Not sure why but the idea of port knocking always seems over complex for little benefit.
Not sure why but the idea of port knocking always seems over complex for little benefit.
But if I'm being honest, back when I signed up with them keypairs would have been a little more difficult than working out that option for rsync.
At worst, the internet will just keep filling your logs with access attempts, none of which will actually accomplish anything.
I did recently decide to start using fail2ban though, not because I'm worried about someone hacking ssh, but because I wanted a centralized system that would monitor various forms of abuse (including obvious spammers).
It requires a little bit of kludging to do this though. :-( As packaged, it's not much more useful than a hacky shell script.
Do not allow password logins. Do. Not.
Have a method to redact keys quickly. The advice of the article becomes irrelevant. If someone gets hold of an unencrypted/crackable private key, they'll likely also have access to the secret portnumber, knock sequence and username, so nothing much gained there.
Consider the Debian PRNG flaw from a couple years ago. As I understand it, most SSH/SSL keys generated on Debian and Debian-derived boxes over a period of about two years were (rather) easily guessable. Even if you were able to redact any compromised keys as soon as this was publicly revealed, who knows how long malicious attackers may have known about it before it was made public. If your server had port knocking enabled you would have had a bit of insulation from this attack.
http://www.fail2ban.org/wiki/index.php/Main_Page
http://denyhosts.sourceforge.net/
denyhosts has the difference that it synchronises this data amongst many hosts.