Comment by lillecarl
7 months ago
Manual banning is about the same since you just book /56 or bigger, entire providers or countries.
Automated banning is harder, you'd probably want a heuristic system and look up info on IPs.
IPv4 with NAT means you can "overban" too.
Why wouldn't something like fail2ban not work here? That's what it's built for and has been around for eons.
Fun part was that fail2ban had RCE vulnerability. So you were more secure not running it now it should be fixed but can you be sure?
You don't always firewall 80/443 in Linux :(