halcon wrote:...
figueroa wrote:I have multiple servers on Desktop machines at the destination location
Sorry... What do you mean under "destination location" here?
The 10 machines, 1 server and 9 used as staff and student desktops, at the remote destination (the LOCATION; a school 600 miles to the north on real local-to-them hardware) are all on the same local net and each can be access via ssh via it's own local IP and SSH port. None of them have software updates installed automatically. The server runs Gentoo; the desktops are running MX-Linux.
I can access the server directly only through a single port forward to OpenSSH server. DropBear is also running on its own port on the server but that cannot be accessed directly from outside the LAN. Should I mess up, and find the sshd port not accessible on the server, I can ssh into any one of the desktop machines and access the DropBear ssh port on the server in order to fix its OpenSSH instance of sshd. It's just a back door. (Push comes to shove, a local helper can boot the server from a flash-drive with a live-usb running sshd, and I can get in that way, also by first accessing one of the desktop machines.)
Each machine is protected with Fail2Ban running with extremely stringent settings. Nothing runs on port 22. Still, we used to get a lot of probes, but after putting a couple of select alternate ports into non-use, we just don't get found anymore -- knock on wood.