Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I add fail2ban as good measure too.

I don't know about literally, but it helps.



It's can certainly be useful if you use anything with password auth or just want to avoid logs full of bots, but otherwise just change default SSH port.


If you only allow incomming traffic to sshd, and require ssh-key login (no password login), fail2ban will likely only add complexity, not security.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: