35 lines
1.5 KiB
Plaintext
35 lines
1.5 KiB
Plaintext
# /etc/fail2ban/action.d/nftables-forward-allports.conf
|
|
#
|
|
# Bans IPs in the nftables FORWARD hook instead of INPUT.
|
|
#
|
|
# Why FORWARD instead of INPUT:
|
|
# Rootful Podman publishes ports via nftables DNAT rules in PREROUTING.
|
|
# After DNAT, the routing decision sends the packet through FORWARD (not
|
|
# INPUT), so INPUT-based bans never see Podman-destined traffic.
|
|
# FORWARD priority -1 evaluates before the watchtower FORWARD chain (0),
|
|
# so banned WireGuard peer IPs (10.8.0.x) are dropped before the
|
|
# `iifname wg0 accept` rule in the watchtower table.
|
|
#
|
|
# Each jail using this action gets its own per-jail chain and set so that
|
|
# multiple jails can safely coexist without shared-chain lifecycle conflicts.
|
|
|
|
[Definition]
|
|
|
|
actionstart = nft add table inet f2b-table
|
|
nft add chain inet f2b-table f2b-<name>-fwd { type filter hook forward priority -1 \; }
|
|
nft add set inet f2b-table f2b-<name>-set { type ipv4_addr \; flags timeout \; }
|
|
nft add rule inet f2b-table f2b-<name>-fwd ip saddr @f2b-<name>-set drop
|
|
|
|
actionstop = nft flush chain inet f2b-table f2b-<name>-fwd
|
|
nft delete chain inet f2b-table f2b-<name>-fwd
|
|
nft delete set inet f2b-table f2b-<name>-set
|
|
|
|
actioncheck = nft list chain inet f2b-table f2b-<name>-fwd
|
|
|
|
actionban = nft add element inet f2b-table f2b-<name>-set { <ip> timeout <bantime>s }
|
|
|
|
actionunban = nft delete element inet f2b-table f2b-<name>-set { <ip> }
|
|
|
|
[Init]
|
|
name = default
|