4 ms·
Crypto-in-crypto seems kind of wasteful... Something like fail2ban would be preferable--block assholes from the entire network for hours (or days) so they can'
by hello_computer 3y ago
Crypto-in-crypto seems kind of wasteful... Something like fail2ban would be preferable--block assholes from the entire network for hours (or days) so they can't hammer other ports for vulnerabilities. Between LocalForward and ProxyJump, I hardly ever need my WireGuard tunnel.
- ttyprintk 3y agoNothing against fail2ban, but with its RCE a few years ago, I wonder about simpler firewall rules: - If the IP has an established port 22 connection, pass any new connections - Otherwise, meter connections from each /24 to one per 21 seconds I think ControlMaster would keep this from gumming up Ansible too much?
- hello_computer 3y ago> RCE a few years ago If it's this one (https://nvd.nist.gov/vuln/detail/CVE-2021-32749 https://nvd.nist.gov/vuln/detail/CVE-2021-32749), I think that's kind of a reach--especially for the typical use case, which uses neither mail nor whois, and only adds an ephemeral block rule to the firewall. My beef with fail2ban is that it only checks logs on a (non-configurable) 1 second interval, which allows an attacker to make several attempts (> N) from the same IP in parallel inside of that second, even when the f2b configuration is set to block at the Nth failure.