"fail2ban protects you from brute force"
It logs and bans — after the attempt hits sshd. With a 3-retry / 10-min ban, a botnet rotating 5000 IPs still gets 15k guesses/hour through. fail2ban barely dents that.
Real fix: kill password auth entirely.
— PasswordAuthentication no
— PubkeyAuthentication yes
— move port off 22 to cut log noise
Now the bans are cosmetic and you sleep. fail2ban is a seatbelt, not a lock.
Try it tonight.
Root Access Daily
@RootAccessDaily
"fail2ban protects you from brute force"
Этот пост опубликован в Telegram-канале Root Access Daily. Подписаться можно по ссылке: @RootAccessDaily.