Adding TOC

La Drôme Laboratoire 2020-03-24 16:24:09 +01:00
parent 12a932e8e5
commit 9f07821f9d
1 changed files with 18 additions and 2 deletions

@ -1,5 +1,20 @@
Setup Fail2ban will prevent attackers to brute force your vault logins. This is particularly important if your instance is publicaly available. Setup Fail2ban will prevent attackers to brute force your vault logins. This is particularly important if your instance is publicaly available.
## Table of Content
- [Pre-requisite](#pre-requisite)
- [Installation](#installation)
* [Debian / Ubuntu / Raspian](#debian--ubuntu--raspian)
* [Fedora / Centos](#fedora--centos)
* [Synology DSM](#synology-dsm)
- [Setup for web vault](#setup-for-web-vault)
* [Filter](#filter)
* [Jail](#jail)
- [Setup for admin page](#setup-for-admin-page)
* [Filter](#filter-1)
* [Jail](#jail-1)
- [Testing Fail2Ban](#testing-fail2ban)
- [SELinux Problems](#selinux-problems)
## Pre-requisite ## Pre-requisite
- Commands below are using `vi`. The basics can be found [there](https://pc.net/resources/commands/vi). However, you can use whatever text editor you want. - Commands below are using `vi`. The basics can be found [there](https://pc.net/resources/commands/vi). However, you can use whatever text editor you want.
@ -10,6 +25,7 @@ Setup Fail2ban will prevent attackers to brute force your vault logins. This is
```` ````
## Installation ## Installation
### Debian / Ubuntu / Raspian ### Debian / Ubuntu / Raspian
``` ```
sudo apt-get install fail2ban -y sudo apt-get install fail2ban -y
@ -110,9 +126,9 @@ Create and fill the following file
ignoreregex = ignoreregex =
```` ````
If you get the following error message `in fail2ban.log` (CentOS 7, Fail2Ban v0.9.7) If you get the following error message in `fail2ban.log` (CentOS 7, Fail2Ban v0.9.7)
`fail2ban.filter [5291]: ERROR No 'host' group in '^.*Username or password is incorrect\. Try again\. IP: <ADDR>\. Username:.*$'` `fail2ban.filter [5291]: ERROR No 'host' group in '^.*Username or password is incorrect\. Try again\. IP: <ADDR>\. Username:.*$'`
Please Use `<HOST>` instead of `<ADDR>` in ``bitwarden.local` Please Use `<HOST>` instead of `<ADDR>` in `bitwarden.local`
### Jail ### Jail
Create and fill the following file Create and fill the following file