Use TCP Wrappers to enhance SSHD security
Brief introduction:
TCP Wrappers is a host-based ACL system that is used to filter access to network services provided by the Linux system. He provides filtering to the daemon process through libwrap.
The workflow of TCP Wrappers:
1. Read the / etc/hosts.allow file, if the policy can be matched, then allow it; otherwise proceed to the next step
2. Read the / etc/hosts.deny file and reject it if the policy can be matched; otherwise, allow it.
Example: only 192.168.0.100DB 24 is allowed to access it.
# cat / etc/hosts.allow
Sshd:192.168.0.100/255.255.255.0
# cat / etc/hosts.deny
Sshd:All