP
                                pmoncho @Reid Cooper
                                last edited by

                                @Reid-Cooper said in Secure Meshcentral server on Vultr:

                                @pmoncho said in Secure Meshcentral server on Vultr:

                                Vultr Firewall setup (I don't believe I need this as UFW is setup on Ubuntu)

                                Less portable that way. Why not do it the normal way?

                                I went the LTS route as I used Vultr's image and its what I know at the moment. No other reason. Someday I will change it over to Ubuntu Current or Fedora.

                                scottalanmillerS 1 Reply Last reply Reply Quote 0
                                • pmonchoP
                                  pmoncho @Reid Cooper
                                  last edited by

                                  @Reid-Cooper said in Secure Meshcentral server on Vultr:

                                  @pmoncho said in Secure Meshcentral server on Vultr:

                                  Vultr Firewall setup (I don't believe I need this as UFW is setup on Ubuntu)

                                  Less portable that way. Why not do it the normal way?

                                  Little lost here. What is the "normal way?"

                                  Basically, I setup the Vultr FW because I wanted to make sure the MC server had a FW up front during the initial install and config. After setting up UFW on Ubuntu, I realized that I may no longer need it.

                                  DashrenderD scottalanmillerS 2 Replies Last reply Reply Quote 0
                                  • DashrenderD
                                    Dashrender @pmoncho
                                    last edited by

                                    @pmoncho said in Secure Meshcentral server on Vultr:

                                    @Reid-Cooper said in Secure Meshcentral server on Vultr:

                                    @pmoncho said in Secure Meshcentral server on Vultr:

                                    Vultr Firewall setup (I don't believe I need this as UFW is setup on Ubuntu)

                                    Less portable that way. Why not do it the normal way?

                                    Little lost here. What is the "normal way?"

                                    Basically, I setup the Vultr FW because I wanted to make sure the MC server had a FW up front during the initial install and config. After setting up UFW on Ubuntu, I realized that I may no longer need it.

                                    Is that really a risk during install though? What ports are open during install that would make this a concern?

                                    pmonchoP 1 Reply Last reply Reply Quote 0
                                    • pmonchoP
                                      pmoncho @Dashrender
                                      last edited by

                                      @Dashrender said in Secure Meshcentral server on Vultr:

                                      @pmoncho said in Secure Meshcentral server on Vultr:

                                      @Reid-Cooper said in Secure Meshcentral server on Vultr:

                                      @pmoncho said in Secure Meshcentral server on Vultr:

                                      Vultr Firewall setup (I don't believe I need this as UFW is setup on Ubuntu)

                                      Less portable that way. Why not do it the normal way?

                                      Little lost here. What is the "normal way?"

                                      Basically, I setup the Vultr FW because I wanted to make sure the MC server had a FW up front during the initial install and config. After setting up UFW on Ubuntu, I realized that I may no longer need it.

                                      Is that really a risk during install though? What ports are open during install that would make this a concern?

                                      Truth is, I have no idea. Most likely not though. Just enabled it until I had the OS installed, opened the SSH port so I could get in from my IP and configured UFW on Ubuntu. Just never disabled the Vultr FW. Figure it didn't hurt so I kept it.

                                      I guess its just personal trust issues. I even sometimes like my car doors while parked in my garage with a garage door opener and locked side door. Weird I know! 🙂

                                      dafyreD 1 Reply Last reply Reply Quote 0
                                      • dafyreD
                                        dafyre @pmoncho
                                        last edited by

                                        @pmoncho said in Secure Meshcentral server on Vultr:

                                        @Dashrender said in Secure Meshcentral server on Vultr:

                                        @pmoncho said in Secure Meshcentral server on Vultr:

                                        @Reid-Cooper said in Secure Meshcentral server on Vultr:

                                        @pmoncho said in Secure Meshcentral server on Vultr:

                                        Vultr Firewall setup (I don't believe I need this as UFW is setup on Ubuntu)

                                        Less portable that way. Why not do it the normal way?

                                        Little lost here. What is the "normal way?"

