Jan. 2nd, 2022

dennisgorelik: 2020-06-13 in my home office (Default)
When configuring production servers, is it better to use standard ports or non-standard ports ("security by obscurity")?

For SSH, should we use standard port 22 or some unknown port, such as 8756?
For SQL Server, should we use standard port 1433 or non-standard port (e.g. 3433)?

We setup firewalls on our servers.
These firewalls allow access to our servers only from a limited set of IP addresses (our developer machines + IP addresses of tech support of our hosting provider).

The advantage of using standard port is lower maintenance:
Less scripts required for setting up servers.
No need to change default port in client tools (such as PuTTY and SSMS).

The advantage of using non-standard ports -- is additional security [by obscurity].
It is trickier for an attacker to find out what port to attack.

Profile

dennisgorelik: 2020-06-13 in my home office (Default)
Dennis Gorelik

June 2025

S M T W T F S
1234 567
891011 12 13 14
15161718192021
22232425262728
2930     

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jul. 29th, 2025 03:59 pm
Powered by Dreamwidth Studios