Files
watchtower-observability-stack/ansible/roles/fail2ban/files/action.d/nftables-forward-allports.conf
T

35 lines
1.5 KiB
Plaintext

# /etc/fail2ban/action.d/nftables-forward-allports.conf
#
# Bans IPs in the nftables FORWARD hook instead of INPUT.
#
# Why FORWARD instead of INPUT:
# Rootful Podman publishes ports via nftables DNAT rules in PREROUTING.
# After DNAT, the routing decision sends the packet through FORWARD (not
# INPUT), so INPUT-based bans never see Podman-destined traffic.
# FORWARD priority -1 evaluates before the watchtower FORWARD chain (0),
# so banned WireGuard peer IPs (10.8.0.x) are dropped before the
# `iifname wg0 accept` rule in the watchtower table.
#
# Each jail using this action gets its own per-jail chain and set so that
# multiple jails can safely coexist without shared-chain lifecycle conflicts.
[Definition]
actionstart = nft add table inet f2b-table
nft add chain inet f2b-table f2b-<name>-fwd { type filter hook forward priority -1 \; }
nft add set inet f2b-table f2b-<name>-set { type ipv4_addr \; flags timeout \; }
nft add rule inet f2b-table f2b-<name>-fwd ip saddr @f2b-<name>-set drop
actionstop = nft flush chain inet f2b-table f2b-<name>-fwd
nft delete chain inet f2b-table f2b-<name>-fwd
nft delete set inet f2b-table f2b-<name>-set
actioncheck = nft list chain inet f2b-table f2b-<name>-fwd
actionban = nft add element inet f2b-table f2b-<name>-set { <ip> timeout <bantime>s }
actionunban = nft delete element inet f2b-table f2b-<name>-set { <ip> }
[Init]
name = default