fail2ban防止暴力破解python
1)下载安装包github
wget https://github.com/fail2ban/fail2ban/archive/0.8.14.tar.gz && tar -xvzf 0.8.14.tar.gz
2)解压后查看说明bash
cd fail2ban-0.8.12 cat README.md
3)检查环境ssh
[root@localhost ~]# python -V Python 2.7.5 [root@localhost ~]# uname -r 3.10.0-693.el7.x86_64
4)安装tcp
cd fail2ban-0.8.12 python setup.py install
5)生成服务启动脚本并开机自启:ide
cp files/redhat-initd /etc/init.d/fail2ban /sbin/chkconfig fail2ban on
6)修改配置 /etc/fail2ban/jail.conf 【enabled = true】测试
[ssh-iptables] # 是否开启 enabled = true # 过滤规则 filter = sshd # 动做 action = iptables[name=SSH, port=ssh, protocol=tcp] # 日志文件的路径 logpath = /var/log/secure # 匹配到的阈值(次数) maxretry = 3
7)启动日志
/etc/init.d/fail2ban start
8)测试code
ssh 192.168.10.123
[root@localhost log]# ssh 192.168.10.194 ssh: connect to host 192.168.10.194 port 22: Connection refused