4 ms·
Just use blacklistd [0], on FreeBSD, instead of changing the port. It works with sshd, and it temporarily blocks IPs that are abusive. [0]: https://docs.freebs
by drclau 5y ago
Just use blacklistd [0], on FreeBSD, instead of changing the port. It works with sshd, and it temporarily blocks IPs that are abusive.
[0]: https://docs.freebsd.org/en/books/handbook/firewalls/#firewalls-blacklistd https://docs.freebsd.org/en/books/handbook/firewalls/#firewa...
- LukeShu 5y agoI always move sshd to a non-standard port, and blacklistd would not address the reason why I do it. One IP abusing it and trying to gain access isn't what I address by moving the port. I move the port to cut out the noise of the thousands of IPs that will connect to it once to probe it and never again. The volume of those one-off probes is so dramatic that it makes the logs entirely useless. By moving the port, I cut out that noise so that if I glance at the logs I actually have a chance of noticing anything that is worth noticing.