mirror of https://github.com/fail2ban/fail2ban
Danila Vershinin
7 years ago
committed by
sebres
2 changed files with 52 additions and 0 deletions
@ -0,0 +1,51 @@
|
||||
# Fail2Ban action file for firewall-cmd/ipset |
||||
# |
||||
# This requires: |
||||
# ipset (package: ipset) |
||||
# firewall-cmd (package: firewalld) |
||||
# |
||||
# This is for ipset protocol 6 (and hopefully later) (ipset v6.14). |
||||
# Use ipset -V to see the protocol and version. |
||||
# |
||||
# IPset was a feature introduced in the linux kernel 2.6.39 and 3.0.0 kernels. |
||||
# |
||||
# If you are running on an older kernel you make need to patch in external |
||||
# modules. |
||||
|
||||
[INCLUDES] |
||||
|
||||
before = iptables-common.conf |
||||
|
||||
[Definition] |
||||
|
||||
actionstart = ipset create fail2ban-<name> hash:ip timeout <bantime> |
||||
firewall-cmd --direct --add-rule ipv4 filter <chain> 0 -m set --match-set fail2ban-<name> src -j <blocktype> |
||||
|
||||
actionstop = firewall-cmd --direct --remove-rule ipv4 filter <chain> 0 -m set --match-set fail2ban-<name> src -j <blocktype> |
||||
ipset flush fail2ban-<name> |
||||
ipset destroy fail2ban-<name> |
||||
|
||||
actionban = ipset add fail2ban-<name> <ip> timeout <bantime> -exist |
||||
|
||||
actionunban = ipset del fail2ban-<name> <ip> -exist |
||||
|
||||
[Init] |
||||
|
||||
# Option: chain |
||||
# Notes specifies the iptables chain to which the fail2ban rules should be |
||||
# added |
||||
# Values: [ STRING ] |
||||
# |
||||
chain = INPUT_direct |
||||
|
||||
# Option: bantime |
||||
# Notes: specifies the bantime in seconds (handled internally rather than by fail2ban) |
||||
# Values: [ NUM ] Default: 600 |
||||
|
||||
bantime = 600 |
||||
|
||||
|
||||
# DEV NOTES: |
||||
# |
||||
# Author: Edgar Hoch and Daniel Black |
||||
# firewallcmd-new / iptables-ipset-proto6 combined for maximium goodness |
Loading…
Reference in new issue