Re: Question on rate limiting on nftables
Slavko <[email protected]> Mon, 08 Jun 2026 16:56:42 +0000
| Newsgroups | gmane.comp.security.firewalls.netfilter.general |
|---|---|
| Message-ID | <[email protected]> |
D=C5=88a 8=2E j=C3=BAna 2026 15:01:37 UTC pou=C5=BE=C3=ADvate=C4=BE Andre R= odier <andre@rodier=2Eme> nap=C3=ADsal: >There is a big advantage on changing the port number, though=2E It is >reducing the noise considerably=2E Also, a connection attempts on a >different port should immediately raise attention, as it is involving >more than a basic SSH scan bot=2E I used high port for ~10 years=2E Yes for first year or two the noise dropped significantly=2E That is from server where SSH access have only i and password auth is disabled anyway, thus i didn't watch it then in detail for multiple years as it was just noise=2E About 5 years ago i did some closer inspection and i collected some stats, and i found, that in average there was attempts from ~1k unique IPs daily, with spikes over 2k daily, i decided what i stated -- not worth to setup non-default port on clients=2E Thus again, changing port is only short term solution=2E My scanners catching stats (on some sort of honeypot) shows ~8k unique ports scanned in last 90 days, and that are only most obvious scans blocked after first acces, without well known scanners (shodan and familly), which are catched by other way before=2E=2E=2E Try to guess how long it will take novadays to discover, that your SSH listens on different port and how long it will take to appear/share/sold that info on some dark forums? regards --=20 Slavko https://www=2Eslavino=2Esk/