

ip firewall filter add action=add-src-to-address-list address-list=ssh_stage1 address-list-timeout=5m chain=forward connection-state=new dst-port=22,23 in-interface=WAN protocol=tcp ip firewall filter add action=add-src-to-address-list address-list=ssh_stage2 address-list-timeout=5m chain=forward connection-state=new dst-port=22,23 in-interface=WAN protocol=tcp src-address-list=ssh_stage1 ip firewall filter add action=add-src-to-address-list address-list=ssh_stage3 address-list-timeout=5m chain=forward connection-state=new dst-port=22,23 in-interface=WAN protocol=tcp src-address-list=ssh_stage2


ip firewall filter add action=add-src-to-address-list address-list=ssh_blacklist address-list-timeout=4w2d chain=forward connection-state=new dst-port=22,23 in-interface=WAN protocol=tcp src-address-list=ssh_stage3 ip firewall filter add action=drop chain=forward comment="Drop SSH brute forcers" src-address-list=ssh_blacklist
