ELSEIF
Your brief EB
1,975 stories from 226 feeds 1249 clusters Refreshed 2 minutes ago next pull 06:34

INFRA Signal 86

OpenBSD tutorial demonstrates SSH access restricted to WireGuard VPN peers only

Illustration only Photo by Conny Schneider on Unsplash

A tutorial outlines configuring OpenBSD to accept SSH connections exclusively from WireGuard VPN peers, reducing exposure to brute-force attacks without relying on static client IPs

WHY IT MATTERS

Engineers running OpenBSD servers can now shield SSH from internet-wide scans while retaining remote access. The approach trades IP-based firewall rules for cryptographic peer authentication, eliminating the need to track dynamic client addresses. It also provides a practical use case for WireGuard’s kernel-level VPN support on OpenBSD

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

SSH connections are accepted only from WireGuard VPN peers, blocking all unauthenticated traffic at the network layer

02

WireGuard’s public-key authentication replaces IP-based allow-lists, removing the need to update firewall rules when client IPs change

03

The setup leverages OpenBSD’s native WireGuard kernel support, avoiding user-space VPN overhead for SSH tunnelling

THE READ

What the cluster adds up to.

ORIGINAL ANALYSIS

The tutorial describes a configuration that restricts SSH access to clients authenticated via WireGuard. This shifts the security boundary from the public internet to the VPN tunnel, effectively hiding the SSH port from unauthenticated scans. The change is transparent to SSH itself; the daemon continues to listen on its usual port, but only WireGuard peers can reach it. This reduces log noise from brute-force attempts without altering SSH’s authentication mechanisms.

WireGuard’s public-key authentication eliminates the need for static client IP addresses. Each peer is identified by its cryptographic key rather than its network address, so dynamic IP changes from ISPs no longer require firewall updates. The configuration maps WireGuard IPs to public keys, allowing the server to accept traffic only from pre-authorised peers. This simplifies remote access for users with changing IPs, such as those on mobile or residential connections.

OpenBSD’s kernel-level WireGuard support ensures the VPN operates with minimal overhead. The tutorial leverages this by configuring WireGuard as a network interface, allowing standard firewall rules to filter traffic before it reaches SSH. This avoids the latency and complexity of user-space VPN solutions, making the setup suitable for low-resource environments. However, the approach requires maintaining WireGuard key pairs and peer configurations, adding operational overhead compared to simple IP-based firewall rules.

The solution stops working if WireGuard itself is compromised or misconfigured. A misconfigured peer list or leaked private key could expose SSH to unauthorised access, bypassing the intended security boundary. Additionally, the setup does not protect against attacks from within the VPN, such as compromised client machines. Engineers must ensure WireGuard keys are securely stored and rotated, as their compromise would grant access equivalent to a stolen SSH private key.

Written by elseif from the cluster below · checked for specifics the sources never contained

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
Nemin's Blog Tunnelling SSH over WireGuard on OpenBSD Open ↗