LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 08-31-2012, 06:46 AM   #1
sieuvocmaytinh
LQ Newbie
 
Registered: Aug 2012
Posts: 13

Rep: Reputation: Disabled
fail2ban: How to ban IP connect port 22


I change ssh port to 10000. I don't use port 22 and i want to ban IP which connect to port 22.

I use fail2ban.
 
Old 08-31-2012, 06:56 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
fail2ban bans hosts by reading logs. If the SSH daemon doesn't run on port TCP/22 then it won't generate any log entries for any logins on that port. Hence wanting to do so doesn't make any sense. Should you want to proceed anyway then I suggest you add a firewall logging rule for the port and make fail2ban recognize the log entry. Since the fail2ban source is freely available you shouldn't have any trouble creating the appropriate filter on your own because, with all due respect, I rather spend time on things that do make sense.
 
1 members found this post helpful.
Old 08-31-2012, 06:57 AM   #3
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
if you don't use port 22 you can't connect to it, so I would suggest you just ignore those requests. for fail2ban you'd just need to log those requests with iptables and then track that log with fail2ban, but there seems next to no realistic benefit in this.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to config fail2ban send email to gmail when it ban IP sieuvocmaytinh Linux - Server 3 08-15-2012 10:14 PM
how to get fail2ban to block a single port ? papampi Linux - Security 6 07-26-2012 07:38 AM
[SOLVED] fail2ban does not ban, maybe my regex is wrong? JeanC Linux - Server 2 03-17-2011 10:01 AM
[SOLVED] Fail2Ban failed to ban Attack on Asterisk, Why ? MET Linux - Security 10 05-27-2010 04:08 AM
fail2ban has banned me, but I can still connect? Brandon.Wamboldt Linux - Server 3 05-07-2009 06:51 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 11:00 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration