Hello,
I created a droplet 2 months ago and I did the basic things like configuring the firewall, setup ssh to only accept public key auth and stuff. Last night I was inspecting the logs located at /var/log/auth.log and /var/log/ufw.log and I noticed that there are a lot of IPs trying to access telnet, ssh (using brute force with random login names) and there are also some attempt to connect to some random TCP ports.
Should I be worried? Is this “normal” ?
Btw: My firewall is configure to drop all incoming packets (except ssh).
Thank you
These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.
You can improve and reduce the attack attempts by:
This is to be expected. Disabling password based authentication in sshd_config makes this a non issue.
This comment has been deleted