• Ajen@sh.itjust.works
    link
    fedilink
    arrow-up
    3
    ·
    2 months ago

    The thing about fail2ban is that it’s only affective against automated scans and script kiddies, and if you keep things updated and configured correctly then they aren’t a threat. Any adversary that can break encryption or exploit a zero day can also get around fail2ban.

    • adminofoz@lemmy.cafe
      link
      fedilink
      arrow-up
      1
      ·
      2 months ago

      Fr tho why does no one do port knocking? I know its not a comprehensive solution but it’s a pretty cool component imo.