Hey,
I've found out that my brute-force prevention isn't working anymore
it sort of blocks now and then when I try portscanning with an online port scanner (http://www.t1shopper.com/tools/port-scan/)
but after 2 blocks or so the ssh becomes visible again.
Code:
Apr 2 23:25:39 kernel: SSH ACCEPT IN=vlan2 OUT= MAC=00:26:18:a1:3c:fb:00:60:4c:e3:66:3c:08:00:45:00:00:3c SRC=208.64.252.230 DST=192.168.1.11 LEN=60 TOS=0x00 PREC=0x00 TTL=46 ID=65460 DF PROTO=TCP SPT=45575 DPT=22 SEQ=3832370418 ACK=0 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405B40402080ABCE9AB460000000001030307)
Apr 2 23:25:39 /opt/sbin/sshd[819]: Did not receive identification string from 208.64.252.230
Apr 2 23:25:55 kernel: SSH ACCEPT IN=vlan2 OUT= MAC=00:26:18:a1:3c:fb:00:60:4c:e3:66:3c:08:00:45:00:00:3c SRC=208.64.252.230 DST=192.168.1.11 LEN=60 TOS=0x00 PREC=0x00 TTL=46 ID=25408 DF PROTO=TCP SPT=45624 DPT=22 SEQ=3845884720 ACK=0 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405B40402080ABCE9E8700000000001030307)
Apr 2 23:25:55 /opt/sbin/sshd[820]: Did not receive identification string from 208.64.252.230
Apr 2 23:26:25 kernel: SSH ACCEPT IN=vlan2 OUT= MAC=00:26:18:a1:3c:fb:00:60:4c:e3:66:3c:08:00:45:00:00:3c SRC=208.64.252.230 DST=192.168.1.11 LEN=60 TOS=0x00 PREC=0x00 TTL=46 ID=46836 DF PROTO=TCP SPT=45729 DPT=22 SEQ=3882735177 ACK=0 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405B40402080ABCEA60BD0000000001030307)
Apr 2 23:26:26 /opt/sbin/sshd[824]: Did not receive identification string from 208.64.252.230
Apr 2 23:26:35 kernel: SSH ACCEPT IN=vlan2 OUT= MAC=00:26:18:a1:3c:fb:00:60:4c:e3:66:3c:08:00:45:00:00:3c SRC=208.64.252.230 DST=192.168.1.11 LEN=60 TOS=0x00 PREC=0x00 TTL=46 ID=18665 DF PROTO=TCP SPT=45765 DPT=22 SEQ=3886140901 ACK=0 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405B40402080ABCEA850C0000000001030307)
Apr 2 23:26:35 /opt/sbin/sshd[825]: Did not receive identification string from 208.64.252.230
also the ip get listed in the /proc/net/ipt_recent/BRUTE file
src=208.64.252.230 ttl: 46 last_seen: 4294823209 oldest_pkt: 4 4294799437, 4294818572, 4294821275, 4294823209
dunno if it's meant to work like this, since I remembered it to work with older versions