Good morning,
Manuel Schweizer manuel@cloudscale.ch writes:
Hey Tobi
Not seeing what you are seeing, but I can really recommend Fail2Ban if you are not using it already.
while the idea of fail2ban is good, I would actually recommend sshguard instead of fail2ban. If you are not using a recent version of fail2ban, it does not handle IPv6 at all and thus does not throttle IPv6 based attacks.
For that reason we switched to sshguard, a smaller and leaner dynamic blocker that fully supports IPv6 and has a variety of backends, including nftables.
Best,
Nico
-- Your Swiss, Open Source and IPv6 Virtual Machine. Now on www.datacenterlight.ch.