1 - I want to remove or denied root access for SSH from a distant location (or i want only local adress to be able to connect to my WD MY CLOUD DL2100 with SSH protocol). I tried to change /etc/sshd_confid but i can’t restart ssh service with busybox and everytime i reload the My Cloud device, the modification i made in the sshd_confid file are remove. Is there a way to make this changes permanent ? or to restart ssh service with busybox ?
2 - an other interrogation is : why am i able to connect myself with my root login remotely from a distant location as i didn’t forward my 22 port on my WD MY CLOUD devices or on my isp router. My port 22 is not forward and i get acces from a distant location. That’s odd right ?
Erm… On your router, don’t create a port forward for TCP port 22 and do not put the IP of your DL2100 onto the router’s DMZ. That will ensure that access to SSH (Port 22) remains accessible only to your local network.
Somewhere on your router you are exposing parts of your NAS or your entire NAS to the WAN side (Internet facing) side of the router.
UPnP is one, but you ruled that one out.
Fort forwarding is the other, but you also rules that one out.
The DMZ feature of the router is the only one left to check.
There does seem to be a reason where Port 22 would be forwarded and that would be if you’re using the remote back-up of the DL to another DL NAS and I believe for this port 22 need a port forward to the WAN if this is being done over the Internet, but then it’s not a wise thing to do. Better to set-up a VPN between sites, but that’s another topic.
I got to ask. Why did you add your NAS to the router’s DMZ? From a security standpoint it’s a dangerous thing to do. When you disabled the router’s DMZ and port 22 was still being passed through then you need to take a close look at the router’s settings.
On some routers some settings may need the router to be rebooted.
Routers are something that are forgotten about and they all have their quirks. Now you reset it it should not need another reset. with some routers for a setting to take effect a reboot is needed. Wish others that same setting will take without a reboot.
Is the firmware within your router up-to-date? That’s another thing people forget about. Applying any firmware updates to routers.