0x00 安装
yum install fail2ban fail2ban-systemd
0x01 配置
在 /etc/fail2ban/ 创建文件 jail.local
ignoreip = #IP白名单
bantime = 864000 # 禁止的时间,单位秒,我这里设置的是24小时.
findtime = 600 # 检测时间,超过600秒自动激活
maxretry = 5 # 允许最大的错误次数
banaction = firewallcmd-ipset
action = %(action_mwl)s
enabled = true
filter = sshd
port = ssh
action = %(action_mwl)s
logpath = /var/log/secure
enabled = true
port = ssh
filter = sshd-ddos
logpath = %(sshd_log)s
maxretry = 5
enabled = true
port = ssh
logpath = %(dropbear_log)s
enabled = true
port = ssh
logpath = %(auditd_log)s
maxretry = 5
enabled = true
port = http,https
filter = apache-auth
logpath = %(apache_error_log)s
maxretry = 5
# Ban hosts which agent identifies spammer robots crawling the web
# for email addresses. The mail outputs are buffered.
port = http,https
logpath = %(apache_access_log)s
bantime = 172800
maxretry = 1
enabled = true
port = http,https
filter = apache-noscript
logpath = %(apache_error_log)s
maxretry = 6
enabled = true
port = http,https
filter = apache-overflows
logpath = %(apache_error_log)s
maxretry = 3
port = http,https
logpath = %(apache_error_log)s
maxretry = 2
port = http,https
logpath = %(apache_error_log)s
maxretry = 2
port = http,https
logpath = %(apache_error_log)s
maxretry = 2
enabled = true
port = http,https
filter = apache-shellshock
logpath = $(apache_error_log)s
maxretry = 1
ports = http,https
logpath = %(nginx_error_log)s
# Ban attackers that try to use PHP's URL-fopen() functionality
# through GET/POST variables. - Experimental, with more than a year
# of usage in production environments.
port = http,https
logpath = %(nginx_access_log)s
port = http,https
logpath = %(suhosin_log)s
# Same as above for Apache's mod_auth
# It catches wrong authentifications
port = http,https
logpath = %(lighttpd_error_log)s
# Webmail and groupware servers
port = http,https
logpath = /var/log/roundcube/userlogins
port = http,https
logpath = /var/log/openwebmail.log
port = http,https
logpath = /var/log/horde/horde.log
port = http,https
logpath = /home/groupoffice/log/info.log
# Monitor SOGo groupware server
# without proxy this would be:
# port = 20000
port = http,https
logpath = /var/log/sogo/sogo.log
logpath = /var/log/tine20/tine20.log
port = http,https
maxretry = 5
# Web Applications
port = http,https
logpath = /var/log/tomcat*/catalina.out
#Ban clients brute-forcing the monit gui login
filter = monit
port = 2812
logpath = /var/log/monit
enabled = true
port = 10000
filter = webmin-auth
logpath = %(syslog_authpriv)s
maxretry = 5
# HTTP Proxy servers
port = 80,443,3128,8080
logpath = /var/log/squid/access.log
port = 3128
logpath = /var/log/3proxy.log
# FTP servers
enabled = true
port = ftp,ftp-data,ftps,ftps-data
filter = proftpd
logpath = %(proftpd_log)s
maxretry = 5
port = ftp,ftp-data,ftps,ftps-data
logpath = %(pureftpd_log)s
maxretry = 6
port = ftp,ftp-data,ftps,ftps-data
logpath = %(syslog_daemon)s
maxretry = 6
port = ftp,ftp-data,ftps,ftps-data
logpath = %(wuftpd_log)s
maxretry = 6
# or overwrite it in jails.local to be
# logpath = %(syslog_authpriv)s
# if you want to rely on PAM failed login attempts
# vsftpd's failregex should match both of those formats
port = ftp,ftp-data,ftps,ftps-data
logpath = %(vsftpd_log)s
# Mail servers
# ASSP SMTP Proxy Jail
port = smtp,465,submission
logpath = /root/path/to/assp/logs/maillog.txt
port = smtp,465,submission
logpath = %(syslog_mail)s
enabled = true
port = smtp,465,submission
logpath = %(postfix_log)s
enabled = true
port = submission,465,smtp
logpath = %(syslog_mail)s
enabled = true
port = smtp,465,submission
logpath = %(syslog_mail)s
filter = qmail
port = smtp,465,submission
logpath = /service/qmail/log/main/current
# dovecot defaults to logging to the mail syslog facility
# but can be set by syslog_facility in the dovecot configuration.
enabled = true
port = pop3,pop3s,imap,imaps,submission,465,sieve
logpath = %(dovecot_log)s
port = smtp,465,submission
logpath = %(dovecot_log)s
port = pop3,pop3s
logpath = %(solidpop3d_log)s
port = smtp,465,submission
logpath = %(exim_main_log)s
port = smtp,465,submission
logpath = %(exim_main_log)s
port = imap,smtp,imaps,465
logpath = /opt/kerio/mailserver/store/logs/security.log
# Mail servers authenticators: might be used for smtp,ftp,imap servers, so
# all relevant ports get banned
port = smtp,465,submission,imap3,imaps,pop3,pop3s
logpath = %(syslog_mail)s
port = smtp,465,submission,imap3,imaps,pop3,pop3s
# You might consider monitoring /var/log/mail.warn instead if you are
# running postfix since it would provide the same log lines at the
# "warn" level but overall at the smaller filesize.
logpath = %(postfix_log)s
