Not Just Paranoid

Another site by Pete Maynard

Whitelist IP addresses based on SSH origin

Here is how you create a list of IP addresses, to be used with NGINX, based on successful ssh connections.

$ cat /usr/bin/


# Make sure that we don't add it more than once.
if ! grep -q $PAM_RHOST $WHITELIST; then
	echo allow $PAM_RHOST\; >> $WHITELIST

$ cat /etc/pam.d/sshd

session optional seteuid /usr/bin/

Login via ssh and it will add your external IP address to the list.

$ cat /etc/nginx/conf/whitelist.conf


Reload NGINX for it to take affect.

13 Aug 2016

Website Last Updated on 15 Sep 2023 (CC BY-SA 4.0)

This site uses JQuery and nanogallery2 hosted by
for the Flickr photo feed and GoatCounter for user insights.