如何配置仅允许ZeroTier网络内设备通过ZeroTier IP SSH访问并禁用公网SSH
Restrict SSH Access to Only ZeroTier IPs
Got it, let's fix this so you can only SSH into your device via its ZeroTier IP, and block all SSH attempts from public IPs or non-ZT network devices. Here's how to set this up using common Linux firewall tools:
Option 1: Using UFW (Ubuntu/Debian-based systems)
This is the easiest method for Ubuntu, Debian, and their derivatives.
- First, allow SSH access only from your ZeroTier subnet. Replace
10.xxx.xx.0/24with the actual subnet of your ZeroTier network (you can get this by runningzerotier-cli listnetworkson your device):sudo ufw allow from 10.xxx.xx.0/24 to any port 22 - Next, deny all other incoming SSH connections. Important: Make sure you're already connected to the device via its ZeroTier IP before running this—otherwise you'll lock yourself out of remote access!
sudo ufw deny 22 - If UFW isn't enabled yet, turn it on and verify the rules:
You should see a rule allowing your ZT subnet on port 22, and another rule denying all other traffic on port 22.sudo ufw enable sudo ufw status verbose
Option 2: Using Iptables (Generic Linux)
For systems that use iptables directly (like CentOS, Fedora, or older distros):
- Add a rule to allow SSH from your ZeroTier subnet again (replace the subnet with your own):
sudo iptables -A INPUT -p tcp --dport 22 -s 10.xxx.xx.0/24 -j ACCEPT - Block all other incoming SSH traffic:
sudo iptables -A INPUT -p tcp --dport 22 -j DROP - Save the iptables rules so they persist after a reboot. The command varies by distro:
- Debian/Ubuntu:
sudo iptables-save > /etc/iptables/rules.v4 - CentOS/RHEL (with iptables service):
sudo service iptables save - For firewalld-based systems (CentOS 7+), use these commands instead:
sudo firewall-cmd --add-rich-rule='rule family="ipv4" source address="10.xxx.xx.0/24" port port="22" protocol="tcp" accept' --permanent sudo firewall-cmd --remove-service=ssh --permanent sudo firewall-cmd --reload
- Debian/Ubuntu:
Key Notes
- Always test first: Before blocking all other SSH access, confirm you can successfully SSH into the device using its ZeroTier IP. If you're connected via public IP right now, switch to the ZT connection first!
- Local LAN access (optional): If you also need to allow SSH from your local home/work LAN, add an extra allow rule before the deny rule. For example, if your LAN subnet is
192.168.1.0/24, runsudo ufw allow from 192.168.1.0/24 to any port 22(for UFW) or the equivalent iptables/firewalld rule. - Verify ZeroTier subnet: Double-check your ZeroTier network's subnet with
zerotier-cli listnetworks—it will show theroutesentry for your network, which includes the subnet and mask.
The reason you could still SSH via public IP before is that your firewall wasn't restricting incoming traffic on port 22. These rules explicitly whitelist only your ZeroTier network for SSH, and block everything else.
内容的提问来源于stack exchange,提问作者bugo99iot
相关产品推荐
相关产品推荐

