Advertisement
Guest User

Untitled

a guest
Jul 19th, 2019
149
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.47 KB | None | 0 0
  1. 2019-07-19 14:18:20 ERROR: COMMAND_FAILED: Direct: '/usr/sbin/iptables-restore -w -n' failed: iptables-restore v1.4.21: Set fail2ban-ssh doesn't exist.
  2.  
  3. Error occurred at line: 2
  4. Try `iptables-restore -h' or 'iptables-restore --help' for more information.
  5.  
  6. firewalld[703]: WARNING: '/usr/sbin/iptables-restore --wait=2 -n' failed: iptables-restore v1.4.21: Set fail2ban-sshd doesn't exist.
  7.  
  8. Error occurred at line: 2
  9. Try 'iptables-restore -h' or 'iptables-restore --help' for more information.
  10. firewalld[703]: ERROR: COMMAND_FAILED
  11.  
  12. [DEFAULT]
  13. ignoreip = 127.0.0.0/8
  14. bantime = 86400
  15. findtime = 86400
  16. maxretry = 5
  17.  
  18. # Override /etc/fail2ban/jail.d/00-firewalld.conf:
  19. banaction = firewallcmd-ipset
  20.  
  21. [sshd]
  22. enabled = true
  23.  
  24. [ssh]
  25. enabled = true
  26. filter = sshd
  27. action = %(action_)s
  28. logpath = /var/log/secure
  29. maxretry = 5
  30.  
  31. sudo yum install firewalld
  32. sudo systemctl start firewalld
  33. sudo firewall-cmd --permanent --add-service=ssh
  34. sudo firewall-cmd --permanent --add-service=http
  35. sudo firewall-cmd --permanent --add-service=https
  36. sudo firewall-cmd --permanent --remove-service=smtp
  37. sudo systemctl enable firewalld
  38.  
  39. # firewall-cmd --direct --get-all-rules
  40.  
  41. ipv4 filter INPUT 0 -p tcp -m multiport --dports ssh -m set --match-set fail2ban-sshd src -j REJECT --reject-with icmp-port-unreachable
  42. ipv4 filter INPUT 0 -p tcp -m multiport --dports 0:65535 -m set --match-set fail2ban-ssh src -j REJECT --reject-with icmp-port-unreachable
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement