A comment in /etc/hosts.allow states that: Wrapping sshd(8) is not normally a good idea Why? Is it because such restrictions should naturally be made using a firewall/PAM/sshd itself/whatever? I think GENERIC sshd wouldn't have been built with libwrap support in the first place. Or?