Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Does OpenSSHd have a blacklist for IPs?

Status
Not open for further replies.

thedaver

IS-IT--Management
Jul 12, 2001
2,741
US
Does OpenSSHd have a blacklist/denylist for IPs as a native function? I know I can screw around with hooking up port 22 to DJB's tcpserver and block IPs before they get a session, but I gotta believe that SSHd has it natively.

I see a lot of IPs are trying to guess user IDs at SSHd. I'd just assume banish those IPs to a blacklist and reject them before they can continue.

Thoughts?

D.E.R. Management - IT Project Management Consulting
 
Block them at your firewall?



BocaBurger
<===========================||////////////////|0
The pen is mightier than the sword, but the sword hurts more!
 
I'm in a position to block by application/port on the server.

I've found that /etc/hosts.deny is a possibility.

D.E.R. Management - IT Project Management Consulting
 
Have you tried using the "DenyUsers *@1.2.3.4" option in sshd_config. I'm not 100% sure the "*" is supported (it doesn't say on the sshd_config man page), but you could experiment with that.

Annihilannic.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top