Fail2ban for SSH Security
This cluster centers on discussions recommending or debating the use of fail2ban and similar tools like sshguard to protect SSH servers from brute-force attacks, often alongside advice on key authentication and log monitoring.
Activity Over Time
Top Contributors
Keywords
Sample Comments
Why wouldn't something like fail2ban not work here? That's what it's built for and has been around for eons.
fail2ban may prove some use: https://www.fail2ban.org
Wouldn't something like fail2ban be enough?
No mention of sshguard or fail2ban?
Why are we building this into SSH itself? Isn't this what things like fail2ban are for?
You should still use fail2ban.https://news.ycombinator.com/item?id=11854576
fail2ban is useful for things other than SSH - I've seen it deal handily with people probing our asterisk server.
I highly recommend installing fail2ban to automatically firewall IPs with consecutive failed attempts, or if possible, disable password authentication altogether and use key auth.
Something like fail2ban could deal with this.
Hopefully they use something akin to fail2ban..