YunoHost / packages_old

[not used anymore] YunoHost Debian package sources
http://yunohost.org
8 stars 7 forks source link

fail2ban : don't ban local IP #19

Open julienmalik opened 10 years ago

julienmalik commented 10 years ago

if your ynh instance is behind a router, fail2ban blocks the whole router.

This means that as soon as one user gets banned, everyone is banned.

opi commented 9 years ago

https://github.com/YunoHost/packages/commit/9e7e8d1941992fed9dcb6406cb2ced90c0259347 ?

julienmalik commented 9 years ago

i really badly described the issue... i'm not able to easily reproduce since my ynh is not anymore in my home LAN.

when doing port forwarding on your home router to your ynh server, if all request coming from the internet are loggued as coming from the router, then the fix you mention simply makes fail2ban inactive.

this needs testing

Kloadut commented 9 years ago

In other words: if your server is in a LAN with a router on top, and 6 different people failed to login at the same time, everyone is banned for 30 minutes \o/