mirror of https://github.com/fail2ban/fail2ban
Yaroslav Halchenko
12 years ago
2 changed files with 36 additions and 0 deletions
@ -0,0 +1,25 @@
|
||||
# Fail2Ban configuration file |
||||
# |
||||
# Author: Michael Gebetsroither |
||||
# |
||||
# This is for blocking whole hosts through blackhole routes. |
||||
# |
||||
# PRO: |
||||
# - Works on all kernel versions and as no compatibility problems (back to debian lenny and WAY further). |
||||
# - It's FAST for very large numbers of blocked ips. |
||||
# - It's FAST because it Blocks traffic before it enters common iptables chains used for filtering. |
||||
# - It's per host, ideal as action against ssh password bruteforcing to block further attack attempts. |
||||
# - No additional software required beside iproute/iproute2 |
||||
# |
||||
# CON: |
||||
# - Blocking is per IP and NOT per service, but ideal as action against ssh password bruteforcing hosts |
||||
|
||||
[Definition] |
||||
actionban = ip route add <type> <ip> |
||||
actionunban = ip route del <type> <ip> |
||||
|
||||
# Type of blocking |
||||
# |
||||
# Type can be blackhole, unreachable and prohibit. Unreachable and prohibit correspond to the ICMP reject messages. |
||||
|
||||
type = blackhole |
Loading…
Reference in new issue