Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fail2ban config/filter #149

Open
anjandev opened this issue Jul 30, 2020 · 1 comment
Open

fail2ban config/filter #149

anjandev opened this issue Jul 30, 2020 · 1 comment

Comments

@anjandev
Copy link

Hey!

I think it would be helpful to document a fail2ban config/filter so umurmur users can harden their installs.

Cheers!

@aphirst
Copy link

aphirst commented Feb 28, 2021

This would be very useful! I've recently started to harden my server (focusing on sshd) with fail2ban, which has massively reduced the amount of spam in my journal, so I'm now noticing other suspicious activity, such as:

Feb 28 00:04:22 alarm umurmurd[365]: WARN: SSL error: error:00000005:lib(0):func(0):DH lib
Feb 28 00:08:26 alarm umurmurd[365]: WARN: SSL error: error:00000001:lib(0):func(0):reason(1)
Feb 28 00:08:26 alarm umurmurd[365]: WARN: SSL negotiation failed with 178.79.xxx.xxx on port 35758
Feb 28 00:08:32 alarm umurmurd[365]: INFO: Connection closed by peer - [1] @178.79.xxx.xxx:38102
Feb 28 00:08:33 alarm umurmurd[365]: WARN: Msg_networkToMessage: Unsupported message 12420

repeated for many similar IPs and ports for about half an hour every couple of days.

Perhaps it would be more productive to request this over at https://github.com/fail2ban/fail2ban themselves?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants