Re: Question on rate limiting on nftables

Andre Rodier <[email protected]> Mon, 08 Jun 2026 16:01:37 +0100
Newsgroups gmane.comp.security.firewalls.netfilter.general
Message-ID <[email protected]>
On Mon, 2026-06-08 at 14:32 +0000, Slavko wrote:
> D=C5=88a 8. j=C3=BAna 2026 12:45:55 UTC pou=C5=BE=C3=ADvate=C4=BE Kerin M=
illar
> <[email protected]> nap=C3=ADsal:
>=20
> > If the problem can be characterised as "I endure too much log noise
> > from sshd and I find it annoying" then perhaps configure sshd(8) to
> > additionally bind to some other random port than 22 and expose only
> > that port.
>=20
> Not worth of change ports, soon or latter it will be found
> and abused as default port.

There is a big advantage on changing the port number, though. It is
reducing the noise considerably. Also, a connection attempts on a
different port should immediately raise attention, as it is involving
more than a basic SSH scan bot.

> Fail2ban or so, can block addresses selectively. BTW, here after
> long time (1-2 years) of banning the counts drops from
> hundreds/thousands
> addresses daily to tens daily. Currently, i have banned 30 addresses
> with bantime up to 90 days, from that the ~20 is today "spike".
>=20
> regards

--=20
=F0=9F=8C=90 https://rodier.me/