Hi everybody I like to know if there is a way to block incoming connections attemps to port TCP 22. I have an end-customer which has lots of connections to his public ip range 0.0.0.0/24 to port TCP22 but not hit the vulnerability 40015 (SSH User Authentication Brute-force Attempt) because it neves triggers the child signature 31914 (SSH2 Login Attempt) because there no attempt to connect, it just an scanning. I'm loooking at DoS Protection, which may works, but I'm not sure what to do in Option/Protection tab. I think I need to configure at Classified option a DoSProteccion Profile, but I'm lost, I donp't know it is better user FloodProtections or Resources Protection. Do anybody has resolved this issue?
... View more