A week-old server already sees thousands of login attempts a day. Key-only SSH, a firewall, fail2ban and monit — and the recovery plan for locking yourself out.
Installing fail2ban is treated as a step that protects the server. What it actually gives you is one jail — [ssh], watching auth.log — while the same brute…