Just curious. Have you enabled password logins on your servers, or do they only allow RSA key-based logins?
The hackers fail according to sshd but logwatch lists a list of chinese and russian attempts.
I was hoping my firewall would block them. I tried entering a block of ips but some of the same ones are connecting.
I don't know what this means:
Illegal users from: undef: 20 times 183.60.177.246: 7 times 217.14.134.68: 7 times 219.149.30.170: 6 times