{"id":4855,"date":"2023-02-27T22:34:00","date_gmt":"2023-02-28T04:34:00","guid":{"rendered":"https:\/\/www.incredigeek.com\/home\/?p=4855"},"modified":"2023-02-27T22:05:20","modified_gmt":"2023-02-28T04:05:20","slug":"hardening-ssh-on-mikrotik-routers","status":"publish","type":"post","link":"https:\/\/www.incredigeek.com\/home\/hardening-ssh-on-mikrotik-routers\/","title":{"rendered":"Hardening SSH on Mikrotik Routers"},"content":{"rendered":"\n<p>Here are the commands you&#8217;ll need to harden SSH on your Mikrotik Routers.  It looks like it still can use SSH-RSA, but it does get rid of most of the weaker crytpo algorithms.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">\/ip\/ssh\/set strong-crypto=yes allow-none-crypto=no always-allow-password-login=no host-key-size=4096<\/pre>\n\n\n\n<p>We&#8217;ll want to regenerate the Host Key now that the settings have been changed.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">\/ip\/ssh\/regenerate-host-key<\/pre>\n\n\n\n<p>It will prompt to enter [y\/N] to confirm that you actually want to regenerate the host key.  Hit y<\/p>\n\n\n\n<p>After your done, you can use something like ssh-audit to check your equipment.<br><a href=\"https:\/\/www.ssh-audit.com\/\">https:\/\/www.ssh-audit.com\/<\/a><\/p>\n\n\n\n<p>Further hardening information is available at the following link.<br><a href=\"https:\/\/wiki.mikrotik.com\/wiki\/Manual:Securing_Your_Router\">https:\/\/wiki.mikrotik.com\/wiki\/Manual:Securing_Your_Router<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Here are the commands you&#8217;ll need to harden SSH on your Mikrotik Routers. It looks like it still can use SSH-RSA, but it does get rid of most of the weaker crytpo algorithms. \/ip\/ssh\/set strong-crypto=yes allow-none-crypto=no always-allow-password-login=no host-key-size=4096 We&#8217;ll want &hellip; <a href=\"https:\/\/www.incredigeek.com\/home\/hardening-ssh-on-mikrotik-routers\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1408,452,573],"tags":[1409,1309,301,388,221],"class_list":["post-4855","post","type-post","status-publish","format-standard","hentry","category-hardening-guides","category-mikrotik","category-security","tag-audit","tag-hardening","tag-mikrotik","tag-routeros","tag-ssh"],"_links":{"self":[{"href":"https:\/\/www.incredigeek.com\/home\/wp-json\/wp\/v2\/posts\/4855","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.incredigeek.com\/home\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.incredigeek.com\/home\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.incredigeek.com\/home\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.incredigeek.com\/home\/wp-json\/wp\/v2\/comments?post=4855"}],"version-history":[{"count":1,"href":"https:\/\/www.incredigeek.com\/home\/wp-json\/wp\/v2\/posts\/4855\/revisions"}],"predecessor-version":[{"id":4856,"href":"https:\/\/www.incredigeek.com\/home\/wp-json\/wp\/v2\/posts\/4855\/revisions\/4856"}],"wp:attachment":[{"href":"https:\/\/www.incredigeek.com\/home\/wp-json\/wp\/v2\/media?parent=4855"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.incredigeek.com\/home\/wp-json\/wp\/v2\/categories?post=4855"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.incredigeek.com\/home\/wp-json\/wp\/v2\/tags?post=4855"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}