I have fail2ban installed on my Ubuntu droplet and it is working great. I have noticed that I receive notifications upwards of 100 banned IP’s each day. I guess it is a brute force attack that is changing the ip of the attacker. Is there something else I could be doing to stop these attacks? Most of the attacks look like they are targeting sasl and ftp.
This textbox defaults to using Markdown to format your answer.
You can type !ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!
This comment has been deleted
In an effort to decrease the likelihood of a successful brute force crack attempt, I have severely increased the ban times for repeated attempts. I ban the attacking IP for a year after the second time it trips a ban.
There isn’t a lot more you can do except to change the ports you’re using to something other than the standard port numbers.
The number of crack attempts used to bother me until I noticed that most of them attempting to gain access via “standard” user names, none of which I use, and I disabled root access. As long as you have a strong password or use public key access, you shouldn’t have much to worry about. The only other thing then was the number of ban notification emails I was getting. I now just automatically file those for reference, so I don’t see them unless I want to, and I really don’t think about them much anymore.
Get paid to write technical tutorials and select a tech-focused charity to receive a matching donation.
Full documentation for every DigitalOcean product.
The Wave has everything you need to know about building a business, from raising funding to marketing your product.
Stay up to date by signing up for DigitalOcean’s Infrastructure as a Newsletter.
New accounts only. By submitting your email you agree to our Privacy Policy
Scale up as you grow — whether you're running one virtual machine or ten thousand.
Sign up and get $200 in credit for your first 60 days with DigitalOcean.*
*This promotional offer applies to new accounts only.