Well, the attack stopped at 16:36 local time -- I guess the botnet recognizes when there's no response on port 22 (ssh).

Curiously though, at 17:27, the firewall rejected a small flurry of twenty or so simultaneous ICMP TYPE=8 packets (from a botnet), and then some ACK-FIN attacks on the SMTP server.

Since then, things have been mostly quiet, with just the normal single-host attempts on port 22 (ssh).

Such fun!