• GreenKnight23@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    12 days ago

    fail2ban will always get you better results than banning countries because VPNs are a thing.

    that said, I automatically ban any IP that comes from outside the US because there’s literally no reason for anyone outside the US to make requests to my infra. I still use smart IP filtering though.

    also, use a WAF on a NAT to expose your apps.