In the MPAQ network, we have all outside traffic channeling on a VPN. If you don't have a VPN cert to connect to it, you can't even see SSH. Plus, we use a proxy afterwards to direct requests to the inside IPs.
Unfortunately, that means, my 2 systems can't see the hacker IP or id have a PHP code automatically insert the IP into .httaccess with "Deny From xxx.xxx.xxx.xxx" that would block them from seeing any of the sites I work on.
As it is, I channel any 404 or what ever into a bad bots area with "strong warning" saying your blocked...
Doesn't do anything but if a person opens a page that isn't there, the average user gets a little scared 😂

