This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision | ||
сервис_fail2ban [2024/05/11 15:47] val [Интеграция fail2ban и snort] |
сервис_fail2ban [2024/12/28 11:55] (current) val [Настройка] |
||
---|---|---|---|
Line 35: | Line 35: | ||
[sshd] | [sshd] | ||
maxretry = 6 | maxretry = 6 | ||
+ | #port = 2222 | ||
#ignoreip = 192.168.X.0/24 192.168.100+X.0/24 | #ignoreip = 192.168.X.0/24 192.168.100+X.0/24 | ||
Line 200: | Line 201: | ||
#!/bin/sh | #!/bin/sh | ||
- | cat > /root/firewall.acl <<EOF | + | cat > /srv/tftp/firewall.acl <<EOF |
no ip access-list extended ACL_FIREWALL | no ip access-list extended ACL_FIREWALL | ||
ip access-list extended ACL_FIREWALL | ip access-list extended ACL_FIREWALL | ||
EOF | EOF | ||
- | /root/cisco-acl-deny.sh >> /root/firewall.acl | + | /root/cisco-acl-deny.sh >> /srv/tftp/firewall.acl |
- | cat /root/cisco-acl-permit.txt >> /root/firewall.acl | + | cat /root/cisco-acl-permit.txt >> /srv/tftp/firewall.acl |
- | /usr/bin/rcp /root/firewall.acl router:running-config | + | #/usr/bin/rcp /srv/tftp/firewall.acl router:running-config |
+ | #/usr/bin/snmpset -c write -v2c router .1.3.6.1.4.1.9.2.1.53.192.168.X.10 string "firewall.acl" | ||
</code><code> | </code><code> | ||
# cat /etc/fail2ban/action.d/cisco-acl.conf | # cat /etc/fail2ban/action.d/cisco-acl.conf |