SSHGuard monitors services through their logging activity. It reacts to messages about dangerous activity by blocking the source address with the local firewall.
sshguard monitors services through their logging activity. it reacts to messages about dangerous activity by blocking the source address with the local firewall. sshguard employs a clever parser that can transparently recognize several logging formats at once (syslog, syslogng, metalog, multilog, raw messages), and detects attacks for many services out of the box, including ssh, several ftpds, and dovecot. it can operate all the major firewalling systems, and features support for ipv6, whitelisting, suspension, and log message authentication.
ssh firewall intrusion-detection freebsd web-log-analyzer bruteforce