Automatic Linux SSH attack blocking

SSH Brute Force Protection for Linux

Guard turns normal SSH authentication evidence into a controlled defense loop: observe failures, correlate the source, apply policy, and enforce the block using the local Linux firewall.

SSH authentication failure monitoring

Supported as part of the Guard monitoring, policy or enforcement workflow.

Configurable threshold and block duration

Supported as part of the Guard monitoring, policy or enforcement workflow.

nftables-based local enforcement

Supported as part of the Guard monitoring, policy or enforcement workflow.

Trusted and allowlisted source protection

Supported as part of the Guard monitoring, policy or enforcement workflow.

Repeat-offender handling

Supported as part of the Guard monitoring, policy or enforcement workflow.

Country and reputation context

Supported as part of the Guard monitoring, policy or enforcement workflow.

Capabilities

What this Guard workflow covers

Designed around observable server evidence

Scantide Guard does not need to attack, exploit or brute-force a service to decide that repeated hostile activity deserves action. Collectors observe evidence already generated by the server, normalize it into a common event model, then apply explicit thresholds, allowlists, exceptions and enforcement policy.

The result is intended to be understandable by an administrator: which source IP was seen, which collector reported it, which rule or threshold was reached, what action Guard took, and when a temporary block is due to expire.

Standalone when you need it. Centralized when you grow.

A single Guard can protect its own server with local policy and local firewall enforcement. Organizations with multiple systems can add Scantide Guard Datacenter for shared policy, fleet visibility, licensing and coordinated reputation services.

Frequently asked questions

Is this a replacement for Fail2ban?

It can cover the SSH failed-login blocking use case while also participating in the wider Scantide Guard management, reputation and Windows/Linux fleet model. The products are not identical.

Does Guard need a cloud firewall?

No. Enforcement is performed locally on the protected Linux system.

Can I monitor applications besides SSH?

Yes. Guard supports web-server sources and custom log monitors so additional application authentication evidence can be normalized into the Guard model.

See Scantide Guard in context

Read the current Guard documentation, deployment notes and product status, then choose the Windows, Linux or Datacenter path that fits your environment.