SSH rules

Last Updated : Jul 28, 2021 |
Prolog information
  • Any IP address sending, on port 22 or 222, packets with the SYN flag, but without RST or ACK is added to the sshsyn list.
  • For any IP address in the sshsyn list that sends, on port 22 or 222:
    Fifteen packets with the SYN flag, but without RST or ACK in 1 minute during the TTL of the previous packet sent, drop the packet.
    Ten packets with the SYN flag, but without RST or ACK in 30 seconds during the TTL of the previous packet sent, reject the packet. An ICMP port unreachable message is sent for the packet.