http://y5wnzw4e6i7srm2gqadlow5anhlaj5avdkzbwzbmrxwkygxdp7ffieqd.onion/blog/firehol-considered-useful.html
If there is a service that uses password authentication, something will try to brute-force/wordlist it [1] , perhaps, for a user that may not actually exist. Fail2Ban could get these IP addresses and ban them for a few hours/days/forever, however, trust me when I say this: it doesn't matter because they have an endless supply of IP addresses.