Re: Question on rate limiting on nftables

Slavko <[email protected]> Mon, 08 Jun 2026 16:56:42 +0000
Newsgroups gmane.comp.security.firewalls.netfilter.general
Message-ID <[email protected]>
D=C5=88a 8=2E j=C3=BAna 2026 15:01:37 UTC pou=C5=BE=C3=ADvate=C4=BE Andre R=
odier <andre@rodier=2Eme> nap=C3=ADsal:

>There is a big advantage on changing the port number, though=2E It is
>reducing the noise considerably=2E Also, a connection attempts on a
>different port should immediately raise attention, as it is involving
>more than a basic SSH scan bot=2E

I used high port for ~10 years=2E Yes for first year or two
the noise dropped significantly=2E That is from server where
SSH access have only i and password auth is disabled anyway,
thus i didn't watch it then in detail for multiple years as
it was just noise=2E About 5 years ago i did some closer
inspection and i collected some stats, and i found, that
in average there was attempts from ~1k unique IPs daily,
with spikes over 2k daily, i decided what i stated -- not
worth to setup non-default port on clients=2E

Thus again, changing port is only short term solution=2E My
scanners catching stats (on some sort of honeypot) shows
~8k unique ports scanned in last 90 days, and that are only
most obvious scans blocked after first acces, without well
known scanners (shodan and familly), which are catched by
other way before=2E=2E=2E

Try to guess how long it will take novadays to discover,
that your SSH listens on different port and how long it
will take to appear/share/sold that info on some dark
forums?

regards


--=20
Slavko
https://www=2Eslavino=2Esk/