Any Linux server with SSH open to the internet is probed for passwords within minutes. Protection has two layers: settings that make guessing pointless, and automatic blocking of the IPs that keep trying. This guide covers both, and what to do when you have more than one server.
Harden sshd first
Edit /etc/ssh/sshd_config (or a file in /etc/ssh/sshd_config.d/):
PasswordAuthentication no
PermitRootLogin prohibit-password
PubkeyAuthentication yes
MaxAuthTries 3
LoginGraceTime 30
Before you reload, make sure your key login works in a second session, then run sshd -t && systemctl reload ssh (the service is called sshd on RHEL-family systems). With password login off, guessing cannot succeed, but bots still fill the logs and use CPU, so blocking is still worth it.
- Limit by source. If you connect from fixed addresses, allow only those in the firewall.
- Moving the port cuts noise but is not protection.
Where the attempts show up
Failed logons are written as Failed password for ... from <IP> or Invalid user ... from <IP> in /var/log/auth.log (Debian, Ubuntu) or /var/log/secure (RHEL family), and in the journal:
journalctl -u ssh --since "1 hour ago" | grep -E "Failed password|Invalid user"
Block repeat offenders with fail2ban
Install fail2ban and enable the sshd jail in /etc/fail2ban/jail.local:
[sshd]
enabled = true
maxretry = 3
findtime = 10m
bantime = 1d
ignoreip = 127.0.0.1/8 203.0.113.10
Apply with systemctl restart fail2ban and check with fail2ban-client status sshd. Put your office and VPN addresses into ignoreip so you don't lock yourself out. To lengthen bans for repeat offenders, fail2ban has the recidive jail.
The limit: every server on its own
fail2ban protects only the machine it runs on. A botnet that was banned on server A starts over on server B. The usual fixes are described in fail2ban on multiple servers.
Sharing bans across all servers with KIPBan
KIPBan installs on top of fail2ban and hooks into every enabled jail, including sshd. Your maxretry and findtime stay yours; what changes is that each caught IP goes into a shared list and every other server, Linux or Windows, blocks it within 5 minutes. Bans escalate from 3 days to 30 days to permanent, and you get a dashboard and Telegram alerts. The first two servers are free. If you also run Windows machines, see RDP brute-force protection.
Questions about SSH protection
Is changing the SSH port enough?
No. It reduces noise from mass scanners, but a port scan finds the new port quickly. Use keys and IP blocking as well.
How do I check which IPs fail2ban banned?
Run fail2ban-client status sshd. To unban an address, use fail2ban-client set sshd unbanip <IP>.
Will I lock myself out?
Add your fixed addresses to ignoreip in fail2ban. With KIPBan, put them in the dashboard whitelist, which is never blocked.