Red Hat Enterprise Linux - Allow Root Login From a Specific IP Address Only

Title: Red Hat Enterprise Linux - Allow Root Login From a Specific IP Address Only
Object Name: mmr_kc-0119626
Document Type: Support Information
Original owner: KCS - Linux
Disclosure level: Public
Version state: final
Environment
FACT:Red Hat Enterprise Linux
Questions/Symptoms
GOAL:Restrict root SSH login to a single IP address
Cause
CAUSE:
Answer/Solution
FIX:This can be accomplished with the use of PAM access controls.  There are two steps:

1. In /etc/pam.d/sshd, add the following line:

account    required     pam_access.so


2. In /etc/security/access.conf, set up root access controls by adding the following two lines at the end of the file:

+ : root : IP_address
- : root : ALL


Replace "IP_address" with the IP address of the system from which root logins will be allowed.  Note that there is a space before and after each colon.  The first line allows root access from the specified IP address; the second line denies root access from everywhere else.  The order of these two lines is significant.  This will take effect immediately with no need to reboot or restart any daemons.


Login attempts that are blocked by this check will be logged in /var/log/secure:

Jul 15 16:51:42 hostname sshd[18241]: fatal: Access denied for user root by PAM account configuration

This method of access control is very flexible and powerful.  For example, if you should need to add a second allowed host at some point in the future, simply add its IP address to the first line:

+ : root : IP_address_1 IP_address_2
- : root : ALL


There are many other options, which are well documented within the access.conf file itself or its reference page.
0 (0)
Article Rating (No Votes)
Rate this article
Attachments
There are no attachments for this article.
Comments
There are no comments for this article. Be the first to post a comment.
Full Name
Email Address
Security Code Security Code
Related Articles RSS Feed
Używanie rsync poprzez Secure Shell
Viewed 42035 times since Thu, May 24, 2018
Inxi – A Powerful Feature-Rich Commandline System Information Tool for Linux
Viewed 19795 times since Sat, Jun 2, 2018
Manage Linux Password Expiration and Aging Using chage
Viewed 6166 times since Tue, Sep 11, 2018
socat: Linux / UNIX TCP Port Forwarder
Viewed 10901 times since Tue, Aug 6, 2019
ZFS: Verify/change properties of a zfs filesystem
Viewed 3483 times since Sun, Jun 3, 2018
Cron YUM How to use yum-cron to automatically update RHEL/CentOS Linux
Viewed 3345 times since Fri, Oct 26, 2018
LVM: Rename root VG/LV
Viewed 8583 times since Sat, Jun 2, 2018
systemctl Use systemd to Start a Linux Service at Boot
Viewed 6801 times since Mon, Dec 7, 2020
What is OS Watcher Utility and How to use it for Database Troubleshooting ?
Viewed 32062 times since Thu, Jun 21, 2018
CentOS / RHEL 7 : Configuring an NFS server and NFS client Linux NFS
Viewed 18196 times since Fri, Feb 21, 2020