diff options
author | ene <ene@sils.li> | 2023-03-25 13:44:19 +0100 |
---|---|---|
committer | ene <ene@sils.li> | 2023-03-25 13:44:19 +0100 |
commit | d476af8dec9529c593ee334045855df4711cbc7f (patch) | |
tree | 055d3638608bec66546d0e8c593f89993b074b99 | |
parent | Fix(acme): Store certs permanently. (diff) | |
parent | Feat(system/services/fail2ban): Add fail2ban (diff) | |
download | nixos-server-d476af8dec9529c593ee334045855df4711cbc7f.tar.gz nixos-server-d476af8dec9529c593ee334045855df4711cbc7f.zip |
Merge pull request 'Feat(system/services/fail2ban): Add fail2ban' (#23) from server1_fail2ban into server1_develop
CC: #23
-rw-r--r-- | system/services/default.nix | 1 | ||||
-rw-r--r-- | system/services/fail2ban/default.nix | 14 |
2 files changed, 15 insertions, 0 deletions
diff --git a/system/services/default.nix b/system/services/default.nix index f36cb29..5d9e5b6 100644 --- a/system/services/default.nix +++ b/system/services/default.nix @@ -7,5 +7,6 @@ ./nix ./opensshd ./rust-motd + ./fail2ban ]; } diff --git a/system/services/fail2ban/default.nix b/system/services/fail2ban/default.nix new file mode 100644 index 0000000..5b5e9e7 --- /dev/null +++ b/system/services/fail2ban/default.nix @@ -0,0 +1,14 @@ +# vim: ts=2 +{...}: { + services.fail2ban = { + enable = true; + maxretry = 2; # ban after 2 failures + bantime-increment = { + enable = true; + rndtime = "8m"; + overalljails = true; + multipliers = "2 4 16 128 256"; + maxtime = "72h"; + }; + }; +} |