Always applied in the Linux block, no prompt, idempotent: - install_fail2ban: fail2ban + nftables, etc/fail2ban/jail.d/local.conf. sshd jail reads the journal (backend systemd, works with or without auth.log) and bans the offender on every port, so the SSH port is irrelevant: the previous server's jail banned 22 while sshd listened on 337. 5 failures / 10 min / 1 h. Loopback + RFC1918 never banned. - install_unattended_upgrades: package + 20auto-upgrades (the file dpkg-reconfigure writes, without the prompt). - harden_sshd: sshd_config.d/20-hardening.conf (PermitRootLogin no, MaxAuthTries 3, LoginGraceTime 20), sshd -t gated: a rejected file is removed and the install continues with a warning. Auth methods, port and user lists untouched. Docs: README table + step 13 + packages, CLAUDE.md layout.
21 lines
852 B
Plaintext
21 lines
852 B
Plaintext
# fail2ban local settings, deployed by install.sh. Debian's defaults-debian.conf
|
|
# enables the sshd jail; this file decides how it bans.
|
|
[DEFAULT]
|
|
# Never ban loopback or the private LAN ranges: five typos from the LAN must not
|
|
# lock the admin out for an hour. Trade-off: a compromised LAN host is never banned.
|
|
ignoreip = 127.0.0.1/8 ::1 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16
|
|
bantime = 1h
|
|
findtime = 10m
|
|
maxretry = 5
|
|
banaction = nftables
|
|
banaction_allports = nftables[type=allports]
|
|
|
|
[sshd]
|
|
enabled = true
|
|
# Read the journal directly: works with or without /var/log/auth.log (rsyslog).
|
|
backend = systemd
|
|
journalmatch = _SYSTEMD_UNIT=ssh.service + _COMM=sshd
|
|
# Ban the offender on every port, so the port sshd listens on is irrelevant. The
|
|
# previous server's jail banned port 22 only while sshd listened on 337.
|
|
banaction = %(banaction_allports)s
|