Incessant tinkerer since the 70’s. Staunch privacy advocate. SelfHoster. Musician of mediocre talent. https://soundcloud.com/hood-poet-608190196

  • 26 Posts
  • 909 Comments
Joined 11 months ago
cake
Cake day: March 24th, 2025

help-circle
  • Am I missing anything here or is this how I’m supposed to be doing it?

    AFA fail2ban, I always set up the jails in aggressive mode:

    [sshd]
    mode = aggressive
    enabled = true
    port = ssh
    filter = sshd
    logpath = /var/log/auth.log
    maxretry = 5 <---edit to tastes
    bantime = 3600 <---edit to tastes
    findtime = 600 <---edit to tastes
    

    You might want to check out Crowdsec, maybe deploy Tailscale as an overlay. How many users are you providing services for? If just yourself, I use the host allow / host deny feature in Linux. Just make sure you do host allow first, lol.