| ▲ | justsomehnguy 14 hours ago | |
> if you're using key-only authentication (which: of course you are) fail2ban has literally no function (unless you think attackers are brute-forcing ECDH keys). Why, fail2ban here still serve a very useful function: it bans the offending IP from talking to the machine. It's a simple and a very effective heuristic to block both non-offending port-scans and offending too. > basically two ways It's always amusing what people like you almost demand what ssh should be run on the port 22 but are fine with a random port for WireGuard. And for all of you to assume what both 22/tcp and WireGuard are always available and never blocked. | ||