You can set an alert for every failed SSH connection because if someone is able to get through that, it's alarming.
This setup has the side effect of reducing your log noise to zero. That SNR is super important for intrusion detection.
You can set an alert for every failed SSH connection because if someone is able to get through that, it's alarming.
This setup has the side effect of reducing your log noise to zero. That SNR is super important for intrusion detection.
I also have alerts for both failed SSH or failed wireguard connections, and for any logins from a new IP with either SSH or wireguard.
https://wiki.nftables.org/wiki-nftables/index.php/Port_knock...
That script gets compiled into BPF and uploaded into the kernel once, at boot/ifup time. All the memory is preallocated.
Userspace can be dead/hung/OOM and you can be sure that at least the port knocking won't be why you got locked out.
I did look up OpenBSD pf again, and it too does port knocking in the kernel. My information was dated (left the misc mailing list at least 5 years ago).