Joined March 2014
·

Kalle Hyvönen

Espoo, Finland
·
·

Posted to Running rootless fail2ban on debian over 1 year ago

Hey! Thanks for the great article!

How should I formulate the iptables rules for ssh-ddos? I just copied the "$IPTABLES -A F2B -p tcp --dport 22 -m recent --update --seconds 3600 --name fail2ban-ssh -j DROP" rule and changed "fail2ban-ssh" to "fail2ban-ssh-ddos" but I get "2014-03-16 13:52:08,587 fail2ban.actions.action: ERROR echo / > /proc/net/xt_recent/fail2ban-ssh-ddos returned 200" in fail2ban.log when I start fail2ban. Otherwise it seems to work like it should.

Achievements
49 Karma
0 Total ProTip Views