Skip to content

Fail2ban ipset choice #3152

Answered by sebres
debashisparial asked this question in Q&A
Discussion options

You must be logged in to vote

There are at least 3 ipset action conf files ... which one to use?

See https://serverfault.com/a/1082704/488604

Also, I came across this repo: fail2ban-ipset , any idea about this?

I don't like the idea for several reasons, most of them described in #2909 and others.
Preventive banning no matter in fail2ban or outside or a ban of large lists for recidive IPs for a long time (or still worse permanently) is not recommended at all, see #2925 (comment) for more info.
Also note that since v.0.11 fail2ban has a new feature bantime.increment which could be used instead.
The bottom line is that neither recidive jail nor persistent banning are expected if you use bantime increment - both are o…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by sebres
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants