Centos7 安装 fail2ban 使用 firewalld 用来防护 ssh 以及 http

Centos7 安装 fail2ban 使用 firewalld 用来防护 ssh 以及 http

Posted by ivo on April 8, 2019

0x00 安装


yum install fail2ban fail2ban-systemd

0x01 配置

在 /etc/fail2ban/ 创建文件 jail.local

ignoreip = #IP白名单
bantime = 864000 # 禁止的时间,单位秒,我这里设置的是24小时.
findtime = 600 # 检测时间,超过600秒自动激活
maxretry = 5 # 允许最大的错误次数
banaction = firewallcmd-ipset
action = %(action_mwl)s

enabled = true
filter = sshd
port = ssh
action = %(action_mwl)s
logpath = /var/log/secure

enabled = true
port = ssh
filter = sshd-ddos
logpath = %(sshd_log)s
maxretry = 5


enabled = true
port     = ssh
logpath  = %(dropbear_log)s


enabled = true
port     = ssh
logpath  = %(auditd_log)s
maxretry = 5

enabled = true
port     = http,https
filter = apache-auth
logpath  = %(apache_error_log)s
maxretry = 5

# Ban hosts which agent identifies spammer robots crawling the web
# for email addresses. The mail outputs are buffered.
port     = http,https
logpath  = %(apache_access_log)s
bantime  = 172800
maxretry = 1

enabled = true
port     = http,https
filter = apache-noscript
logpath  = %(apache_error_log)s
maxretry = 6

enabled = true
port     = http,https
filter = apache-overflows
logpath  = %(apache_error_log)s
maxretry = 3


port     = http,https
logpath  = %(apache_error_log)s
maxretry = 2


port     = http,https
logpath  = %(apache_error_log)s
maxretry = 2


port     = http,https
logpath  = %(apache_error_log)s
maxretry = 2

enabled = true
port    = http,https
filter = apache-shellshock
logpath = $(apache_error_log)s
maxretry = 1


ports   = http,https
logpath = %(nginx_error_log)s

# Ban attackers that try to use PHP's URL-fopen() functionality
# through GET/POST variables. - Experimental, with more than a year
# of usage in production environments.


port    = http,https
logpath = %(nginx_access_log)s


port    = http,https
logpath = %(suhosin_log)s

# Same as above for Apache's mod_auth
# It catches wrong authentifications
port    = http,https
logpath = %(lighttpd_error_log)s

# Webmail and groupware servers


port     = http,https
logpath  = /var/log/roundcube/userlogins


port     = http,https
logpath  = /var/log/openwebmail.log


port     = http,https
logpath  = /var/log/horde/horde.log


port     = http,https
logpath  = /home/groupoffice/log/info.log

# Monitor SOGo groupware server
# without proxy this would be:
# port    = 20000
port     = http,https
logpath  = /var/log/sogo/sogo.log


logpath  = /var/log/tine20/tine20.log
port     = http,https
maxretry = 5

# Web Applications


port     = http,https
logpath  = /var/log/tomcat*/catalina.out

#Ban clients brute-forcing the monit gui login
filter   = monit
port = 2812
logpath  = /var/log/monit

enabled = true
port    = 10000
filter = webmin-auth
logpath = %(syslog_authpriv)s
maxretry = 5

# HTTP Proxy servers


port     =  80,443,3128,8080
logpath = /var/log/squid/access.log


port    = 3128
logpath = /var/log/3proxy.log

# FTP servers

enabled = true
port     = ftp,ftp-data,ftps,ftps-data
filter = proftpd
logpath  = %(proftpd_log)s
maxretry = 5


port     = ftp,ftp-data,ftps,ftps-data
logpath  = %(pureftpd_log)s
maxretry = 6


port     = ftp,ftp-data,ftps,ftps-data
logpath  = %(syslog_daemon)s
maxretry = 6


port     = ftp,ftp-data,ftps,ftps-data
logpath  = %(wuftpd_log)s
maxretry = 6

# or overwrite it in jails.local to be
# logpath = %(syslog_authpriv)s
# if you want to rely on PAM failed login attempts
# vsftpd's failregex should match both of those formats
port     = ftp,ftp-data,ftps,ftps-data
logpath  = %(vsftpd_log)s

# Mail servers

# ASSP SMTP Proxy Jail

port     = smtp,465,submission
logpath  = /root/path/to/assp/logs/maillog.txt


port     = smtp,465,submission
logpath  = %(syslog_mail)s

enabled = true
port     = smtp,465,submission
logpath  = %(postfix_log)s

enabled = true
port    = submission,465,smtp
logpath = %(syslog_mail)s

enabled = true
port     = smtp,465,submission
logpath  = %(syslog_mail)s


filter  = qmail
port    = smtp,465,submission
logpath = /service/qmail/log/main/current

# dovecot defaults to logging to the mail syslog facility
# but can be set by syslog_facility in the dovecot configuration.
enabled = true
port    = pop3,pop3s,imap,imaps,submission,465,sieve
logpath = %(dovecot_log)s


port   = smtp,465,submission
logpath = %(dovecot_log)s


port    = pop3,pop3s
logpath = %(solidpop3d_log)s


port   = smtp,465,submission
logpath = %(exim_main_log)s


port   = smtp,465,submission
logpath = %(exim_main_log)s


port    = imap,smtp,imaps,465
logpath = /opt/kerio/mailserver/store/logs/security.log

