post-start-stop.example 471 B

123456
  1. # Blocks all IP which connect to port 22
  2. # BEWARE: this is to be activate ONLY
  3. # IF YOU CHANGED YOUR SSH DEFAULT PORT
  4. $do_action $IPTABLES_INSERT $IT_INPUT -m set --match-set banned_ips src -j DROP
  5. $do_action $IPTABLES_INSERT $IT_INPUT -p tcp --dport 22 -m conntrack --ctstate NEW -m recent --set --name SSH_BLOCK --rsource
  6. $do_action $IPTABLES_INSERT $IT_INPUT -p tcp --dport 22 -m recent --update --hitcount 1 --name SSH_BLOCK --rsource -j SET --add-set banned_ips src