if your sshd was compiled with lbwrap you can use /etc/hosts.allow or /etc/hosts.deny
then every time someone connects the tcpwrapper checks for this files and reads them to see if the ip / hostname have access.
man hosts.allow
man hosts.deny
if it doesn't work remove previous instalation, get the source code and read the INSTALL file.
anyway, it should go something like:
./configure --with-tcp-wrappers
make
su
make install
|