Using a tool like fail2ban is also favourable. Most of the bots will give up and look for other targets even if you ban them for a hour.
I have always been surprised that fail2ban is so popular, since iptables can do rate limiting, etc. So, it's easy to block most attacks with the in-kernel firewall:
Since clearly you are confused what it actually does.
But you probably thought that I was suggesting to block IPs by hand. I wasn't.
ssh -l "root@ 1.2.4.5" ssh.example.com
Allowing you to lockout the specified IP."I work for Linode, but everything I say is me being an idiot." so..