From c190631f8842b884199354f34f0ad8caf02051a2 Mon Sep 17 00:00:00 2001 From: Danila Vershinin Date: Thu, 5 Oct 2017 18:26:11 +0300 Subject: [PATCH 1/2] New ban action firewallcmd-ipset-allports. Closes #1167 --- ChangeLog | 1 + .../action.d/firewallcmd-ipset-allports.conf | 51 +++++++++++++++++++ 2 files changed, 52 insertions(+) create mode 100644 config/action.d/firewallcmd-ipset-allports.conf diff --git a/ChangeLog b/ChangeLog index 1917f079..1cdb28b7 100644 --- a/ChangeLog +++ b/ChangeLog @@ -47,6 +47,7 @@ releases. * filter.d/kerio.conf - filter extended with new rules (see gh-1455) * filter.d/phpmyadmin-syslog.conf - new filter for phpMyAdmin using syslog for auth logging * filter.d/zoneminder.conf - new filter for ZoneMinder (gh-1376) +* action.d/firewallcmd-ipset-allports.conf - new firewallcmd-ipset-allports action (gh-1167) ver. 0.9.7 (2017/05/11) - awaiting-victory diff --git a/config/action.d/firewallcmd-ipset-allports.conf b/config/action.d/firewallcmd-ipset-allports.conf new file mode 100644 index 00000000..eb940ee0 --- /dev/null +++ b/config/action.d/firewallcmd-ipset-allports.conf @@ -0,0 +1,51 @@ +# Fail2Ban action file for firewall-cmd/ipset +# +# This requires: +# ipset (package: ipset) +# firewall-cmd (package: firewalld) +# +# This is for ipset protocol 6 (and hopefully later) (ipset v6.14). +# Use ipset -V to see the protocol and version. +# +# IPset was a feature introduced in the linux kernel 2.6.39 and 3.0.0 kernels. +# +# If you are running on an older kernel you make need to patch in external +# modules. + +[INCLUDES] + +before = iptables-common.conf + +[Definition] + +actionstart = ipset create fail2ban- hash:ip timeout + firewall-cmd --direct --add-rule ipv4 filter 0 -m set --match-set fail2ban- src -j + +actionstop = firewall-cmd --direct --remove-rule ipv4 filter 0 -m set --match-set fail2ban- src -j + ipset flush fail2ban- + ipset destroy fail2ban- + +actionban = ipset add fail2ban- timeout -exist + +actionunban = ipset del fail2ban- -exist + +[Init] + +# Option: chain +# Notes specifies the iptables chain to which the fail2ban rules should be +# added +# Values: [ STRING ] +# +chain = INPUT_direct + +# Option: bantime +# Notes: specifies the bantime in seconds (handled internally rather than by fail2ban) +# Values: [ NUM ] Default: 600 + +bantime = 600 + + +# DEV NOTES: +# +# Author: Edgar Hoch and Daniel Black +# firewallcmd-new / iptables-ipset-proto6 combined for maximium goodness \ No newline at end of file From 131b94e11e6a1e05655aad31458556ab2529f24d Mon Sep 17 00:00:00 2001 From: sebres Date: Wed, 10 Jan 2018 10:11:11 +0100 Subject: [PATCH 2/2] firewallcmd-ipset-allports: implemented in `action.d/firewallcmd-ipset.conf` now (`action.d/firewallcmd-ipset-allports.conf` removed), usage: banaction = firewallcmd-ipset[actiontype=""] --- .../action.d/firewallcmd-ipset-allports.conf | 51 ------------------- config/action.d/firewallcmd-ipset.conf | 21 +++++++- 2 files changed, 19 insertions(+), 53 deletions(-) delete mode 100644 config/action.d/firewallcmd-ipset-allports.conf diff --git a/config/action.d/firewallcmd-ipset-allports.conf b/config/action.d/firewallcmd-ipset-allports.conf deleted file mode 100644 index eb940ee0..00000000 --- a/config/action.d/firewallcmd-ipset-allports.conf +++ /dev/null @@ -1,51 +0,0 @@ -# Fail2Ban action file for firewall-cmd/ipset -# -# This requires: -# ipset (package: ipset) -# firewall-cmd (package: firewalld) -# -# This is for ipset protocol 6 (and hopefully later) (ipset v6.14). -# Use ipset -V to see the protocol and version. -# -# IPset was a feature introduced in the linux kernel 2.6.39 and 3.0.0 kernels. -# -# If you are running on an older kernel you make need to patch in external -# modules. - -[INCLUDES] - -before = iptables-common.conf - -[Definition] - -actionstart = ipset create fail2ban- hash:ip timeout - firewall-cmd --direct --add-rule ipv4 filter 0 -m set --match-set fail2ban- src -j - -actionstop = firewall-cmd --direct --remove-rule ipv4 filter 0 -m set --match-set fail2ban- src -j - ipset flush fail2ban- - ipset destroy fail2ban- - -actionban = ipset add fail2ban- timeout -exist - -actionunban = ipset del fail2ban- -exist - -[Init] - -# Option: chain -# Notes specifies the iptables chain to which the fail2ban rules should be -# added -# Values: [ STRING ] -# -chain = INPUT_direct - -# Option: bantime -# Notes: specifies the bantime in seconds (handled internally rather than by fail2ban) -# Values: [ NUM ] Default: 600 - -bantime = 600 - - -# DEV NOTES: -# -# Author: Edgar Hoch and Daniel Black -# firewallcmd-new / iptables-ipset-proto6 combined for maximium goodness \ No newline at end of file diff --git a/config/action.d/firewallcmd-ipset.conf b/config/action.d/firewallcmd-ipset.conf index 38b0f3d3..62b6e7c2 100644 --- a/config/action.d/firewallcmd-ipset.conf +++ b/config/action.d/firewallcmd-ipset.conf @@ -19,9 +19,9 @@ before = iptables-common.conf [Definition] actionstart = ipset create fail2ban- hash:ip timeout - firewall-cmd --direct --add-rule ipv4 filter 0 -p -m multiport --dports -m set --match-set fail2ban- src -j + firewall-cmd --direct --add-rule ipv4 filter 0 -m set --match-set fail2ban- src -j -actionstop = firewall-cmd --direct --remove-rule ipv4 filter 0 -p -m multiport --dports -m set --match-set fail2ban- src -j +actionstop = firewall-cmd --direct --remove-rule ipv4 filter 0 -m set --match-set fail2ban- src -j ipset flush fail2ban- ipset destroy fail2ban- @@ -44,6 +44,23 @@ chain = INPUT_direct bantime = 600 +# Option: actiontype +# Notes.: defines additions to the blocking rule +# Values: leave empty to block all attempts from the host +# Default: Value of the multiport +actiontype = + +# Option: allports +# Notes.: default addition to block all ports +# Usage.: use in jail config: banaction = firewallcmd-ipset[actiontype=] +# for all protocols: banaction = firewallcmd-ipset[actiontype=""] +allports = -p + +# Option: multiport +# Notes.: addition to block access only to specific ports +# Usage.: use in jail config: banaction = firewallcmd-ipset[actiontype=] +multiport = -p -m multiport --dports + # DEV NOTES: #