How to set temporary IP ban in one command
Hello,
i want to deny an IP 2.2.2.2 using iptables for 15 minutes. This must be one line command, because i want to use it in mod_deflate in this variable: Quote:
Quote:
|
|
if you can't/don't want compile code or have problems with installation of mod_evasive, another option is Fail2Ban, you can manually ban an ip for a pre-configured time (you can have more than one time, or JAILs in fail2ban docs).
|
Quote:
DOSSystemCommand “sudo /sbin/iptables -A INPUT -s %s -j DROP;echo \"iptables -D INPUT -s %s -j DROP\" | at now + 2 hours" |
I second gengisdave's suggestion for fail2ban. Not only does it lay down all the groundwork it also can use ipset which is way better maintenance and performance-wise. Also use the mangle for bit buckets. Save the filter table for stuff that matters.
|
All times are GMT -5. The time now is 01:48 AM. |