Ahojte mam pod. problem
uz dlhsiu dobu sa trapim s utokmi na ssh, skusal som vselico, zmenit port, vseliake firewall nastavenia, ale utoky sa stale opakuju. Moj posledny firewall vyzera takto
add action=jump chain=forward jump-target=icmp protocol=icmp
add chain=icmp comment="Limits pings ICMP" limit=50/5s,2
add chain=icmp comment="Accept ICMP - INPUT" log-prefix=ICMP
add action=log chain=icmp comment="Log: ICMP" log=yes log-prefix=ICMP
add action=add-src-to-address-list address-list=blocked-addr address-list-timeout=1d chain=input connection-limit=50,32 protocol=tcp
add action=tarpit chain=input connection-limit=3,32 protocol=tcp src-address-list=blocked-addr
add action=jump chain=forward comment="SYN Flood protect" connection-state=new disabled=yes jump-target=SYN-Protect protocol=tcp tcp-flags=syn
add chain=SYN-Protect connection-state=new limit=400,5 protocol=tcp tcp-flags=syn
add action=drop chain=SYN-Protect connection-state=new protocol=tcp tcp-flags=syn
add action=drop chain=input comment="Zahodit ssh neziaducich" dst-port=22 protocol=tcp src-address-list=ssh_blacklist
add action=add-src-to-address-list address-list=ssh_blacklist address-list-timeout=1w3d chain=input connection-state=new dst-port=22 protocol=tcp src-address-list=\
ssh_stage3
add action=add-src-to-address-list address-list=ssh_stage3 address-list-timeout=1m chain=input connection-state=new dst-port=22 protocol=tcp src-address-list=ssh_stage2
add action=add-src-to-address-list address-list=ssh_stage2 address-list-timeout=1m chain=input connection-state=new dst-port=22 protocol=tcp src-address-list=ssh_stage1
add action=add-src-to-address-list address-list=ssh_stage1 address-list-timeout=1m chain=input connection-state=new dst-port=22 protocol=tcp
add action=drop chain=forward comment="drop ssh brute downstream" dst-port=22 protocol=tcp src-address-list=ssh_blacklist
add action=drop chain=forward comment="Neoznacene packety" disabled=yes packet-mark=no-mark
Ale bohuzial za 2 dni pozriem adress list a je tam cca 200 ip bloknutych. viete mi poradit ako to poriesit ?
SSH v ip services ked vypnem tak mi nejde vobec ssh, bohuzial firemny zakaznici potrebuju.
Zmena portu nepomaha, po 2-3 dnoch to zacina opat.
Zatial som zisil len tolko ze to ide z vonku nie z vnutra siete
Za kazdu radu vopred Ďakujem