Re: Question on rate limiting on nftables
Gordon Fisher <[email protected]> Fri, 26 Jun 2026 10:04:02 -0700
| Newsgroups | gmane.comp.security.firewalls.netfilter.general |
|---|---|
| Message-ID | <[email protected]> |
On 6/8/26 9:05 AM, Reindl Harald wrote: > > > Am 08.06.26 um 17:01 schrieb Andre Rodier: >> On Mon, 2026-06-08 at 14:32 +0000, Slavko wrote: >>> Dňa 8. júna 2026 12:45:55 UTC používateľ Kerin Millar >>> <[email protected]> napísal: >>> >>>> If the problem can be characterised as "I endure too much log noise >>>> from sshd and I find it annoying" then perhaps configure sshd(8) to >>>> additionally bind to some other random port than 22 and expose only >>>> that port. >>> >>> Not worth of change ports, soon or latter it will be found >>> and abused as default port. >> >> There is a big advantage on changing the port number, though. It is >> reducing the noise considerably. Also, a connection attempts on a >> different port should immediately raise attention, as it is involving >> more than a basic SSH scan bot > > and in fact you can have a few ports before as trigger to put the IP > on a drop-list for a few minutes which isn't possible when you host > ftp servers > Which raises the question, why are people still using ye olde FTP still instead of, say, SFTP? -- gfish