# Mail servers authenticators: might be used for smtp,ftp,imap servers, so
# all relevant ports get banned


port     = smtp,465,submission,imap3,imaps,pop3,pop3s
logpath  = %(syslog_mail)s


port     = smtp,465,submission,imap3,imaps,pop3,pop3s
# You might consider monitoring /var/log/mail.warn instead if you are
# running postfix since it would provide the same log lines at the
# "warn" level but overall at the smaller filesize.
logpath  = %(postfix_log)s


port   = imap3,imaps,pop3,pop3s
logpath = %(syslog_mail)s


port = smtp,465,submission,imap2,imap3,imaps,pop3,pop3s,http,https,socks
logpath = /var/lib/squirrelmail/prefs/squirrelmail_access_log


port   = imap3,imaps
logpath = %(syslog_mail)s


port   = imap3,imaps
logpath = %(syslog_mail)s

# DNS servers

# !!! WARNING !!!
#   Since UDP is connection-less protocol, spoofing of IP and imitation
#   of illegal actions is way too simple.  Thus enabling of this filter
#   might provide an easy way for implementing a DoS against a chosen
#   victim. See
#    http://nion.modprobe.de/blog/archives/690-fail2ban-+-dns-fail.html
#   Please DO NOT USE this jail unless you know what you are doing.
# IMPORTANT: see filter.d/named-refused for instructions to enable logging
# This jail blocks UDP traffic for DNS requests.
# [named-refused-udp]
# filter   = named-refused
# port     = domain,953
# protocol = udp
# logpath  = /var/log/named/security.log

# IMPORTANT: see filter.d/named-refused for instructions to enable logging
# This jail blocks TCP traffic for DNS requests.


port     = domain,953
logpath  = /var/log/named/security.log


port     = 53
action   = %(banaction)s[name=%(__name__)s-tcp, port="%(port)s", protocol="tcp", chain="%(chain)s", actname=%(banaction)s-tcp]
           %(banaction)s[name=%(__name__)s-udp, port="%(port)s", protocol="udp", chain="%(chain)s", actname=%(banaction)s-udp]
logpath = /var/log/nsd.log

# Miscellaneous


port     = 5060,5061
action   = %(banaction)s[name=%(__name__)s-tcp, port="%(port)s", protocol="tcp", chain="%(chain)s", actname=%(banaction)s-tcp]
           %(banaction)s[name=%(__name__)s-udp, port="%(port)s", protocol="udp", chain="%(chain)s", actname=%(banaction)s-udp]
           %(mta)s-whois[name=%(__name__)s, dest="%(destemail)s"]
logpath  = /var/log/asterisk/messages
maxretry = 10


port     = 5060,5061
action   = %(banaction)s[name=%(__name__)s-tcp, port="%(port)s", protocol="tcp", chain="%(chain)s", actname=%(banaction)s-tcp]
           %(banaction)s[name=%(__name__)s-udp, port="%(port)s", protocol="udp", chain="%(chain)s", actname=%(banaction)s-udp]
           %(mta)s-whois[name=%(__name__)s, dest="%(destemail)s"]
logpath  = /var/log/freeswitch.log
maxretry = 10

# To log wrong MySQL access attempts add to /etc/my.cnf in [mysqld] or
# equivalent section:
# log-warning = 2
# for syslog (daemon facility)
# [mysqld_safe]
# syslog
# for own logfile
# [mysqld]
# log-error=/var/log/mysqld.log

port     = 3306
logpath  = %(mysql_log)s
maxretry = 5

# Jail for more extended banning of persistent abusers
# !!! WARNING !!!
#   Make sure that your loglevel specified in fail2ban.conf/.local
#   is not at DEBUG level -- which might then cause fail2ban to fall into
#   an infinite loop constantly feeding itself with non-informative lines

logpath  = /var/log/fail2ban.log
port     = all
protocol = all
bantime  = 604800  ; 1 week
findtime = 86400   ; 1 day
maxretry = 5

# Generic filter for PAM. Has to be used with action which bans all
# ports such as iptables-allports, shorewall

# pam-generic filter can be customized to monitor specific subset of 'tty's
banaction = iptables-allports
logpath  = %(syslog_authpriv)s


banaction = iptables-multiport-log
logpath   = %(syslog_daemon)s
maxretry  = 2

# stunnel - need to set port for this

logpath = /var/log/stunnel4/stunnel.log


port    = 5222
logpath = /var/log/ejabberd/ejabberd.log


logpath = /opt/cstrike/logs/L[0-9]*.log
# Firewall: http://www.cstrike-planet.com/faq/6
tcpport = 27030,27031,27032,27033,27034,27035,27036,27037,27038,27039
udpport = 1200,27000,27001,27002,27003,27004,27005,27006,27007,27008,27009,27010,27011,27012,27013,27014,27015
action  = %(banaction)s[name=%(__name__)s-tcp, port="%(tcpport)s", protocol="tcp", chain="%(chain)s", actname=%(banaction)s-tcp]
           %(banaction)s[name=%(__name__)s-udp, port="%(udpport)s", protocol="udp", chain="%(chain)s", actname=%(banaction)s-udp]

# consider low maxretry and a long bantime
# nobody except your own Nagios server should ever probe nrpe

enabled  = false
logpath  = %(syslog_daemon)s     ; nrpe.cfg may define a different log_facility
maxretry = 1

# see "oracleims" filter file for configuration requirement for Oracle IMS v6 and above
enabled = false
logpath = /opt/sun/comms/messaging64/log/mail.log_current
maxretry = 6
banaction = iptables-allports

enabled = false
logpath = /var/log/directadmin/login.log
port = 2222

enabled  = false
logpath  = /var/lib/portsentry/portsentry.history
maxretry = 1

重启fail2ban即可 systemctl restart fail2ban

本内容同步更新在我的个人博客 「我们都是害虫」 https://ezlost.com 搜索查询关注订阅评论 更加方便快捷.内容转载请注明来源。