V8.00.000.2025.06.17
All checks were successful
🛡️ Shell Script Linting / 🛡️ Shell Script Linting (push) Successful in 1m51s
All checks were successful
🛡️ Shell Script Linting / 🛡️ Shell Script Linting (push) Successful in 1m51s
Signed-off-by: Marc S. Weidner <msw@coresecret.dev>
This commit is contained in:
@@ -144,7 +144,7 @@ bantime.maxtime = 16d
|
||||
bantime.multipliers = 1 2 4 8 16 32 64 128 256 384
|
||||
bantime.overalljails = true
|
||||
bantime.rndtime = 877s
|
||||
filter = ciss.icmp
|
||||
filter = ciss-icmp
|
||||
findtime = 16m
|
||||
logpath = /var/log/ufw.log
|
||||
maxretry = 1
|
||||
@@ -159,7 +159,7 @@ bantime.maxtime = 16d
|
||||
bantime.multipliers = 1 2 4 8 16 32 64 128 256 384
|
||||
bantime.overalljails = true
|
||||
bantime.rndtime = 877s
|
||||
filter = ciss.ufw
|
||||
filter = ciss-ufw
|
||||
findtime = 16m
|
||||
logpath = /var/log/ufw.log
|
||||
maxretry = 1
|
||||
@@ -242,7 +242,7 @@ bantime.maxtime = 16d
|
||||
bantime.multipliers = 1 2 4 8 16 32 64 128 256 384
|
||||
bantime.overalljails = true
|
||||
bantime.rndtime = 877s
|
||||
filter = ciss.icmp
|
||||
filter = ciss-icmp
|
||||
findtime = 16m
|
||||
logpath = /var/log/ufw.log
|
||||
maxretry = 3
|
||||
@@ -257,7 +257,7 @@ bantime.maxtime = 16d
|
||||
bantime.multipliers = 1 2 4 8 16 32 64 128 256 384
|
||||
bantime.overalljails = true
|
||||
bantime.rndtime = 877s
|
||||
filter = ciss.ufw
|
||||
filter = ciss-ufw
|
||||
findtime = 16m
|
||||
logpath = /var/log/ufw.log
|
||||
maxretry = 3
|
||||
@@ -274,9 +274,9 @@ EOF
|
||||
|
||||
fi
|
||||
|
||||
insert_header "${var_target}/etc/fail2ban/filter.d/ciss.icmp.conf"
|
||||
insert_comments "${var_target}/etc/fail2ban/filter.d/ciss.icmp.conf"
|
||||
cat << EOF >> "${var_target}/etc/fail2ban/filter.d/ciss.icmp.conf"
|
||||
insert_header "${var_target}/etc/fail2ban/filter.d/ciss-icmp.conf"
|
||||
insert_comments "${var_target}/etc/fail2ban/filter.d/ciss-icmp.conf"
|
||||
cat << EOF >> "${var_target}/etc/fail2ban/filter.d/ciss-icmp.conf"
|
||||
[Definition]
|
||||
# Generic ICMP/ICMPv6 blocks
|
||||
failregex = ^.*UFW (?:BLOCK|REJECT).*?\bSRC=<HOST>\b.*?\bPROTO=ICMP\b.*$
|
||||
@@ -285,9 +285,9 @@ failregex = ^.*UFW (?:BLOCK|REJECT).*?\bSRC=<HOST>\b.*?\bPROTO=ICMP\
|
||||
# vim: number et ts=2 sw=2 sts=2 ai tw=128 ft=conf
|
||||
EOF
|
||||
|
||||
insert_header "${var_target}/etc/fail2ban/filter.d/ciss.ufw.conf"
|
||||
insert_comments "${var_target}/etc/fail2ban/filter.d/ciss.ufw.conf"
|
||||
cat << EOF >> "${var_target}/etc/fail2ban/filter.d/ciss.ufw.conf"
|
||||
insert_header "${var_target}/etc/fail2ban/filter.d/ciss-ufw.conf"
|
||||
insert_comments "${var_target}/etc/fail2ban/filter.d/ciss-ufw.conf"
|
||||
cat << EOF >> "${var_target}/etc/fail2ban/filter.d/ciss-ufw.conf"
|
||||
[Definition]
|
||||
# Match UFW BLOCK/REJECT with a source IP and *any* port field (SPT or DPT), protocol may be missing.
|
||||
failregex = ^.*UFW (?:BLOCK|REJECT).*?\bSRC=<HOST>\b.*?(?:\bDPT=\d+\b|\bSPT=\d+\b).*$
|
||||
|
||||
Reference in New Issue
Block a user