๐ง Linux Fail2Ban ่้ฒ็ซ็ๆดๅ้ฒ้ๆ็จ:ๅฐ้ๆกๆ IP ๅ จๆป็ฅ
ๅจ้ๆพ็ถฒ่ทฏ็ฐๅขไธญ,Linux ไผบๆๅจๅธธ้ญๅๆดๅ็ปๅ ฅ่ๆๆๆปๆ。Fail2Ban ๅฏ่ชๅๅๆๆฅ่ช、ๅฐ้ๆกๆ IP,ๆญ้ firewalld ๆ iptables,่ฝๆๆ้ฒๆญข SSH、HTTP、FTP ็ญๆๅ่ขซๆดๅ็ ด่งฃ。ๆฌๆๆไฝ ๅพๅฎ่ฃ、่จญๅฎๅฐ้ฒ้้ฒ็ฆฆๆดๅ็ๅฎๆดๅฏฆไฝ。
๐ ไธ、Fail2Ban ๆฆๅฟต่้ไฝๅ็
- ๆ ธๅฟๅ็:้้ๅๆๆฅ่ช(ๅฆ /var/log/secure),ๅตๆธฌ้่คๅคฑๆ็ปๅ ฅ่ก็บ。
- ๅฐ้ๆฉๅถ:่ชๅๅผๅซ้ฒ็ซ็(firewalld / iptables)ๅฐ้ไพๆบ IP。
- ๆดๅ็ฏๅ:SSH、vsftpd、Postfix、nginx、Apache、Proxmox ็ๅฏๅฅ็จ。
⚙️ ไบ、ๅฎ่ฃ Fail2Ban
# Rocky / CentOS
sudo dnf install fail2ban -y
# Ubuntu / Debian
sudo apt install fail2ban -y
ๅๅไธฆ่จญๅฎ้ๆฉ่ชๅๅ็จ:
sudo systemctl enable fail2ban
sudo systemctl start fail2ban
sudo systemctl status fail2ban
active (running),ไปฃ่กจๆๅๅๅๆๅ。
๐งฉ ไธ、่จญๅฎ SSH ้ฒๆดๅ็ปๅ ฅไฟ่ญท
ๅปบ็ซ่ฆๅฏซ่จญๅฎๆช:
sudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local
็ทจ่ผฏ /etc/fail2ban/jail.local:
[sshd]
enabled = true
port = ssh
logpath = /var/log/secure
maxretry = 3
bantime = 600
backend = systemd
ๅฅ็จ่จญๅฎ:
sudo systemctl restart fail2ban
๐งฑ ๅ、ๆดๅ firewalld ๅฐ้่ฆๅ
Fail2Ban ๆ่ชๅๅปบ็ซ zone f2b-sshd,ๅฏ็จไปฅไธๆไปคๆชขๆฅ:
sudo firewall-cmd --info-zone=f2b-sshd
sudo firewall-cmd --list-all-zones | grep f2b
ๆฅ็็ฎๅ่ขซๅฐ้ IP:
sudo fail2ban-client status sshd
่งฃ้คๅฐ้(ไพๅฆ่งฃ้ค 192.168.1.50):
sudo fail2ban-client set sshd unbanip 192.168.1.50
๐ ไบ、ๆฅ่ช่็ๆ ็ฃๆง
# ๆฅ็ Fail2Ban ็ธฝ็ๆ
sudo fail2ban-client status
# ๆฅ็ๅ jail ๅฐ้็ด้
sudo fail2ban-client status sshd
# ็ฃๆงๅณๆๅฐ้
sudo tail -f /var/log/fail2ban.log
๐ง ๅ ญ、้ฒ้ๆ็จ:่ช่จๅค้้ฒ็ฆฆ
- ็ตๅ nginx ๆ apache ๆฅ่ช,ๅฐ้็นๅฎ่ทฏๅพ็ๆปๆ。
- ้้
recidivejail ็ดฏ็ฉๅฐ้ๅคๆฌก้็ฏ IP。 - ๆญ้ systemd ๅฎๆๆธ ็่็ด้。
[recidive]
enabled = true
filter = recidive
logpath = /var/log/fail2ban.log
bantime = 86400
findtime = 3600
๐ ไธ、็ต่ช
้้ Fail2Ban ๆญ้ ้ฒ็ซ็,ๅฏ่ชๅๅตๆธฌไธฆๅฐ้ๆกๆ็ปๅ ฅไพๆบ,ๅคงๅน ๆๅไผบๆๅจๅฎๅ จๆง。ๅปบ่ญฐๅๆญ้ GoAccess ๆ rsyslog ๅๆต้่็ฐๅธธๅๆ,ๅฝขๆๅฎๆดๅฎๅ จ็ฃๆง้。
๐ ๅปถไผธ้ฑ่ฎ
- ๐ง Linux Proxy Server ๆต้่จ้่ GoAccess ่ฆ่ฆบๅๅๆ
- ๐ง Linux systemd ๆทฑๅ ฅ่งฃๆ่ๅๅๆต็จ็ฎก็
- ๐ง Linux ้ฒ็ซ็่ Fail2Ban ่ชๅๅไฟ่ญทๅฏฆๆฐ
— WWFandy・็ณป็ตฑ่็ถฒ่ทฏ็ญ่จ
ๆฒๆ็่จ:
ๅผต่ฒผ็่จ