|
|
|
[main]
|
|
|
|
includes = ${CMAKE_INSTALL_FULL_SYSCONFDIR}/f2b/conf-enabled
|
|
|
|
pidfile = /var/run/f2b.pid
|
|
|
|
statedir = ${CMAKE_INSTALL_FULL_LOCALSTATEDIR}/lib/f2b
|
|
|
|
; valid destinations: stdout, stderr, syslog, file (logfile option should be set)
|
|
|
|
logdest = syslog
|
|
|
|
loglevel = info
|
|
|
|
logfile = /var/log/f2b.log
|
|
|
|
user = root
|
|
|
|
group = root
|
|
|
|
daemon = yes
|
|
|
|
coredumps = no
|
|
|
|
nice = 0
|
|
|
|
|
|
|
|
[defaults]
|
|
|
|
state = no
|
|
|
|
enabled = yes
|
|
|
|
bantime = 3600
|
|
|
|
findtime = 300
|
|
|
|
expiretime = 14400
|
|
|
|
bantime_extend = 0.2
|
|
|
|
findtime_extend = 0.07
|
|
|
|
banscore = 50
|
|
|
|
backend = exec-ipset:banned
|
|
|
|
|
|
|
|
[csocket]
|
|
|
|
listen = unix:/var/run/f2b.sock
|
|
|
|
;listen = inet:localhost
|
|
|
|
;listen = inet:192.168.1.1
|
|
|
|
;listen = inet:[::1]:12345
|
|
|
|
; auth used only for 'inet' connections
|
|
|
|
; if password not set - it will be generated on each restart, see logs
|
|
|
|
;password = <something-long-enough>
|