Yuriy Gorlichenko writes:
Looks no, because connection must be established for handling it in the config file. This error fired by ssl library during Negotiation process.
But you can try tcpdump, at least you will see Who tries to established connection
Yes, I could do that, but I would rather get the IP address to syslog so that I could fail2ban it.
-- Juha