Hacker News new | ask | show | jobs
by BrandoElFollito 989 days ago
Absolutely agree. Fail2ban, sooner or later, bans you from your services becasue something in the configuration went wrong.

It does not protect against anything serious: you must have proper credentials/MFA or certificates and therefore bots can check as much as they want.

There is no protection against DoS either.

And I agree about moving the port - I only see a tiny activity in my logs coming from bots when my ssh port moved away. Obviously 443 is there to stay (this is a public service) so I will get whatever comes.