Can you switch over to public/private key based authentication and disable keyboard interactive logins on the server? Thats what I did, so let em bang on the door all day long. Unless they have a key file AND the password they wont ever get in.
Sure you still get stuff in your logs but dynamic filtering is a tricky thing, be it at the firewall side or the SSH server side
|