logoalt Hacker News

justsomehnguytoday at 8:25 AM0 repliesview on HN

> if you're using key-only authentication (which: of course you are) fail2ban has literally no function (unless you think attackers are brute-forcing ECDH keys).

Why, fail2ban here still serve a very useful function: it bans the offending IP from talking to the machine. It's a simple and a very effective heuristic to block both non-offending port-scans and offending too.

> basically two ways

It's always amusing what people like you almost demand what ssh should be run on the port 22 but are fine with a random port for WireGuard.

And for all of you to assume what both 22/tcp and WireGuard are always available and never blocked.