Re: Question on rate limiting on nftables

"Kerin Millar" <[email protected]> Mon, 08 Jun 2026 16:25:35 +0100
Newsgroups gmane.comp.security.firewalls.netfilter.general
Message-ID <[email protected]>
On Mon, 8 Jun 2026, at 3:32 PM, Slavko wrote:
> D=C5=88a 8. j=C3=BAna 2026 12:45:55 UTC pou=C5=BE=C3=ADvate=C4=BE Keri=
n Millar=20
> <[email protected]> nap=C3=ADsal:
>
>>If the problem can be characterised as "I endure too much log noise fr=
om sshd and I find it annoying" then perhaps configure sshd(8) to additi=
onally bind to some other random port than 22 and expose only that port.
>
> Not worth of change ports, soon or latter it will be found
> and abused as default port.

In my experience, choosing a random high port has a demonstrable effect =
on reducing sshd(8) log noise. I make no claim that it eliminates log no=
ise outright, nor that it places the service beyond the purview of bots =
at large.

>
> Fail2ban or so, can block addresses selectively. BTW, here after
> long time (1-2 years) of banning the counts drops from hundreds/thousa=
nds
> addresses daily to tens daily. Currently, i have banned 30 addresses
> with bantime up to 90 days, from that the ~20 is today "spike".

I understand that you probably have different requirements to the OP. St=
ill, no userspace tool is needed if the only criteria by which a ban is =
to be exacted is that of exceeding a TCP connect rate limit. Netfilter, =
itself, is best positioned to manage that.

--
Kerin Millar