diff --git a/docs/f2b.conf.sample b/docs/f2b.conf.sample index bf69900..c63d914 100644 --- a/docs/f2b.conf.sample +++ b/docs/f2b.conf.sample @@ -1,8 +1,9 @@ [main] includes = /etc/f2b/conf.d -logdest = stderr -logfile = /var/log/f2b.log +pidfile = /var/run/f2b.pid +logdest = syslog loglevel = info +logfile = /var/log/f2b.log user = root group = root daemon = yes @@ -15,13 +16,15 @@ load = libf2b_filter_preg.so [backend:exec-ipset] load = libf2b_backend_exec.so -start = /usr/sbin/ipset create hash:ip -stop = /usr/sbin/ipset destroy -ban = /usr/sbin/ipset add -check = /usr/sbin/ipset test -unban = /usr/sbin/ipset del -timeout = 1 +start = /sbin/ipset -! create hash:ip +start = /sbin/iptables -I INPUT -m set --match-set -j DROP +stop = /sbin/iptables -D INPUT -m set --match-set -j DROP +stop = /sbin/ipset -! destroy +ban = /sbin/ipset -! add +check = /sbin/ipset -! test +unban = /sbin/ipset -! del +timeout = 2 [jail:ssh] source = files:/var/log/*.log -filter = preg:filters/preg/ssh +filter = preg:filters/ssh.preg