Add the ip of the user performing the install to the ignore ip list of fail2ban
This commit is contained in:
parent
df92a10eba
commit
8a06d0aa8b
|
@ -4,7 +4,7 @@
|
|||
# Whitelist our own IP addresses. 127.0.0.1/8 is the default. But our status checks
|
||||
# ping services over the public interface so we should whitelist that address of
|
||||
# ours too. The string is substituted during installation.
|
||||
ignoreip = 127.0.0.1/8 PUBLIC_IP
|
||||
ignoreip = 127.0.0.1/8 PUBLIC_IP REMOTE_IP
|
||||
|
||||
# JAILS
|
||||
|
||||
|
|
|
@ -282,8 +282,12 @@ restart_service resolvconf
|
|||
# ### Fail2Ban Service
|
||||
|
||||
# Configure the Fail2Ban installation to prevent dumb bruce-force attacks against dovecot, postfix and ssh
|
||||
#
|
||||
# We will whitelist our public IP and the IP of the user performing the install
|
||||
IP_ADDRESS_OF_USER=$(pinky -w `logname` | tail -n+2 | tail -n1 | awk '{print $(NF)}')
|
||||
cat conf/fail2ban/jail.local \
|
||||
| sed "s/PUBLIC_IP/$PUBLIC_IP/g" \
|
||||
| sed "s/REMOTE_IP/$IP_ADDRESS_OF_USER/g" \
|
||||
> /etc/fail2ban/jail.local
|
||||
cp conf/fail2ban/dovecotimap.conf /etc/fail2ban/filter.d/dovecotimap.conf
|
||||
|
||||
|
|
Loading…
Reference in New Issue