/var/log/auth.log 中记录了SSH登录尝试,如果没有此文件,可尝试重启syslog: service syslog restart
sudo apt install fail2ban
vim /etc/fail2ban/jail.local
[sshd]
enabled = true
port = 14213
filter = sshd
logpath = /var/log/auth.log
maxretry = 5
service fail2ban restart
fail2ban-client status sshd