

Rookie numbers.
My favourite f2b rule is the one strike ban on SSH root login attempts. Any IP originating a SSH root login attempt is clearly compromised, and gets black holed on all my hosts for a month.
Note: direct SSH login isn’t permitted at all, the daemon is exposed purely to log the attempts.











The actual span is a random period between 2 and 4 weeks, it’s interesting to watch how long it takes for attempts to resume.
I prefer a more granular visibility, repeat offenders automagically ratchet up their stay in the sin bin.