This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision Next revision Both sides next revision | ||
сервис_fail2ban [2021/07/09 14:34] val [Интеграция fail2ban и cisco log] |
сервис_fail2ban [2022/03/15 13:08] val [Интеграция fail2ban и snort] |
||
---|---|---|---|
Line 8: | Line 8: | ||
<code> | <code> | ||
+ | debian11# apt install iptables | ||
+ | |||
# apt install fail2ban | # apt install fail2ban | ||
</code> | </code> | ||
Line 54: | Line 56: | ||
===== Интеграция fail2ban и cisco log ===== | ===== Интеграция fail2ban и cisco log ===== | ||
+ | |||
+ | * Резервное копирование конфигурации | ||
+ | |||
<code> | <code> | ||
# cat /etc/fail2ban/jail.d/cisco-change-config.conf | # cat /etc/fail2ban/jail.d/cisco-change-config.conf | ||
Line 91: | Line 96: | ||
bantime = 300 | bantime = 300 | ||
filter = snort_filter | filter = snort_filter | ||
- | maxretry = 1 | + | maxretry = 3 |
logpath = /var/log/auth.log | logpath = /var/log/auth.log | ||
#action = mail-admin | #action = mail-admin | ||
Line 151: | Line 156: | ||
<code> | <code> | ||
+ | server# rsh router show access-lists | ||
+ | </code><code> | ||
# cat /root/cisco-acl-deny.sh | # cat /root/cisco-acl-deny.sh | ||
</code><code> | </code><code> | ||
Line 170: | Line 177: | ||
permit udp any any | permit udp any any | ||
permit tcp any any established | permit tcp any any established | ||
- | deny ip any any log | + | deny ip any any ! log |
end | end | ||
</code><code> | </code><code> |