shell fail2ban配置ssh防爆力破解

 yum -y install epel-release
 yum -y install fail2ban
配置fail2ban并实现防暴力破解
vim /etc/fail2ban/jail.conf
[DEFAULT]
# 用于指定哪些地址ip可以忽略 fail2ban 防御,以空格间隔。(根据自己具体地址写)
ignoreip = 127.0.0.1/20
# 客户端主机被禁止的时长(默认单位为秒)
bantime  = 3600
# 过滤的时长(秒)
findtime  = 600
# 匹配到的阈值(次数)
maxretry = 3
[ssh-iptables]
# 是否开启
enabled  = true
# 过滤规则
filter   = sshd
# 动作
action   = iptables[name=SSH, port=ssh, protocol=tcp]
# 日志文件的路径
logpath  = /var/log/secure

启动fail2ban

systemctl start fail2ban

猜你喜欢

转载自blog.csdn.net/lq_hello/article/details/106222678
今日推荐