User Tools

Site Tools


сервис_fail2ban

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
сервис_fail2ban [2024/05/11 10:54]
val [Интеграция fail2ban и snort]
сервис_fail2ban [2024/12/28 11:55] (current)
val [Настройка]
Line 35: Line 35:
 [sshd] [sshd]
 maxretry = 6 maxretry = 6
 +#port = 2222
 #ignoreip = 192.168.X.0/​24 192.168.100+X.0/​24 #ignoreip = 192.168.X.0/​24 192.168.100+X.0/​24
  
Line 97: Line 98:
  
   * [[https://​github.com/​frankiejol/​snortban|frankiejol/​snortban]]   * [[https://​github.com/​frankiejol/​snortban|frankiejol/​snortban]]
 +  * Сервис SNORT [[Сервис SNORT#​Копирование alert_unified2 в syslog]]
  
 <​code>​ <​code>​
Line 199: Line 201:
 #!/bin/sh #!/bin/sh
  
-cat > /root/​firewall.acl <<EOF+cat > /srv/tftp/​firewall.acl <<EOF
 no ip access-list extended ACL_FIREWALL no ip access-list extended ACL_FIREWALL
 ip access-list extended ACL_FIREWALL ip access-list extended ACL_FIREWALL
 EOF EOF
  
-/​root/​cisco-acl-deny.sh >> /root/​firewall.acl+/​root/​cisco-acl-deny.sh >> /srv/tftp/​firewall.acl
  
-cat /​root/​cisco-acl-permit.txt >> /root/​firewall.acl+cat /​root/​cisco-acl-permit.txt >> /srv/tftp/​firewall.acl
  
-/​usr/​bin/​rcp /root/​firewall.acl router:​running-config+#/​usr/​bin/​rcp /srv/tftp/​firewall.acl router:​running-config 
 +#/​usr/​bin/​snmpset -c write -v2c router .1.3.6.1.4.1.9.2.1.53.192.168.X.10 string "​firewall.acl"​
 </​code><​code>​ </​code><​code>​
 # cat /​etc/​fail2ban/​action.d/​cisco-acl.conf # cat /​etc/​fail2ban/​action.d/​cisco-acl.conf
сервис_fail2ban.1715414076.txt.gz · Last modified: 2024/05/11 10:54 by val