diff --git a/config/action.d/firewall-cmd-direct-new.conf b/config/action.d/firewall-cmd-direct-new.conf index c151ba48..55681887 100644 --- a/config/action.d/firewall-cmd-direct-new.conf +++ b/config/action.d/firewall-cmd-direct-new.conf @@ -5,6 +5,10 @@ # It uses "firewall-cmd" instead of "iptables". # firewall-cmd is based on the command of version firewalld-0.3.4-1.fc19. +[INCLUDES] + +before = iptables-blocktype.conf + [Definition] actionstart = firewall-cmd --direct --add-chain ipv4 filter fail2ban- @@ -16,6 +20,7 @@ actionstart = firewall-cmd --direct --add-chain ipv4 filter fail2ban- # The better rule would be the following, but firewall-cmd has not implemented this command with firewalld-0.3.3-2.fc19 . # firewall-cmd --direct --flush-chain ipv4 filter fail2ban- # The following is a workaround using a loop to implement the --flush-chain command. +# https://fedorahosted.org/firewalld/ticket/10 actionstop = firewall-cmd --direct --remove-rule ipv4 filter 0 -m state --state NEW -p --dport -j fail2ban- ( IFS='|' ; for r in $( firewall-cmd --direct --get-rules ipv4 filter fail2ban- | tr '\n' '|' ) ; do eval firewall-cmd --direct --remove-rule ipv4 filter fail2ban- $r ; done ) @@ -23,9 +28,9 @@ actionstop = firewall-cmd --direct --remove-rule ipv4 filter 0 -m state actioncheck = firewall-cmd --direct --get-chains ipv4 filter | grep -q 'fail2ban-[ \t]' -actionban = firewall-cmd --direct --add-rule ipv4 filter fail2ban- 0 -s -j DROP +actionban = firewall-cmd --direct --add-rule ipv4 filter fail2ban- 0 -s -j -actionunban = firewall-cmd --direct --remove-rule ipv4 filter fail2ban- 0 -s -j DROP +actionunban = firewall-cmd --direct --remove-rule ipv4 filter fail2ban- 0 -s -j [Init]