|
|
|
@ -171,16 +171,16 @@ banaction = iptables-multiport
|
|
|
|
|
banaction_allports = iptables-allports |
|
|
|
|
|
|
|
|
|
# The simplest action to take: ban only |
|
|
|
|
action_ = %(banaction)s[name=%(__name__)s, bantime="%(bantime)s", port="%(port)s", protocol="%(protocol)s", chain="%(chain)s"] |
|
|
|
|
action_ = %(banaction)s[bantime="%(bantime)s", port="%(port)s", protocol="%(protocol)s", chain="%(chain)s"] |
|
|
|
|
|
|
|
|
|
# ban & send an e-mail with whois report to the destemail. |
|
|
|
|
action_mw = %(action_)s |
|
|
|
|
%(mta)s-whois[name=%(__name__)s, sender="%(sender)s", dest="%(destemail)s", protocol="%(protocol)s", chain="%(chain)s"] |
|
|
|
|
%(mta)s-whois[sender="%(sender)s", dest="%(destemail)s", protocol="%(protocol)s", chain="%(chain)s"] |
|
|
|
|
|
|
|
|
|
# ban & send an e-mail with whois report and relevant log lines |
|
|
|
|
# to the destemail. |
|
|
|
|
action_mwl = %(action_)s |
|
|
|
|
%(mta)s-whois-lines[name=%(__name__)s, sender="%(sender)s", dest="%(destemail)s", logpath="%(logpath)s", chain="%(chain)s"] |
|
|
|
|
%(mta)s-whois-lines[sender="%(sender)s", dest="%(destemail)s", logpath="%(logpath)s", chain="%(chain)s"] |
|
|
|
|
|
|
|
|
|
# See the IMPORTANT note in action.d/xarf-login-attack for when to use this action |
|
|
|
|
# |
|
|
|
@ -192,7 +192,7 @@ action_xarf = %(action_)s
|
|
|
|
|
# ban IP on CloudFlare & send an e-mail with whois report and relevant log lines |
|
|
|
|
# to the destemail. |
|
|
|
|
action_cf_mwl = cloudflare[cfuser="%(cfemail)s", cftoken="%(cfapikey)s"] |
|
|
|
|
%(mta)s-whois-lines[name=%(__name__)s, sender="%(sender)s", dest="%(destemail)s", logpath="%(logpath)s", chain="%(chain)s"] |
|
|
|
|
%(mta)s-whois-lines[sender="%(sender)s", dest="%(destemail)s", logpath="%(logpath)s", chain="%(chain)s"] |
|
|
|
|
|
|
|
|
|
# Report block via blocklist.de fail2ban reporting service API |
|
|
|
|
# |
|
|
|
|