Also sprach Andy Ruhl (
> On 8/17/05, Steven M. Bellovin <> wrote:
> Is it your goal to just listen on 2 ports or actually run a totally
> separate instance? If the later, do you mind if I ask why?

Multiple sshd instances can be useful if you want redundancy for
security reasons (even sshd might crash or hang, so a fallback
solution is required) or if you want to use several instances for
several users/groups.=20

On our PostgreSQL server, three instances of sshd listen,=20
one on :22 and another on :443, they are the same and
:443 serves as a fallback solution. Additionally, both are set to
accept PubKey only and allow only my user, to avoid dictionary
attacks. A third sshd listens on the internal NIC for the institutes
members, it is filtered with ipf to allow only specified clients and
it does allow password based authentication.

BTW: sometime ago I wrote a German explanation of the sshd.config
options, it can be fount at

