

Set up a firewall and only open port 22 with your IP (you can look it up using ip.me).
I keep wondering about this part whenever I read it. Do y’all have static IP addresses so you can do this easily? If I did this, I’d probably lock myself out within a week (which is roughly the interval at which my public IPv4 will change).


Sure, that’s what I do for hosting my stuff. DDNS does not help with SSH whitelisting because that is IP-based, not based on a URL.