Skip to content

Blocking regardless of findtime #3689

Closed Answered by sebres
hack3rcon asked this question in Q&A
Discussion options

You must be logged in to vote

Just noticed the subject - "Blocking regardless of findtime".
So the emphasis of question seems to be on regardless of findtime.

Well, it is complicated - one can surely set findtime to something large, like findtime = 1y (1 year), but...
Physically it would mean:

  • any IP with a single failure (or attempt count smaller than maxretry) would be hold by fail2ban in a fail-manager list of jail for 1 year, because it'd wait for maxretry attempts from IP, so it'd disappear at the earliest 1 year after last attempt, even if that was a single accidental attempt, let alone some dynamic IP;
  • that would cause that a lot of this "pending" tickets would unnecessarily increase memory usage and bother th…

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
1 reply
@sebres
Comment options

Comment options

You must be logged in to vote
0 replies
Answer selected by sebres
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants