Re: Question on rate limiting on nftables

Slavko <[email protected]> Mon, 08 Jun 2026 14:32:31 +0000
Newsgroups gmane.comp.security.firewalls.netfilter.general
Message-ID <[email protected]>
D=C5=88a 8=2E j=C3=BAna 2026 12:45:55 UTC pou=C5=BE=C3=ADvate=C4=BE Kerin M=
illar <kfm@plushkava=2Enet> nap=C3=ADsal:

>If the problem can be characterised as "I endure too much log noise from =
sshd and I find it annoying" then perhaps configure sshd(8) to additionally=
 bind to some other random port than 22 and expose only that port=2E

Not worth of change ports, soon or latter it will be found
and abused as default port=2E

Fail2ban or so, can block addresses selectively=2E BTW, here after
long time (1-2 years) of banning the counts drops from hundreds/thousands
addresses daily to tens daily=2E Currently, i have banned 30 addresses
with bantime up to 90 days, from that the ~20 is today "spike"=2E

regards


--=20
Slavko
https://www=2Eslavino=2Esk/