3 ms·
Another really nifty way to achieve pretty much the same is to use iptables' built-in limit module like so: -A INPUT -p tcp -m tcp --dport 22 -m state --stat
by rmk2 13y ago
Another really nifty way to achieve pretty much the same is to use iptables' built-in limit module like so:
-A INPUT -p tcp -m tcp --dport 22 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -m limit --limit 3/min --limit-burst 4 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 22 -j DROP
Limit-bursts allows that many packages through before any limit counter starts, if any of the other packages afterwards also do not garner any response, a counter counts up for every further package, effectively blocking everything after the first 7 packages arriving within a minute. (You could also do 3/hour, for example, if you think you need it.)
The limit module is a beautiful thing, since you can also use it to limit log messages generated for events etc., using the same syntax, like so:
-A INPUT -m limit --limit 1/hour --limit-burst 3 -j LOG --log-prefix "iptables denied: "
- Hello71 13y agoAwesome, now I can DoS your SSH with only 3 requests per minute.
- SpenserJ 13y agoBoth limit and spindritf's suggestion will mitigate the attack, but they won't notify you about it. In most circumstances, I'd prefer to skip on the thousands of notifications per day, however I sometimes like to know about every detail on a server, and Fail2ban gives me that level of control, without the need to tail a log file.