Paste

Markdown Detected Guest 3 Views Size: 759 bytes Posted on: Sep 4, 26 @ 12:12 PM

[Definition]

failregex = .[UFW BLOCK] IN=. SRC=<HOST> DST=\S+ .DPT=(?P<F-PORT>\d+) .fatal: .*for <HOST>

Private/link-local ranges + this host's own public IP + multicast, so

internal traffic and normal multicast/mDNS noise don't get banned.

ignoreregex = SRC=(10.|172.1[6-9].|172.2[0-9].|172.3[0-1].|192.168.|fe80:). DST=(178.62.105.126|224.0.0.). PROTO=(2|UDP)(\s+|. DPT=(1900|3702|5353|5355) LEN=\d\s+)$ SRC=(10.|172.(1[6-9]|2[0-9]|3[0-1]).|192.168.)

[Init]

Scope journal scanning to kernel-sourced (netfilter/UFW) log lines for

performance. If your "fatal: ... for <HOST>" line comes from a different

journal unit, split this into two jails/filters instead of one.

journalmatch = _TRANSPORT=kernel

Raw Paste

Comments 0
Login to post a comment.
  • No comments yet. Be the first.
Login to post a comment. Login or Register
We use cookies. To comply with GDPR in the EU and the UK we have to show you these.

We use cookies and similar technologies to keep this website functional (including spam protection via Google reCAPTCHA or Cloudflare Turnstile), and — with your consent — to measure usage and show ads. See Privacy.