Re: Китайский фильтр
Поставил сиё Fail2Ban, но шибко жутко работает, залочило пару моих железок.
2010-06-14 15:16:18,018 fail2ban.server : INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.8.4
2010-06-14 15:16:18,019 fail2ban.jail : INFO Creating new jail 'asterisk-iptables'
2010-06-14 15:16:18,020 fail2ban.jail : INFO Jail 'asterisk-iptables' uses poller
2010-06-14 15:16:18,056 fail2ban.filter : INFO Added logfile = /var/log/messages
2010-06-14 15:16:18,057 fail2ban.filter : INFO Set maxRetry = 5
2010-06-14 15:16:18,065 fail2ban.filter : INFO Set findtime = 600
2010-06-14 15:16:18,066 fail2ban.actions: INFO Set banTime = 259200
2010-06-14 15:16:18,101 fail2ban.jail : INFO Jail 'asterisk-iptables' started
2010-06-14 15:16:38,136 fail2ban.actions: WARNING [asterisk-iptables] Ban 10.61.191.191
2010-06-14 15:48:13,690 fail2ban.actions: WARNING [asterisk-iptables] Unban 10.61.191.191
2010-06-14 15:48:13,891 fail2ban.jail : INFO Jail 'asterisk-iptables' stopped
2010-06-14 15:48:13,892 fail2ban.server : INFO Exiting Fail2ban
2010-06-14 15:51:08,142 fail2ban.server : INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.8.4
2010-06-14 15:51:08,143 fail2ban.jail : INFO Creating new jail 'asterisk-iptables'
2010-06-14 15:51:08,143 fail2ban.jail : INFO Jail 'asterisk-iptables' uses poller
2010-06-14 15:51:08,168 fail2ban.filter : INFO Added logfile = /var/log/messages
2010-06-14 15:51:08,169 fail2ban.filter : INFO Set maxRetry = 5
2010-06-14 15:51:08,177 fail2ban.filter : INFO Set findtime = 600
2010-06-14 15:51:08,178 fail2ban.actions: INFO Set banTime = 259200
2010-06-14 15:51:08,213 fail2ban.jail : INFO Jail 'asterisk-iptables' started
2010-06-14 15:51:15,269 fail2ban.actions: WARNING [asterisk-iptables] Ban 10.61.191.191
2010-06-14 22:22:31,405 fail2ban.actions: WARNING [asterisk-iptables] Ban 91.185.19.63
2010-06-14 22:22:32,132 fail2ban.actions: WARNING [asterisk-iptables] 91.185.19.63 already banned
2010-06-14 22:30:25,097 fail2ban.actions: WARNING [asterisk-iptables] 10.61.191.191 already banned
2010-06-14 22:30:38,095 fail2ban.actions: WARNING [asterisk-iptables] Unban 10.61.191.191
2010-06-14 22:30:38,129 fail2ban.actions.action: ERROR iptables -n -L INPUT | grep -q fail2ban-ASTERISK returned 100
2010-06-14 22:30:38,130 fail2ban.actions.action: ERROR Invariant check failed. Trying to restore a sane environment
2010-06-14 22:30:38,134 fail2ban.actions.action: ERROR iptables -D INPUT -p all -j fail2ban-ASTERISK
iptables -F fail2ban-ASTERISK
iptables -X fail2ban-ASTERISK returned 100
2010-06-14 22:30:38,146 fail2ban.actions.action: ERROR iptables -D fail2ban-ASTERISK -s 10.61.191.191 -j DROP returned 100
2010-06-14 22:30:38,146 fail2ban.actions: WARNING [asterisk-iptables] Unban 91.185.19.63
2010-06-14 22:30:38,152 fail2ban.actions.action: ERROR iptables -D fail2ban-ASTERISK -s 91.185.19.63 -j DROP returned 100
2010-06-14 22:30:38,172 fail2ban.jail : INFO Jail 'asterisk-iptables' stopped
2010-06-14 22:30:38,173 fail2ban.server : INFO Exiting Fail2ban
Как бы помягче сделать правила, что бы лочило ну после явных плохих дел?
|