• anoma's avatar
    Activate FAIL2BAN recidive jail · 593fd242
    anoma authored
    Recidive can be thought of as FAIL2BAN checking itself. This setup will monitor the FAIL2BAN log and if 10 bans are seen within one day activate a week long ban and email the mail in a box admin that it has been applied . These bans survive FAIL2BAN service restarts so are much stronger which obviously means we need to be careful with them.
    
    Our current settings are relatively safe and definitely not easy to trigger by mistake e.g to activate a recidive IP jail by failed SSH logins a user would have to fail logging into SSH  6 times in 10 minutes, get banned, wait for the ban to expire and then repeat this process 9 further times within a 24 hour period.
    
    The default maxretry of 5 is much saner but that can be applied once users are happy with this jail. I have been running a stronger version of this for months and it does a very good job of ejecting persistent abusers.
    593fd242
Name
Last commit
Last update
..
fail2ban Loading commit data...
zpush Loading commit data...
ios-profile.xml Loading commit data...
management-initscript Loading commit data...
mozilla-autoconfig.xml Loading commit data...
nginx-alldomains.conf Loading commit data...
nginx-primaryonly.conf Loading commit data...
nginx-ssl.conf Loading commit data...
nginx-top.conf Loading commit data...
nginx.conf Loading commit data...
postfix_outgoing_mail_header_filters Loading commit data...
sieve-spam.txt Loading commit data...
www_default.html Loading commit data...