Skip to content
GitLab
Menu
Projects
Groups
Snippets
Help
Help
Support
Community forum
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in
Toggle navigation
Menu
Open sidebar
LQDN Adminsys
piops-roles
security-lqdn
Commits
ae7eb3eb
Commit
ae7eb3eb
authored
Nov 17, 2021
by
nono
💻
Browse files
Ajout des filtres Fail2Ban pour Nextcloud
parent
43d20a00
Changes
3
Hide whitespace changes
Inline
Side-by-side
tasks/fail2ban.yml
View file @
ae7eb3eb
...
...
@@ -24,7 +24,7 @@
notify
:
-
Relance de fail2ban
-
name
:
Installation des filtres et prison
en plus
-
name
:
Installation des filtres et prison
Keycloak
block
:
-
name
:
Filtres keycloak
template
:
...
...
@@ -44,5 +44,28 @@
group
:
root
mode
:
0644
notify
:
-
Relance de fail2ban
-
Relance de fail2ban
when
:
ansible_facts["nodename"] == "keycloak"
-
name
:
Installation des filtres et prison Nextcloud
block
:
-
name
:
Filtres Nextcloud
template
:
src
:
fail2ban/filter.nextcloud.conf
dest
:
/etc/fail2ban/filter.d/nextcloud.conf
owner
:
root
group
:
root
mode
:
0644
notify
:
-
Relance de fail2ban
-
name
:
Prisons keycloak
template
:
src
:
fail2ban/jail.nextcloud.conf.j2
dest
:
/etc/fail2ban/jail.d/nextcloud.conf
owner
:
root
group
:
root
mode
:
0644
notify
:
-
Relance de fail2ban
when
:
ansible_facts["nodename"] == "nextcloud"
templates/fail2ban/filer.nextcloud.conf
View file @
ae7eb3eb
[
Definition
]
_
groupsre
= (?:(?:,?\
s
*
"\w+"
:(?:
"[^"
]+
"
|\
w
+))*)
failregex
= ^\{%(
_
groupsre
)
s
,?\
s
*
"remoteAddr"
:
"<HOST>"
%(
_
groupsre
)
s
,?\
s
*
"message"
:
"
Login
failed
:
^\{%(
_
groupsre
)
s
,?\
s
*
"remoteAddr"
:
"<HOST>"
%(
_
groupsre
)
s
,?\
s
*
"message"
:
"
Trusted
domain
error
.
datepattern
= ,?\
s
*
"time"
\
s
*:\
s
*
"%%Y-%%m-%%d[T ]%%H:%%M:%%S(%%z)?"
templates/fail2ban/jail.nextcloud.local.j2
0 → 100644
View file @
ae7eb3eb
[nextcloud]
backend = auto
enabled = true
port = 80,443
protocol = tcp
filter = nextcloud
maxretry = 3
bantime = 86400
findtime = 43200
logpath = /var/ncdata/nextcloud.log
Write
Preview
Supports
Markdown
0%
Try again
or
attach a new file
.
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment