Limit ciphers&macs, then set password authentication to no, and the hits go down a bunch.
On Mon, Feb 2, 2026, 10:12 AM Jonathan Hutchins hutchins@tarcanfel.org wrote:
I posted the latest logwatch report to the list. I believe those pam login failures are sshd connection attempts. Currently we're running SSHD on port 222. That redirection is so well known now that we might as well run it on 22. I would suggest that we chose a more random, arbitrary port and see if that cuts back on the hits.
-- Jonathan _______________________________________________ KCLUG mailing list -- kclug@kclug.org To unsubscribe send an email to kclug-leave@kclug.org https://kclug.org/mailman3/postorius/lists/kclug.kclug.org/