Hi

I have a lot of IP ranges blocked in /etc/hosts.deny, but I've noticed
fail2ban generating what I think is unnecessary noise for refused
connections from within those ranges. In other words, if an IP address
is already blocked by hosts.deny, I don't see why fail2ban needs to
jail it too.

Is there any reason to keep the line

  ^refused connect from \S+ \(<HOST>\)

in 'filter.d/sshd.conf'?

Thanks
Adam



_______________________________________________
Fail2ban-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/fail2ban-users

Reply via email to