From owner-freebsd-pf@FreeBSD.ORG Wed Feb 9 09:13:03 2011 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 975B41065672 for ; Wed, 9 Feb 2011 09:13:03 +0000 (UTC) (envelope-from ml@my.gd) Received: from mail-fx0-f54.google.com (mail-fx0-f54.google.com [209.85.161.54]) by mx1.freebsd.org (Postfix) with ESMTP id 32E3E8FC12 for ; Wed, 9 Feb 2011 09:13:00 +0000 (UTC) Received: by fxm16 with SMTP id 16so7408599fxm.13 for ; Wed, 09 Feb 2011 01:12:59 -0800 (PST) Received: by 10.223.98.197 with SMTP id r5mr5844905fan.68.1297242779577; Wed, 09 Feb 2011 01:12:59 -0800 (PST) Received: from [10.139.5.94] ([92.90.16.21]) by mx.google.com with ESMTPS id 21sm31994fav.41.2011.02.09.01.12.55 (version=TLSv1/SSLv3 cipher=RC4-MD5); Wed, 09 Feb 2011 01:12:58 -0800 (PST) References: <5A0B04327C334DA18745BFDBDBECE055@charlieroot.de> In-Reply-To: <5A0B04327C334DA18745BFDBDBECE055@charlieroot.de> Mime-Version: 1.0 (iPhone Mail 8A293) Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=us-ascii Message-Id: <0F70CC90-40EC-4501-9B7D-6E13D38CC231@my.gd> X-Mailer: iPhone Mail (8A293) From: Damien Fleuriot Date: Wed, 9 Feb 2011 10:12:38 +0100 To: Helmut Schneider Cc: "" Subject: Re: brutal SSH attacks X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 09 Feb 2011 09:13:03 -0000 I didn't see anything the author posted to indicate that his abusive hosts t= able was being populated. @OP: install sshguard from the ports --- Fleuriot Damien On 8 Feb 2011, at 23:26, "Helmut Schneider" wrote: >> Could somebody help in figuring out why PF configuration meant to prevent= brutal SSH attacks doesn't work. >=20 > Check your pflog. The ruleset itself seems fine (if it is complete and you= did not forget to post a vital part). We also can assume that pf is enabled= , can we?=20 > _______________________________________________ > freebsd-pf@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-pf > To unsubscribe, send any mail to "freebsd-pf-unsubscribe@freebsd.org"