For remote maintenance, we use to block ssh for all normal users, only root is allowed. Root has an extra strong password. I cannot think of a broute-force attack which is able to break in. Maintenance is simple and the users' self-choosen password's strength does not affect external ssh.