feat(security): fail2ban sshd.local с ignoreip admin и banaction ufw.
This commit is contained in:
@@ -104,6 +104,8 @@ sudo fail2ban-client status haproxy-reject
|
||||
|
||||
Порог: **15** reject за **10 мин** → бан **24 ч** через UFW. `ignoreip`: LAN, VPN, admin.
|
||||
|
||||
**sshd:** `jail.d/sshd.local` — `banaction = ufw`, те же `ignoreip` (не банить admin/VPN/LAN).
|
||||
|
||||
После `systemctl restart fail2ban` подождите 1–2 с перед `fail2ban-client status` (сокет).
|
||||
|
||||
### SSH (пример)
|
||||
|
||||
Reference in New Issue
Block a user