Zixi Security Best Practices
Remote SSH Connections
2min
for os login, it is recommended to use passphrase protected ssh key pairs instead of passwords, and to not allow remote root login to do this, take the following steps generate a passphrase protected ssh key for each system that needs to access the server disable ssh password authentication disable root login legacy zixi feeders & receivers, zec and zixi broadcasters have a section under settings that enables you to define reverse tunnels to a remote ssh server, in order to allow accessing the application through a secure ssh tunnel remotely make sure to stop/delete all tunnels if remote access is not desirable to configure an ssh tunnel in legacy zixi feeder/receiver go to settings > ssh tunnels in the server connection section configure the server connection, as described in the table below click apply in the reverse tunnels section, click add the tunnel details dialog appears in the remote source port field, type the remote source port that will be used to connect in the local destination ip field, type the ip address of the zixi feeder/receiver in the local destination port field, type the port number in the zixi feeder/receiver for the specific reverse ssh tunnel click ok to configure an ssh tunnel in zixi broadcaster go to settings > ssh connections click + add connection the add ssh connection dialog appears configure the server connection, as described in the table below click apply the configuration will be added to the defined connections section on the screen click on the name of the new ssh connection in the remote source port field, specify the port that will be used to connect in the local destination ip field, specify the ip address of the zixi broadcaster in the local destination port field, specify the port number in the zixi broadcaster for the specific reverse ssh tunnel click ok field description server connection host specify the host name or ip address of the remote server for the ssh connection ssh port specify the port for the ssh connection default 22 username specify the username required for ssh connection default the username on the remote computer is the same as that on the local one key file indicates if a key file has been uploaded click upload key to upload a key to the server reverse tunnels remote source port specify the remote source port local destination ip specify the ip address of the local destination local destination port specify the port number of the local destination status specify the status of the ssh tunnel