After some posts a discussion on the freebsd-table mailing list goes into several approaches to deal with these SSH probes. See http://lists.freebsd.org/pipermail/freebsd-stable/2009-December/053326.html You still could allow outgoing ssh traffic on port 22 and allow incoming SSH on another port. Adriaan