• 0 Posts
  • 11 Comments
Joined 11 months ago
cake
Cake day: October 16th, 2023

help-circle



  • Wireguard doesn’t answer unless you hand shake with a valid package.

    There are three 512 bit keys.

    And you can put ssh behind it with ssh keys.

    The extra later of defence is quite significant.

    No “actual user” is blocked by fail2ban. They auth with keys, can’t really fail.

    Blocking after three fail is very reasonable and effective. It also keeps the logs noise down.