Getting Started with Fail2Ban on Linux
ittavern.com
ittavern.com
(fail)(2)(ban)
A solution is to use ipset and have fail2ban adding/removing up with ipset. I intend to write a blog about it, and other things about running your own server, as soon as I get some free time.
For example, shorewall/shorewall6 has rule set optimization for blrules (be warned single threaded Perl can take awhile for 300k IPs, and quick-boot rule-caching should be off during initial configuration).
I also use a crude ban-list generator script for certain persistently annoying country codes poking around, that currently imports a lot of iblocklist, spamhaus, known compromised IP posts on dodgy forums, and malformed whois records.
Yes it is rude to black-hole entire countries, but these same areas often tend to ruin the games with lagged connections and lame vulnerability/exfiltration scans.
The question you have to ask is: "are you better off not knowing?"
Minimizing attack surfaces often means role specific servers, and some sort of proprietary virtualization/sandbox. There are some good arguments to rotate and burn mail server instances every 3 months like clockwork, and expire your keys. i.e. makes sure permission rot, deleted user files, and failed binary sums are auto-deleted or captured in a peer forensic log.
Now the failed logins on ssh is down to 1-2 per day instead of hundreds.
I like denyhosts, because of the sharing blacklist feature. I'd rather not give the attackers a chance to guess the password when they've already hit 10 other hosts and it's a pattern.
Unfortunately denyhosts hasn't been updated in a while.