Greetings folks, thanks for taking the time to read this...
I have a number of gentoo boxes with only the sshd daemon exposed to the Internet. Now, we all know how people love to run scripts and hammer SSHD... a while ago I saw a PAM plug-in that would essentially blacklist an IP address on some configurable parameters (>3 attempts failed in 10 seconds, etc)...
What strategies do you use to protect SSHd? (Please keep in mind I log into these boxes from virtually anywhere, so IP masking them through my firewall isn't really an option... some good tricks? PAM options?
Thank you for your time.



