|
If Shorewall works the same as iptables, existing connections are
ESTABLISHED rather than NEW so won't be terminated. Personally I'd
remove all selectors on the packet state or cstate so the firewall
acts on all packets. Otherwise you need to add the Shorewall
equivalent of ESTABLISHED and RELATED and there is no point in
adding all possible state options. It is easier to remove the
state/cstate selector. Again, but not knowing Shorewall, I am surprised there is only one blocking chain for f2b. This means, conceptually, one jail can unblock another jail's bans which is not good if both jails are blocking the same IP for different reasons. On 28/11/2018 09:10, Koenraad Lelong
wrote:
|
_______________________________________________ Fail2ban-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/fail2ban-users
