Jump to content
  • 0

fail2ban


Feefty

Question


  • Group:  Members
  • Topic Count:  47
  • Topics Per Day:  0.01
  • Content Count:  175
  • Reputation:   14
  • Joined:  11/21/11
  • Last Seen:  

should i use fail2ban? http://www.fail2ban.org/

because last time i used it, some of my players can't login.

Link to comment
Share on other sites

3 answers to this question

Recommended Posts


  • Group:  Members
  • Topic Count:  22
  • Topics Per Day:  0.00
  • Content Count:  1479
  • Reputation:   172
  • Joined:  12/14/11
  • Last Seen:  

well, it's just up to you. just tell you 1 thing.

A, B, C, D, E, F, G are your players. All of them are using the same internet provider: X, which gives dynamic IP.

C got IP no. 1 and had a bad idea that he attacked your server. fail2ban recognized it and ban the IP.

The next day, other's IP restarted. C got IP 2 and do it again to your server and got banned again.

The next day, D got IP 1, and F got IP 2. both of those IP are banned. then, your players would think _______________ <fill in the blank by yourself~>

Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  0
  • Topics Per Day:  0
  • Content Count:  7
  • Reputation:   0
  • Joined:  01/05/12
  • Last Seen:  

Just think of why you need fail2ban, what for ?

Then edit your fail2ban config file to fit it to your server and your needs

fail2ban purpose is generally to limit bruteforce attacks on ssh

if some of your users are still being banned by f2b, then search for why they want to initiate a ssh connection

Link to comment
Share on other sites


  • Group:  Members
  • Topic Count:  3
  • Topics Per Day:  0.00
  • Content Count:  707
  • Reputation:   168
  • Joined:  01/26/12
  • Last Seen:  

Hi Feefty,

Mitsu's explanation is correct. 'fail2ban' is for banning bruteforce/more-than-usual attempts to your SSH/SFTP or any other port/service you may configured it for.; so it doesn't actually do anything for network attacks (DDOS). If you are looking to beef up security for your server, I recommend CSF/LFD; http://configserver.com/cp/csf.html

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Answer this question...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...