diff options
author | Hendrik Jaeger <root@netwichtig.de> | 2019-08-04 12:50:18 +0200 |
---|---|---|
committer | Hendrik Jaeger <root@netwichtig.de> | 2019-08-04 12:51:40 +0200 |
commit | 06d453739b634978f46a6376e5ac7527ddc0dc16 (patch) | |
tree | 7468421ceecd3498d14b2b6b0ebc37d73787d067 /files/etc | |
parent | 488498bebf122f427c8a408a15765d08c5d85c68 (diff) |
Update firewall setup (iptables, nftables)
Add nftables module
Add nftables snippets to needed modules
Update included modules on leonardo so nftables rules are complete
Fix package names in related modules, and similar errors
Diffstat (limited to 'files/etc')
-rw-r--r-- | files/etc/logcheck/ignore.d.server/local-nftables | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/files/etc/logcheck/ignore.d.server/local-nftables b/files/etc/logcheck/ignore.d.server/local-nftables new file mode 100644 index 0000000..5793c0d --- /dev/null +++ b/files/etc/logcheck/ignore.d.server/local-nftables @@ -0,0 +1 @@ +^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ kernel: \[[[:digit:][:space:].]+\] Bruteforce attack: IN=[[:alnum:]]+ OUT= MAC=[[:digit:]a-f:]+ SRC=[[:digit:]a-f:.]+ DST=[[:digit:]a-f:.]+ LEN=[[:digit:]]+ (TC=[[:digit:]]+ HOPLIMIT=[[:digit:]]+ FLOWLBL=[[:digit:]]+|TOS=0x[[:xdigit:]]+ PREC=0x[[:xdigit:]]+ TTL=[[:digit:]]+ ID=[[:digit:]]+) (DF )?PROTO=(TCP|UDP) SPT=[[:digit:]]+ DPT=[[:digit:]]+ (WINDOW=[[:digit:]]+ RES=0x00 (CWR ECE )?(SYN|ACK|RST) (PSH )?(FIN )??URGP=[[:digit:]]+|LEN=[[:digit:]]+)$ |