Netban, a Bash script posted on dev.to, bans an SSH bot's whole /24 for 24 hours by default. Its author built it after one bot tripped Wazuh 91 times. Bans live in a separate nftables table and expire by themselves, leaving existing UFW or firewalld rules untouched.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap−5
- Incentives30
- Confidence45
One developer's audit of a self-hosted OpenClaw agent found four ports Docker opened past ufw and watchdog crons using about 1,340 LLM turns a week. The repairs bind container ports to loopback, and the author now measures agent cost as quota by counting task runs.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence45
A dev.to layering guide for self-hosted Laravel admins runs from ufw defaults through ModSecurity to a five-per-minute login limiter. Both fail2ban and that limiter depend on resolving the real client IP.
Reality
- Evidence36
- Adoption
- Insufficient
- Hype gap+12
- Incentives62
- Confidence54
Putting sshd on a WireGuard tailnet and deleting the public firewall rule is a twenty-minute change. The part worth reviewing is the admin-console toggle that keeps a headless box from logging itself out.
Reality
- Evidence46
- Adoption
- Insufficient
- Hype gap+8
- Incentives34
- Confidence52
A sysadmin's incident writeup argues the reboot reflex destroys the evidence you need. Its fixed check order is the useful part, though only two of the five steps survive in the published text.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+32
- Incentives48
- Confidence56