I've already read that some here think that forcing users to use Console via SSH and Serial Console is the only way and that having a console in GUI is a security flaw. I happen to think that forcing one to use SSH is a security flaw. Any way to remedy it without hearing from the wise guys about how their way is the only way?
Hm, I think protecting via VPN and block the rest is fine. Also a dedicated management network without users is fine.
SSH is the most secure remote acess method existing. Just keep password login disabled and use public key authentication.