From: Kevin Z. <kev...@gm...> - 2021-11-18 23:59:00
|
Hi Greg, On 11/18/21 3:02 PM, Greg Bell via sshguard-users wrote: > My iptables setup broke somehow - the INPUT table wasn't linked to the > sshguard table, so blocking wasn't actually happening. > > I only discovered it after seeing a few thousand attempts to > authenticate as 'root' from the same IP, in logwatch's daily email. > > Can/should sshguard check for this situation? I'm not very familiar with iptables. How does this happen (that the table gets unlinked), and is there a command that sshguard can run to double check the iptables setup? Thanks, Kevin |