Add fail2ban 4xx/badbots filters, jail backend fix, and review #007
- Add reverse-proxy-4xx and reverse-proxy-badbots fail2ban filters - Set backend=auto and ignoreip on all jails (fixes silent no-match when defaults-debian.conf inherits systemd backend) - Document three-jail setup and REQUEST log format in README - Add review #007 covering connection lifecycle, logging, and deployment drift triggered by the 2026-07-24 FD exhaustion incident
This commit is contained in:
1 parent
f6e62a37ef
commit
e803817350
5 files changed
+637
-7
No files matched your search
@@ -0,0 +1,6 @@
|
||||
[Definition]
|
||||
failregex = ^.*prefix="REQUEST" client_ip=<HOST> .* status=(401|403) .*$
|
||||
ignoreregex =
|
||||
|
||||
[Init]
|
||||
maxlines = 1
|
||||
@@ -0,0 +1,14 @@
|
||||
[Definition]
|
||||
failregex = ^.*prefix="REQUEST" client_ip=<HOST> .* method=(GET|POST|HEAD|PUT|DELETE|PATCH) path=/\.(env|git|DS_Store|aws|config)[^ ]* status=\d+
|
||||
^.*prefix="REQUEST" client_ip=<HOST> .* method=(PROPFIND|CONNECT) [^ ]* status=\d+
|
||||
^.*prefix="REQUEST" client_ip=<HOST> .* method=(GET|POST|HEAD) path=/(<webmail>|<phpmyadmin>|<wordpress>|cgi-bin|mysqladmin|actuator|SDK|ecp|developmentserver|wp-admin|wp-login\.php|phpinfo|\.aws|\.ssh)[^ ]* status=(400|404|405|413)
|
||||
^.*prefix="REQUEST" client_ip=<HOST> .* method=(GET|POST|HEAD) path=/[^ ]*[\x00-\x1f\x80-\xff]
|
||||
|
||||
webmail = roundcube|(ext)?mail|horde|(v-?)?webmail
|
||||
phpmyadmin = (typo3/|xampp/|admin/|)(pma|(php)?[Mm]y[Aa]dmin)
|
||||
wordpress = wp-(login|signup|admin)\.php
|
||||
|
||||
ignoreregex =
|
||||
|
||||
[Init]
|
||||
maxlines = 1
|
||||
@@ -1,7 +1,29 @@
|
||||
[reverse-proxy]
|
||||
enabled = true
|
||||
filter = reverse-proxy
|
||||
backend = auto
|
||||
logpath = /var/log/reverse-proxy/access.log
|
||||
maxretry = 10
|
||||
findtime = 60
|
||||
bantime = 3600
|
||||
bantime = 3600
|
||||
ignoreip = 127.0.0.1/8 ::1 10.0.0.0/8
|
||||
|
||||
[reverse-proxy-4xx]
|
||||
enabled = true
|
||||
filter = reverse-proxy-4xx
|
||||
backend = auto
|
||||
logpath = /var/log/reverse-proxy/access.log
|
||||
maxretry = 5
|
||||
findtime = 10m
|
||||
bantime = 1h
|
||||
ignoreip = 127.0.0.1/8 ::1 10.0.0.0/8
|
||||
|
||||
[reverse-proxy-badbots]
|
||||
enabled = true
|
||||
filter = reverse-proxy-badbots
|
||||
backend = auto
|
||||
logpath = /var/log/reverse-proxy/access.log
|
||||
maxretry = 5
|
||||
findtime = 10m
|
||||
bantime = 1h
|
||||
ignoreip = 127.0.0.1/8 ::1 10.0.0.0/8
|
||||
Reference in new issue
Block a user