SSH brute-force protection
Protect an internet-facing SSH service on RouterOS with firewall rules that count new connections per source address and block a source that opens too many in a short time. Covers what to do before exposing SSH, placing the rules in the default firewall, exempting trusted addresses, IPv6, checking and unblocking, and how many password guesses the rules still allow.