| @@ -2,3 +2 @@ |
|
|
|
| # All jails overview
|
# All jails overview |
|
|
| @@ -14,3 +12 @@ |
|
|
|
| # Ban a test IP
|
# Ban a test IP |
|
|
| @@ -32,3 +28 @@ |
|
|
|
| fail2ban-client get nginx-404 bantime
|
fail2ban-client get nginx-404 bantime |
|
|
| @@ -41,3 +35 @@ |
|
|
|
| # Watch fail2ban log in real time
|
# Watch fail2ban log in real time |
|
|
| @@ -47,3 +39,3 @@ |
| fail2ban-client status nginx-404 | grep "Banned IP"
|
| fail2ban-client status nginx-botsearch | grep "Banned IP"
|
| fail2ban-client status recidive | grep "Banned IP"
|
| fail2ban-client status nginx-404 | grep "Banned IP" |
| fail2ban-client status nginx-botsearch | grep "Banned IP" |
| fail2ban-client status recidive | grep "Banned IP" |
|
|
| @@ -52 +44 @@ |
| fail2ban-client status nginx-404 | grep "Total banned"
|
| fail2ban-client status nginx-404 | grep "Total banned" |
|
|
| @@ -56,3 +48 @@ |
|
|
|
| # All current rich rules (fail2ban entries)
|
# All current rich rules (fail2ban entries) |
|
|
| @@ -69,3 +59 @@ |
|
|
|
| # Recidive watches fail2ban.log for repeat offenders
|
# Recidive watches fail2ban.log for repeat offenders |
|
|
| @@ -84,3 +72 @@ |
|
|
|
| # Test a filter against actual log
|
# Test a filter against actual log |
|
|
| @@ -94,4 +80,2 @@ |
|
|
|
| # fail2ban not banning despite log entries
|
| # → Check filter regex matches log format
|
# fail2ban not banning despite log entries |
| # → Check filter regex matches log format |
|
|
| @@ -101 +85 @@ |
| # → Check banaction is firewallcmd not iptables
|
| # → Check banaction is firewallcmd not iptables |
|
|
| @@ -103 +87 @@ |
| # → Verify firewalld rules being created
|
| # → Verify firewalld rules being created |
|
|
| @@ -107,3 +91,3 @@ |
| # → Recidive restores bans silently on restart
|
| # → Only new bans trigger email
|
| # → Test with manual banip
|
| # → Recidive restores bans silently on restart |
| # → Only new bans trigger email |
| # → Test with manual banip |
|
|
| @@ -112 +96 @@ |
| # → Edit jail.conf directly, copy to webstack
|
| # → Edit jail.conf directly, copy to webstack |
|
|
| @@ -115 +99 @@ |
| # → Verify: fail2ban-client version
|
| # → Verify: fail2ban-client version |
|
|
|
| @@ -123 +105 @@ |
| echo "=== Fail2ban Status ==="
|
| echo "=== Fail2ban Status ===" |
|
|
| @@ -126,2 +108,2 @@ |
| echo ""
|
| echo "=== Active Bans ==="
|
| echo "" |
| echo "=== Active Bans ===" |
|
|
| @@ -129,2 +111,2 @@ |
| echo "--- $jail ---"
|
| fail2ban-client status $jail | grep -E "Currently banned|Total banned|Banned IP"
|
| echo "--- $jail ---" |
| fail2ban-client status $jail | grep -E "Currently banned|Total banned|Banned IP" |
|
|
| @@ -133,3 +115,3 @@ |
| echo ""
|
| echo "=== Firewalld Rules ==="
|
| echo "Total rules: $(firewall-cmd --list-rich-rules | wc -l)"
|
| echo "" |
| echo "=== Firewalld Rules ===" |
| echo "Total rules: $(firewall-cmd --list-rich-rules | wc -l)" |
|
|
| @@ -137 +119 @@ |
| echo "(showing last 5)"
|
| echo "(showing last 5)" |
|
|
|