3 ms·
fail2ban is not very performant and it will only reduce the amount of attempts. An alternative is to add a nftables rule (or iptables or whatever firewall). Som
by idoubtit 3y ago
fail2ban is not very performant and it will only reduce the amount of attempts.
An alternative is to add a nftables rule (or iptables or whatever firewall). Something like :
table inet filter {
chain input {
tcp dport ssh accept comment "Accept SSH"
tcp dport 22 ct state new limit rate over 2/minute drop
But even with rate limiting, the logs are still polluted by auth attempts. Changing the port does little. The only solution we found was to configure port knocking (with direct access from a few whitelisted IPs).