From 257a7d8b05bf081ea338132012861cf4d196fee1 Mon Sep 17 00:00:00 2001 From: Denis Chevalier Date: Thu, 6 Aug 2026 13:32:38 +0200 Subject: fix fail2ban config --- etc/fail2ban/jail.d/sshd.conf | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) create mode 100644 etc/fail2ban/jail.d/sshd.conf (limited to 'etc/fail2ban/jail.d/sshd.conf') diff --git a/etc/fail2ban/jail.d/sshd.conf b/etc/fail2ban/jail.d/sshd.conf new file mode 100644 index 0000000..35a73c7 --- /dev/null +++ b/etc/fail2ban/jail.d/sshd.conf @@ -0,0 +1,19 @@ +[DEFAULT] +# Use UFW to execute IP bans +banaction = ufw + +# Read logs directly from systemd journal (required for Arch Linux) +backend = systemd + +# Ignore local traffic +ignoreip = 127.0.0.1/8 ::1 192.168.1.0/24 + +# Ban parameters +findtime = 10m +maxretry = 4 +bantime = 1h + +[sshd] +enabled = true +port = 39901 +mode = normal -- cgit