From: Jos C. <ssh...@cl...> - 2016-09-05 12:16:26
|
Dear team, Just to request a slightly different line on blocking earlier blocked IP addresses: Sep 5 13:23:56 ares kernel: Sep 5 13:23:56 ares sshguard[771]: blacklist: added 116.209.118.176 Sep 5 13:23:56 ares sshguard[771]: 116.209.118.176: blocking forever (3 attacks in 7 secs, after 1 abuses over 7 secs) Sep 5 13:23:56 ares kernel: Sep 5 13:23:56 ares sshguard[771]: 116.209.118.176: blocking forever (3 attacks in 7 secs, after 1 abuses over 7 secs) After blocking this ip you add this line: Sep 5 13:23:56 ares sshguard[771]: 116.209.118.176: should already have been blocked Sep 5 13:23:56 ares kernel: Sep 5 13:23:56 ares sshguard[771]: 116.209.118.176: should already have been blocked This is confusingas it reads that SSHGuard doesn't know whether it has been blocked or not ("should have been blocked" - human line interpretation). Better(and more demanding) would be: Sep 5 13:23:56 ares sshguard[771]: 116.209.118.176: has already been blocked (forever) Just thinking with your, Jos Chrispijn |