You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置仅允许ZeroTier网络内设备通过ZeroTier IP SSH访问并禁用公网SSH

Restrict SSH Access to Only ZeroTier IPs

Got it, let's fix this so you can only SSH into your device via its ZeroTier IP, and block all SSH attempts from public IPs or non-ZT network devices. Here's how to set this up using common Linux firewall tools:

Option 1: Using UFW (Ubuntu/Debian-based systems)

This is the easiest method for Ubuntu, Debian, and their derivatives.

  • First, allow SSH access only from your ZeroTier subnet. Replace 10.xxx.xx.0/24 with the actual subnet of your ZeroTier network (you can get this by running zerotier-cli listnetworks on your device):
    sudo ufw allow from 10.xxx.xx.0/24 to any port 22
    
  • Next, deny all other incoming SSH connections. Important: Make sure you're already connected to the device via its ZeroTier IP before running this—otherwise you'll lock yourself out of remote access!
    sudo ufw deny 22
    
  • If UFW isn't enabled yet, turn it on and verify the rules:
    sudo ufw enable
    sudo ufw status verbose
    
    You should see a rule allowing your ZT subnet on port 22, and another rule denying all other traffic on port 22.

Option 2: Using Iptables (Generic Linux)

For systems that use iptables directly (like CentOS, Fedora, or older distros):

  • Add a rule to allow SSH from your ZeroTier subnet again (replace the subnet with your own):
    sudo iptables -A INPUT -p tcp --dport 22 -s 10.xxx.xx.0/24 -j ACCEPT
    
  • Block all other incoming SSH traffic:
    sudo iptables -A INPUT -p tcp --dport 22 -j DROP
    
  • Save the iptables rules so they persist after a reboot. The command varies by distro:
    • Debian/Ubuntu: sudo iptables-save > /etc/iptables/rules.v4
    • CentOS/RHEL (with iptables service): sudo service iptables save
    • For firewalld-based systems (CentOS 7+), use these commands instead:
      sudo firewall-cmd --add-rich-rule='rule family="ipv4" source address="10.xxx.xx.0/24" port port="22" protocol="tcp" accept' --permanent
      sudo firewall-cmd --remove-service=ssh --permanent
      sudo firewall-cmd --reload
      

Key Notes

  • Always test first: Before blocking all other SSH access, confirm you can successfully SSH into the device using its ZeroTier IP. If you're connected via public IP right now, switch to the ZT connection first!
  • Local LAN access (optional): If you also need to allow SSH from your local home/work LAN, add an extra allow rule before the deny rule. For example, if your LAN subnet is 192.168.1.0/24, run sudo ufw allow from 192.168.1.0/24 to any port 22 (for UFW) or the equivalent iptables/firewalld rule.
  • Verify ZeroTier subnet: Double-check your ZeroTier network's subnet with zerotier-cli listnetworks—it will show the routes entry for your network, which includes the subnet and mask.

The reason you could still SSH via public IP before is that your firewall wasn't restricting incoming traffic on port 22. These rules explicitly whitelist only your ZeroTier network for SSH, and block everything else.

内容的提问来源于stack exchange,提问作者bugo99iot

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:23:21