[sshd] enabled = true mode = aggressive port = ssh backend = systemd action = iptables-allports[name=sshd, protocol=all] bantime = 24h maxretry = 3 findtime = 600