In the 5+ years I have been using this method, I have had very few
legitimate users that get blocked with this method.

I feel if someone/bot is attempting to log into my server on ssh that they
are up to no good (it's not a service we offer to our customers) and
therefore I have no issues at all with blocking the ip address permanently
on all ports.

On 10/1/07, Tomas L. Byrnes <tomb at byrneit.net> wrote:
> How do you handle the "scorched earth" problem? Many attacking IPs are
> dynamic.
> > I use an iptables script setup that will add the ip address
> > of someone attempting to log into my servers with an invalid
> > name or any of the common services. The block list I have now
> > has grown pretty large from all the scans, but once in the
> > blocked list they get cut off from all services.
