This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Blocking certain IP's from ssh access

Hi board,

I need to have the network for accessing the ssh-access set to ANY.
Nevertheless, no some script kiddys are brute forcing my ssh port like hell.
Is there a way of telling ssh to block the source ip for a certain amount of time if having 3 failed logins? Like doing that on the webaccess page.

Or is there a way of making a rule in the ssh access frame for NOT-Host x.x.x.x?

Thanks a lot for you replys.
Cheers
Marcus


This thread was automatically locked due to age.
Parents
  • Why do you have it set to ANY?  We never setup a customer's system in this manner.  If you have it set that way to allow a roving user to login, have them use the VPN to connect in first.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Reply
  • Why do you have it set to ANY?  We never setup a customer's system in this manner.  If you have it set that way to allow a roving user to login, have them use the VPN to connect in first.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Children