mirror of
				https://github.com/NginxProxyManager/nginx-proxy-manager.git
				synced 2025-10-31 15:53:33 +00:00 
			
		
		
		
	
		
			
				
	
	
		
			31 lines
		
	
	
		
			1.0 KiB
		
	
	
	
		
			Plaintext
		
	
	
	
	
	
			
		
		
	
	
			31 lines
		
	
	
		
			1.0 KiB
		
	
	
	
		
			Plaintext
		
	
	
	
	
	
| ## Version 2022/08/06
 | |
| # Fail2Ban configuration file
 | |
| #
 | |
| # Author: Michael Gebetsroither
 | |
| #
 | |
| # This is for blocking whole hosts through blackhole routes.
 | |
| #
 | |
| # PRO:
 | |
| #   - Works on all kernel versions and as no compatibility problems (back to debian lenny and WAY further).
 | |
| #   - It's FAST for very large numbers of blocked ips.
 | |
| #   - It's FAST because it Blocks traffic before it enters common iptables chains used for filtering.
 | |
| #   - It's per host, ideal as action against ssh password bruteforcing to block further attack attempts.
 | |
| #   - No additional software required beside iproute/iproute2
 | |
| #
 | |
| # CON:
 | |
| #   - Blocking is per IP and NOT per service, but ideal as action against ssh password bruteforcing hosts
 | |
| 
 | |
| [Definition]
 | |
| actionban   = ip route add <blocktype> <ip>
 | |
| actionunban = ip route del <blocktype> <ip>
 | |
| actioncheck =
 | |
| actionstart =
 | |
| actionstop =
 | |
| 
 | |
| [Init]
 | |
| 
 | |
| # Option:  blocktype
 | |
| # Note:    Type can be blackhole, unreachable and prohibit. Unreachable and prohibit correspond to the ICMP reject messages.
 | |
| # Values:  STRING
 | |
| blocktype = unreachable
 |