From 33c2059d1d8e6a3617e4f30f8a5f6f694dd720e4 Mon Sep 17 00:00:00 2001 From: Th4nat0s Date: Sun, 17 Jun 2012 00:50:17 +0200 Subject: [PATCH] ip validation and reconfiguration of iptables actions --- config/action.d/iptables-allports.conf | 23 +++++++-------- config/action.d/iptables-multiport-log.conf | 31 +++++++++++---------- config/action.d/iptables-multiport.conf | 21 +++++++------- config/action.d/iptables-new.conf | 23 +++++++-------- config/action.d/iptables.conf | 21 +++++++------- server/filter.py | 18 +++++++++--- 6 files changed, 76 insertions(+), 61 deletions(-) diff --git a/config/action.d/iptables-allports.conf b/config/action.d/iptables-allports.conf index 1cc2daba..51dc8a5d 100644 --- a/config/action.d/iptables-allports.conf +++ b/config/action.d/iptables-allports.conf @@ -2,7 +2,8 @@ # # Author: Cyril Jaquier # Modified: Yaroslav O. Halchenko -# made active on all ports from original iptables.conf +# made active on all ports from original fail2ban-iptables.conf +# Modified by Paul J aka Thanat0s for ipv6 support # # $Revision$ # @@ -13,23 +14,23 @@ # Notes.: command executed once at the start of Fail2Ban. # Values: CMD # -actionstart = iptables -N fail2ban- - iptables -A fail2ban- -j RETURN - iptables -I -p -j fail2ban- +actionstart = fail2ban-iptables -N fail2ban- + fail2ban-iptables -A fail2ban- -j RETURN + fail2ban-iptables -I -p -j fail2ban- # Option: actionstop # Notes.: command executed once at the end of Fail2Ban # Values: CMD # -actionstop = iptables -D -p -j fail2ban- - iptables -F fail2ban- - iptables -X fail2ban- +actionstop = fail2ban-iptables -D -p -j fail2ban- + fail2ban-iptables -F fail2ban- + fail2ban-iptables -X fail2ban- # Option: actioncheck # Notes.: command executed once before each actionban command # Values: CMD # -actioncheck = iptables -n -L | grep -q fail2ban- +actioncheck = fail2ban-iptables -n -L | grep -q fail2ban- # Option: actionban # Notes.: command executed when banning an IP. Take care that the @@ -39,7 +40,7 @@ actioncheck = iptables -n -L | grep -q fail2ban- #