Re: Question on rate limiting on nftables

"Kerin Millar" <[email protected]> Mon, 08 Jun 2026 18:24:14 +0100
Newsgroups gmane.comp.security.firewalls.netfilter.general
Message-ID <[email protected]>
On Mon, 8 Jun 2026, at 5:56 PM, Slavko wrote:
> D=C5=88a 8. j=C3=BAna 2026 15:01:37 UTC pou=C5=BE=C3=ADvate=C4=BE Andr=
e Rodier <[email protected]> nap=C3=ADsal:
>
>>There is a big advantage on changing the port number, though. It is
>>reducing the noise considerably. Also, a connection attempts on a
>>different port should immediately raise attention, as it is involving
>>more than a basic SSH scan bot.
>
> I used high port for ~10 years. Yes for first year or two
> the noise dropped significantly. That is from server where
> SSH access have only i and password auth is disabled anyway,
> thus i didn't watch it then in detail for multiple years as
> it was just noise. About 5 years ago i did some closer
> inspection and i collected some stats, and i found, that
> in average there was attempts from ~1k unique IPs daily,
> with spikes over 2k daily, i decided what i stated -- not
> worth to setup non-default port on clients.
>
> Thus again, changing port is only short term solution. My
> scanners catching stats (on some sort of honeypot) shows
> ~8k unique ports scanned in last 90 days, and that are only
> most obvious scans blocked after first acces, without well
> known scanners (shodan and familly), which are catched by
> other way before...
>
> Try to guess how long it will take novadays to discover,
> that your SSH listens on different port and how long it
> will take to appear/share/sold that info on some dark
> forums?

Allow me to put it as forthrightly as I can: I do not care in the least =
where such information appears. I will continue to select a non-standard=
 port for as long as it demonstrably improves the signal-to-noise ratio =
of my logs. And I will gladly change the port again, should I wish to. A=
lthough, my recently introduced anti-scanning measures should diminish t=
he likelihood of that happening any time soon.

--=20
Kerin Millar