diff --git a/config/action.d/firewallcmd-allports.conf b/config/action.d/firewallcmd-allports.conf index a478f25c..c0c378a4 100644 --- a/config/action.d/firewallcmd-allports.conf +++ b/config/action.d/firewallcmd-allports.conf @@ -17,10 +17,10 @@ actionstop = firewall-cmd --direct --remove-rule ipv4 filter 0 -j f2b- -# Note: uses regular expression word boundaries '\b' -# Example actioncheck: firewall-cmd --direct --get-chains ipv4 filter | grep -q '\bf2b-recidive\b' +# Note: uses regular expression whitespaces '\s' & end of line '$' +# Example actioncheck: firewall-cmd --direct --get-chains ipv4 filter | grep -q '\sf2b-recidive$' -actioncheck = firewall-cmd --direct --get-chains ipv4 filter | grep -q '\bf2b-\b' +actioncheck = firewall-cmd --direct --get-chains ipv4 filter | grep -q '\sf2b-$' actionban = firewall-cmd --direct --add-rule ipv4 filter f2b- 0 -s -j