Changes

From SME Server
Jump to navigationJump to search
462 bytes added ,  21:25, 30 July 2022
m
Line 26: Line 26:     
==Koozali SME v9/v10==
 
==Koozali SME v9/v10==
 +
 
{{#smeversion: smeserver-fail2ban}}
 
{{#smeversion: smeserver-fail2ban}}
   −
== Installation sme9 / sme10==
+
== Installation Koozali SME==
Configure EPEL's repository:
+
<tabs container><tab name="For SME 10">
 
+
  yum --enablerepo=smecontribs install smeserver-fail2ban
<onlyinclude>{{#ifeq:{{{transcludesection|epel9}}}|epel9|
+
</tab><tab name="For SME 9">
For SME 9.x,
  −
  /sbin/e-smith/db yum_repositories set epel repository \
  −
Name 'Epel - EL6' \
  −
BaseUrl 'http://download.fedoraproject.org/pub/epel/6/$basearch' \
  −
MirrorList 'http://mirrors.fedoraproject.org/mirrorlist?repo=epel-6&arch=$basearch' \
  −
EnableGroups no \
  −
GPGCheck yes \
  −
GPGKey http://dl.fedoraproject.org/pub/epel/RPM-GPG-KEY-EPEL \
  −
Visible no \
  −
status disabled
  −
}}</onlyinclude>
  −
 
  −
signal-event yum-modify
     −
*install the rpms
+
* install the rpms
 
  −
yum --enablerepo=smecontribs --enablerepo=epel install smeserver-fail2ban
      +
yum --enablerepo=smecontribs install smeserver-fail2ban
    
* Apply the needed configuration:
 
* Apply the needed configuration:
Line 61: Line 48:  
  db configuration setprop masq status enabled
 
  db configuration setprop masq status enabled
 
  signal-event post-upgrade; signal-event reboot
 
  signal-event post-upgrade; signal-event reboot
      
{{warning box| Failing to run either of these command will completely lock network access next time iptables rules are reloaded}}
 
{{warning box| Failing to run either of these command will completely lock network access next time iptables rules are reloaded}}
 
{{warning box| The masq service must be enabled for fail2Ban to work correctly. If you disable it, Fail2ban won't ban anything}}
 
{{warning box| The masq service must be enabled for fail2Ban to work correctly. If you disable it, Fail2ban won't ban anything}}
 +
</tab>
 +
</tabs>
 +
{{warning box| Starting SME10 and smeserver-fail2ban 0.1.18-29, manual change of configuration is included in core backup, if you use .local files in  the folders action.d/                fail2ban.d/        filter.d/        jail.d/. Any change to rpm owned .conf file is not added in core backup. Use the .local files to override the conf file instead and it will be in the backup. See http://www.fail2ban.org/wiki/index.php/MANUAL_0_8#Configuration.}}
    
== Disable SME Feature AutoBlock SME 9 or greater ==
 
== Disable SME Feature AutoBlock SME 9 or greater ==
Line 281: Line 270:  
           smeserver-sendmail[name="Recidive",dest=root]
 
           smeserver-sendmail[name="Recidive",dest=root]
    +
====Custom local filters====
 +
 +
You can add your custom rules by adding a filtername.local file in /etc/fail2ban/filters.d/
 +
wget https://bugs.koozali.org/attachment.cgi?id=6229 -O /etc/fail2ban/filters.d/apache-badbots.local
 +
 +
would be an example of local bad bots rules, be careful to test for your personal case. Some advanced rules could create a lot of false positive and lock out your users.
    
== Uninstall ==
 
== Uninstall ==
Line 409: Line 404:  
Below is an overview of the current issues for this contrib:{{#bugzilla:columns=id,product,version,status,summary|sort=id|order=desc|component=smeserver-fail2ban|noresultsmessage=No open bugs found.}}  
 
Below is an overview of the current issues for this contrib:{{#bugzilla:columns=id,product,version,status,summary|sort=id|order=desc|component=smeserver-fail2ban|noresultsmessage=No open bugs found.}}  
   −
===Changelog===
+
==Changelog==
 
Only released version in smecontrib are listed here.
 
Only released version in smecontrib are listed here.
  
3,054

edits

Navigation menu