On 2008/01/11 12:33, Lars Noodin wrote:
> 
> I suppose another option is to use pf to filter out all incoming traffic
> to the servers originating from Windows computers

you can take a look for yourself with tcpdump -O, but I think you'll
find the ssh scans are more likely to be from some variety of unix.

an inclusive match is usually better e.g.
pass proto tcp from any os "OpenBSD" to port ssh

Reply via email to