port = imap3,imaps,pop3,pop3s
logpath = %(syslog_mail)s
port = smtp,465,submission,imap2,imap3,imaps,pop3,pop3s,http,https,socks
logpath = /var/lib/squirrelmail/prefs/squirrelmail_access_log
port = imap3,imaps
logpath = %(syslog_mail)s
port = imap3,imaps
logpath = %(syslog_mail)s
# DNS servers
# !!! WARNING !!!
# Since UDP is connection-less protocol, spoofing of IP and imitation
# of illegal actions is way too simple. Thus enabling of this filter
# might provide an easy way for implementing a DoS against a chosen
# victim. See
# http://nion.modprobe.de/blog/archives/690-fail2ban-+-dns-fail.html
# Please DO NOT USE this jail unless you know what you are doing.
# IMPORTANT: see filter.d/named-refused for instructions to enable logging
# This jail blocks UDP traffic for DNS requests.
# [named-refused-udp]
# filter = named-refused
# port = domain,953
# protocol = udp
# logpath = /var/log/named/security.log
# IMPORTANT: see filter.d/named-refused for instructions to enable logging
# This jail blocks TCP traffic for DNS requests.
port = domain,953
logpath = /var/log/named/security.log
port = 53
action = %(banaction)s[name=%(__name__)s-tcp, port="%(port)s", protocol="tcp", chain="%(chain)s", actname=%(banaction)s-tcp]
%(banaction)s[name=%(__name__)s-udp, port="%(port)s", protocol="udp", chain="%(chain)s", actname=%(banaction)s-udp]
logpath = /var/log/nsd.log
# Miscellaneous
port = 5060,5061
action = %(banaction)s[name=%(__name__)s-tcp, port="%(port)s", protocol="tcp", chain="%(chain)s", actname=%(banaction)s-tcp]
%(banaction)s[name=%(__name__)s-udp, port="%(port)s", protocol="udp", chain="%(chain)s", actname=%(banaction)s-udp]
%(mta)s-whois[name=%(__name__)s, dest="%(destemail)s"]
logpath = /var/log/asterisk/messages
maxretry = 10
port = 5060,5061
action = %(banaction)s[name=%(__name__)s-tcp, port="%(port)s", protocol="tcp", chain="%(chain)s", actname=%(banaction)s-tcp]
%(banaction)s[name=%(__name__)s-udp, port="%(port)s", protocol="udp", chain="%(chain)s", actname=%(banaction)s-udp]
%(mta)s-whois[name=%(__name__)s, dest="%(destemail)s"]
logpath = /var/log/freeswitch.log
maxretry = 10
# To log wrong MySQL access attempts add to /etc/my.cnf in [mysqld] or
# equivalent section:
# log-warning = 2
# for syslog (daemon facility)
# [mysqld_safe]
# syslog
# for own logfile
# [mysqld]
# log-error=/var/log/mysqld.log
port = 3306
logpath = %(mysql_log)s
maxretry = 5
# Jail for more extended banning of persistent abusers
# !!! WARNING !!!
# Make sure that your loglevel specified in fail2ban.conf/.local
# is not at DEBUG level -- which might then cause fail2ban to fall into
# an infinite loop constantly feeding itself with non-informative lines
logpath = /var/log/fail2ban.log
port = all
protocol = all
bantime = 604800 ; 1 week
findtime = 86400 ; 1 day
maxretry = 5
# Generic filter for PAM. Has to be used with action which bans all
# ports such as iptables-allports, shorewall
# pam-generic filter can be customized to monitor specific subset of 'tty's
banaction = iptables-allports
logpath = %(syslog_authpriv)s
banaction = iptables-multiport-log
logpath = %(syslog_daemon)s
maxretry = 2
# stunnel - need to set port for this
logpath = /var/log/stunnel4/stunnel.log
port = 5222
logpath = /var/log/ejabberd/ejabberd.log
logpath = /opt/cstrike/logs/L[0-9]*.log
# Firewall: http://www.cstrike-planet.com/faq/6
tcpport = 27030,27031,27032,27033,27034,27035,27036,27037,27038,27039
udpport = 1200,27000,27001,27002,27003,27004,27005,27006,27007,27008,27009,27010,27011,27012,27013,27014,27015
action = %(banaction)s[name=%(__name__)s-tcp, port="%(tcpport)s", protocol="tcp", chain="%(chain)s", actname=%(banaction)s-tcp]
%(banaction)s[name=%(__name__)s-udp, port="%(udpport)s", protocol="udp", chain="%(chain)s", actname=%(banaction)s-udp]
# consider low maxretry and a long bantime
# nobody except your own Nagios server should ever probe nrpe
enabled = false
logpath = %(syslog_daemon)s ; nrpe.cfg may define a different log_facility
maxretry = 1
# see "oracleims" filter file for configuration requirement for Oracle IMS v6 and above
enabled = false
logpath = /opt/sun/comms/messaging64/log/mail.log_current
maxretry = 6
banaction = iptables-allports
enabled = false
logpath = /var/log/directadmin/login.log
port = 2222
enabled = false
logpath = /var/lib/portsentry/portsentry.history
maxretry = 1
重启fail2ban即可 systemctl restart fail2ban
本内容同步更新在我的个人博客 「我们都是害虫」 https://ezlost.com 搜索查询关注订阅评论 更加方便快捷.内容转载请注明来源。