OpenRC SSH daemon default listen-on-all-interfaces without firewall rule
24K reputation · 17 Dec 2024, 05:24 UTC
The goal is to determine whether Artix Linux should apply a default network filter that limits incoming SSH connections to trusted interfaces or subnets while the OpenRC sshd service remains enabled by default.
Currently, installing the openssh package starts sshd listening on 0.0.0.0:22 and :::22, and the base ISO does not activate nftables/iptables or a default deny policy, leaving the port reachable from any network host unless an administrator manually adds rules. This creates a permission‑boundary gap that may expose systems to unintended access if strong authentication is not enforced.
Should Artix ship a minimal firewall profile that automatically restricts SSH, and if so, what interface or subnet criteria should the default rule use to balance security with administrative accessibility?