Add new comment
Do you like HowtoForge? Please consider supporting us by becoming a subscriber.
|
Remember that automated tools like Fail2Ban and PortSentry leave you open to denial of service attacks. If someone were spoof the address of an SSH client you regularly connect from, you could be locked out of your server. While it's not easy to spoof enough of an SSH connection to trigger Fail2Ban, it is possible. Another senario is where you SSH to your home server from behind a corporate NAT router. Anyone else on you your corporate network could lock you out by simply trying to log in a few times. I'm not trying to talk anyone out of using Fail2Ban (I use it!), but I think it's important to know the implications of doing so. Rich B.
Reply |





Recent comments
19 hours 48 min ago
1 day 2 hours ago
1 day 5 hours ago
1 day 7 hours ago
1 day 10 hours ago
1 day 10 hours ago
1 day 20 hours ago
2 days 1 hour ago
2 days 1 hour ago
2 days 3 hours ago