                                        Basically, I setup the Vultr FW because I wanted to make sure the MC server had a FW up front during the initial install and config. After setting up UFW on Ubuntu, I realized that I may no longer need it.

                                        Is that really a risk during install though? What ports are open during install that would make this a concern?

                                        Truth is, I have no idea. Most likely not though. Just enabled it until I had the OS installed, opened the SSH port so I could get in from my IP and configured UFW on Ubuntu. Just never disabled the Vultr FW. Figure it didn't hurt so I kept it.

                                        I guess its just personal trust issues. I even sometimes like my car doors while parked in my garage with a garage door opener and locked side door. Weird I know! 🙂

                                        A little paranoia isn't a bad thing... but I think you may be tiptoeing the line.

                                        pmonchoP 1 Reply Last reply Reply Quote 0
                                        • pmonchoP
                                          pmoncho @dafyre
                                          last edited by

                                          @dafyre said in Secure Meshcentral server on Vultr:

                                          @pmoncho said in Secure Meshcentral server on Vultr:

                                          @Dashrender said in Secure Meshcentral server on Vultr:

                                          @pmoncho said in Secure Meshcentral server on Vultr:

                                          @Reid-Cooper said in Secure Meshcentral server on Vultr:

                                          @pmoncho said in Secure Meshcentral server on Vultr:

                                          Vultr Firewall setup (I don't believe I need this as UFW is setup on Ubuntu)

                                          Less portable that way. Why not do it the normal way?

                                          Little lost here. What is the "normal way?"

                                          Basically, I setup the Vultr FW because I wanted to make sure the MC server had a FW up front during the initial install and config. After setting up UFW on Ubuntu, I realized that I may no longer need it.

                                          Is that really a risk during install though? What ports are open during install that would make this a concern?

                                          Truth is, I have no idea. Most likely not though. Just enabled it until I had the OS installed, opened the SSH port so I could get in from my IP and configured UFW on Ubuntu. Just never disabled the Vultr FW. Figure it didn't hurt so I kept it.

                                          I guess its just personal trust issues. I even sometimes like my car doors while parked in my garage with a garage door opener and locked side door. Weird I know! 🙂

                                          A little paranoia isn't a bad thing... but I think you may be tiptoeing the line.

                                          No doubt. Have to let go a little.

                                          dafyreD 1 Reply Last reply Reply Quote 0
                                          • dafyreD
                                            dafyre @pmoncho
                                            last edited by

                                            @pmoncho said in Secure Meshcentral server on Vultr:

                                            @dafyre said in Secure Meshcentral server on Vultr:

                                            @pmoncho said in Secure Meshcentral server on Vultr:

                                            @Dashrender said in Secure Meshcentral server on Vultr:

                                            @pmoncho said in Secure Meshcentral server on Vultr:

                                            @Reid-Cooper said in Secure Meshcentral server on Vultr:

                                            @pmoncho said in Secure Meshcentral server on Vultr:

                                            Vultr Firewall setup (I don't believe I need this as UFW is setup on Ubuntu)

                                            Less portable that way. Why not do it the normal way?

                                            Little lost here. What is the "normal way?"

                                            Basically, I setup the Vultr FW because I wanted to make sure the MC server had a FW up front during the initial install and config. After setting up UFW on Ubuntu, I realized that I may no longer need it.

                                            Is that really a risk during install though? What ports are open during install that would make this a concern?

                                            Truth is, I have no idea. Most likely not though. Just enabled it until I had the OS installed, opened the SSH port so I could get in from my IP and configured UFW on Ubuntu. Just never disabled the Vultr FW. Figure it didn't hurt so I kept it.

                                            I guess its just personal trust issues. I even sometimes like my car doors while parked in my garage with a garage door opener and locked side door. Weird I know! 🙂

                                            A little paranoia isn't a bad thing... but I think you may be tiptoeing the line.

                                            No doubt. Have to let go a little.

                                            But only a little. Don't want somebody to steal your car when they get into your garage. 😉

                                            DashrenderD 1 Reply Last reply Reply Quote 1
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post