3 ms·
Fail2ban [0] bans ip addresses based on failed login attempts (works for more than ssh), minus the isolation layer. [0]: https://www.fail2ban.org/wiki/index.ph
by bcrack 6y ago
Fail2ban [0] bans ip addresses based on failed login attempts (works for more than ssh), minus the isolation layer.
[0]: https://www.fail2ban.org/wiki/index.php/Main_Page https://www.fail2ban.org/wiki/index.php/Main_Page
- encom 6y agofail2ban should be avoided. It does not support IPv6, so should be considered legacy software. EDIT: Source: https://github.com/fail2ban/fail2ban/issues/1123 https://github.com/fail2ban/fail2ban/issues/1123 It appears they have moved forward a little in supporting IPv6, but it's still incomplete. It's unacceptable to not support it fully in 2020.
- bcrack 6y agoIt looks like ipv6 matching is supported since late 2017 (version 10.0 [0]), although the changelog states that "not all ban actions are IPv6-capable now". As for IPv6 capabilities, I don't have any recent experience with the software. [0]: https://github.com/fail2ban/fail2ban/blob/0.11.1/ChangeLog https://github.com/fail2ban/fail2ban/blob/0.11.1/ChangeLog
- jbverschoor 6y agoit does more than just scanning iptables logs..
- tinus_hn 6y agoWith IPv6 every user gets an IPv4 internet worth of addresses for himself which makes fail2ban useless.
- Forbo 6y agoCouldn't you just ban the /64 and call it good? It's not like they get a random selection of addresses, they're all going to be the same CIDR. Or am I overlooking something here?