Maybe not the right place but we have our HA open to the www.
I am getting countless invalid logins from China and so on I assume people trying to hack in. I have it setup that 3 incorrect attempts block forever but it seems to be getting worse.
My question is if i have a strong password and username, the 3 incorrect and block. Is that enough?