More SSH 'trolling'

Vladimir G. Ivanovic vladimir at
Fri Oct 15 23:17:27 UTC 2004

>>>>> "bp" == Björn Persson <listor1.rombobeorn at> writes:

    bp> As written, every incoming packet would be compared to those rules. You
    bp> couls however create a new chain, "blocked" say, and configure the log
    bp> watcher to add the rules to that chain. In the main "INPUT" chain you
    bp> would then have a rule to jump to the chain "blocked" only on connection
    bp> attempts to port 22.

I see. Could someone more iptables-knowledgeable than I post some rules
that accomplish what Björn has suggested?

--- Vladimir

