1
# Fail2Ban configuration file
3
# Author: Michael Gebetsroither
5
# This is for blocking whole hosts through blackhole routes.
8
# - Works on all kernel versions and as no compatibility problems (back to debian lenny and WAY further).
9
# - It's FAST for very large numbers of blocked ips.
10
# - It's FAST because it Blocks traffic before it enters common iptables chains used for filtering.
11
# - It's per host, ideal as action against ssh password bruteforcing to block further attack attempts.
12
# - No additional software required beside iproute/iproute2
15
# - Blocking is per IP and NOT per service, but ideal as action against ssh password bruteforcing hosts
18
actionban = ip route add <blocktype> <ip>
19
actionunban = ip route del <blocktype> <ip>
22
# Note: Type can be blackhole, unreachable and prohibit. Unreachable and prohibit correspond to the ICMP reject messages.
24
blocktype = unreachable