add support for blocking through blackhole routes

pull/104/head
Michael Gebetsroither 2013-01-03 18:46:31 +01:00
parent be06b1b914
commit f9b78ba927
1 changed files with 19 additions and 0 deletions

View File

@ -0,0 +1,19 @@
# Fail2Ban configuration file
#
# Author: Michael Gebetsroither
#
# This is for blocking whole hosts through blackhole routes.
#
# PRO:
# - Works on all kernel versions and as no compatibility problems (back to debian lenny and WAY further).
# - It's FAST for very large numbers of blocked ips.
# - It's FAST because it Blocks traffic before it enters common iptables chains used for filtering.
# - It's per host, ideal as action against ssh password bruteforcing to block further attack attempts.
# - No additional software required beside iproute/iproute2
#
# CON:
# - Blocking is per IP and NOT per service, but ideal as action against ssh password bruteforcing hosts
[Definition]
actionban = ip route add blackhole <ip>
actionunban = ip route del blackhole <ip>