Re: Question on rate limiting on nftables

Reindl Harald <[email protected]> Mon, 8 Jun 2026 18:05:48 +0200
Newsgroups gmane.comp.security.firewalls.netfilter.general
Organization the lounge interactive design
Message-ID <[email protected]>

Am 08.06.26 um 17:01 schrieb Andre Rodier:
> On Mon, 2026-06-08 at 14:32 +0000, Slavko wrote:
>> Dňa 8. júna 2026 12:45:55 UTC používateľ Kerin Millar
>> <[email protected]> napísal:
>>
>>> If the problem can be characterised as "I endure too much log noise
>>> from sshd and I find it annoying" then perhaps configure sshd(8) to
>>> additionally bind to some other random port than 22 and expose only
>>> that port.
>>
>> Not worth of change ports, soon or latter it will be found
>> and abused as default port.
> 
> There is a big advantage on changing the port number, though. It is
> reducing the noise considerably. Also, a connection attempts on a
> different port should immediately raise attention, as it is involving
> more than a basic SSH scan bot

and in fact you can have a few ports before as trigger to put the IP on 
a drop-list for a few minutes which isn't possible when you host ftp servers