From 9221886df69091f07a0feaff6e617749b804b452 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Tue, 11 Dec 2012 23:58:48 +1100 Subject: [PATCH] more documentation and optimisations/fixes based on testing --- config/action.d/iptables-ipset-proto4.conf | 19 ++++++++++++++++--- config/action.d/iptables-ipset-proto6.conf | 19 ++++++++++++++++--- 2 files changed, 32 insertions(+), 6 deletions(-) diff --git a/config/action.d/iptables-ipset-proto4.conf b/config/action.d/iptables-ipset-proto4.conf index 21401ad7..f7d03f67 100644 --- a/config/action.d/iptables-ipset-proto4.conf +++ b/config/action.d/iptables-ipset-proto4.conf @@ -2,8 +2,21 @@ # # Author: Daniel Black # -# Tested against protocol 4 (ipset v4.2) +# This is for ipset protocol 4 (ipset v4.2). If you have a later version +# of ipset try to use the iptables-ipset-proto6.conf as it does some things +# nicer. +# +# This requires the program ipset which is normally in package called ipset. # +# IPset was a feature introduced in the linux kernel 2.6.39 and 3.0.0 kernels. +# +# If you are running on an older kernel you make need to patch in external +# modules. +# +# On Debian machines this can be done with: +# +# apt-get install ipset xtables-addons-source +# module-assistant auto-install xtables-addons [Definition] @@ -28,7 +41,7 @@ actionstop = iptables -D INPUT -p -m multiport --dports -m set # Tags: IP address # Values: CMD # -actionban = ipset --test fail2ban- || ipset --add fail2ban- -exist +actionban = ipset --test fail2ban- || ipset --add fail2ban- # Option: actionunban # Notes.: command executed when unbanning an IP. Take care that the @@ -40,7 +53,7 @@ actionunban = ipset --test fail2ban- && ipset --del fail2ban- < [Init] -# Defaut name of the chain +# Defaut name of the ipset # name = default diff --git a/config/action.d/iptables-ipset-proto6.conf b/config/action.d/iptables-ipset-proto6.conf index 084f8738..3352d63d 100644 --- a/config/action.d/iptables-ipset-proto6.conf +++ b/config/action.d/iptables-ipset-proto6.conf @@ -2,8 +2,21 @@ # # Author: Daniel Black # -# Tested against protocol 6 (ipset v6.14) +# This is for ipset protocol 6 (and hopefully later) (ipset v6.14). +# Use ipset -V to see the protocol and version. Version 4 should use +# iptables-ipset-proto4.conf. # +# This requires the program ipset which is normally in package called ipset. +# +# IPset was a feature introduced in the linux kernel 2.6.39 and 3.0.0 kernels. +# +# If you are running on an older kernel you make need to patch in external +# modules. +# +# On Debian machines this can be done with: +# +# apt-get install ipset xtables-addons-source +# module-assistant auto-install xtables-addons [Definition] @@ -28,7 +41,7 @@ actionstop = iptables -D INPUT -p -m multiport --dports -m set # Tags: IP address # Values: CMD # -actionban = ipset add fail2ban- -exist +actionban = ipset add fail2ban- timeout -exist # Option: actionunban # Notes.: command executed when unbanning an IP. Take care that the @@ -40,7 +53,7 @@ actionunban = ipset del fail2ban- -exist [Init] -# Defaut name of the chain +# Defaut name of the ipset # name = default