From owner-freebsd-questions@FreeBSD.ORG Tue Jan 11 05:40:56 2005 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 5042516A4CE for ; Tue, 11 Jan 2005 05:40:56 +0000 (GMT) Received: from fusion.vilot.net (vilot.com [64.246.32.88]) by mx1.FreeBSD.org (Postfix) with ESMTP id F08A843D55 for ; Tue, 11 Jan 2005 05:40:55 +0000 (GMT) (envelope-from tom@vilot.com) Received: from [192.168.1.105] (c-24-8-184-241.client.comcast.net [24.8.184.241]) (authenticated bits=0) by fusion.vilot.net (8.13.1/8.12.9) with ESMTP id j0B5beCA058158; Mon, 10 Jan 2005 23:37:41 -0600 (CST) (envelope-from tom@vilot.com) Message-ID: <41E366E0.5070504@vilot.com> Date: Mon, 10 Jan 2005 22:40:48 -0700 From: Tom Vilot User-Agent: Mozilla Thunderbird 1.0 (X11/20041222) X-Accept-Language: en-us, en MIME-Version: 1.0 To: murraytaylor@bytecraftsystems.com References: <002101c4f79e$f3233200$c82aa8c0@LTTAYLORMNEW> In-Reply-To: <002101c4f79e$f3233200$c82aa8c0@LTTAYLORMNEW> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit cc: 'Gene' cc: "'freebsd-questions@FreeBSD. ORG'" Subject: Re: High levels of breakin attempts X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 11 Jan 2005 05:40:56 -0000 Murray Taylor wrote: >I havent checked forsure but could sysutils/ipa help. > >it can 'open/close' firewalls upon certain limit conditions... > > The closest thing I have seen is portsentry. However, portsentry is a different beast. I don't think it "knows" about attempts to log in via ssh. In other words ... I don't think portsentry can say "Hey!! Wait a sec. There are no users such as those. In fact, this server doesn't allow logins from ANYONE except X Y and Z via ssh keys .... Okay, time to block this bonehead ....."