4 ms·
Install fail2ban, leave ssh on port 22, and have clean logs.
by nuclear_eclipse 13y ago
Install fail2ban, leave ssh on port 22, and have clean logs.
- antihero 13y agoIf someone knows your IP, can't they spoof the packets and get you banned from your own server? Or did they solve this issue somehow already?
- nuclear_eclipse 13y agoa) This was suggested as a method to combat random trolling from botnets, so this sort of response is highly unlikely unless you're already getting DDOS'd [1], and b) Fail2Ban allows you to whitelist some IP's that won't be banned, if you really need to protect against that sort of attack. 1: at which point you'd most likely need to be a lot more involved anyways, and you should most likely be running something more serious in front of your server anyways...
- greenail 13y agothere is a whitelist capability
- pilif 13y agoThe ssh authentication works over TCP which isn't realistically spoofable because to open a connection (which you need first, before you can fail to authenticate ssh), you need to be able to receive the response packets to your spoofed sender address