[DEFAULT] # Use UFW to execute IP bans banaction = ufw # Read logs directly from systemd journal (required for Arch Linux) backend = systemd # Ignore local traffic ignoreip = 127.0.0.1/8 ::1 192.168.1.0/24 # Ban parameters findtime = 10m maxretry = 4 bantime = 1h [sshd] enabled = true port = 22 mode = normal