iptables or denyhosts

#1
iptables or hosts.deny

Just wondering, if someone was attempting to brute force root/shh what is the better way for blocking the the offending IP#`s?

iptables or hosts.deny?

I have BFD installed, but of course it won`t block everyone that is attempting a brute force. Sometimes there could be hundreds of attempts before the cron runs BFD again.

Thanks.
 
Top