I created a droplet 2 months ago and I did the basic things like configuring the firewall, setup ssh to only accept public key auth and stuff. Last night I was inspecting the logs located at /var/log/auth.log and /var/log/ufw.log and I noticed that there are a lot of IPs trying to access telnet, ssh (using brute force with random login names) and there are also some attempt to connect to some random TCP ports.
Should I be worried? Is this “normal” ?
Btw: My firewall is configure to drop all incoming packets (except ssh).
These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.