<?xml version="1.0" encoding="koi8-r"?>
<rss version="0.91">
<channel>
    <title>OpenForum RSS: sshguard</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID1/95037.html</link>
    <description>Всем привет настраиваю sshguard под FreeBSD&lt;br&gt;&lt;br&gt;Сталкнулся с делемой...&lt;br&gt;Настраиваю строку по мануалу: http://infobsd.ru/freebsd/sshguard-pf&lt;br&gt;&lt;br&gt;Вобщем PF (фаирвол) невкакую нехочет блокировать ИП атакующего,&lt;br&gt;хотя ИП у него в таблице присутствует.&lt;br&gt;&lt;br&gt;cat /etc/sshguard-black&lt;br&gt;&#091;code&#093;&lt;br&gt;^&#064;^A^&#064;^DГ^Yк╚g┤bW&quot;^M^&#064;^&#064;^&#064;F^&#064;^&#064;^&#064;^A^&#064;^&#064;^&#064;F^&#064;^&#064;^&#064;^&#064;192.168.170.2^&#064;4 ^&#064;^&#064;^&#064;^&#064;^&#064;&lt;br&gt;&#091;/code&#093;&lt;br&gt;&lt;br&gt;pfctl -T show -t sshguard&lt;br&gt;&#091;code&#093;&lt;br&gt;No ALTQ support in kernel&lt;br&gt;ALTQ related functions disabled&lt;br&gt;   192.168.170.2&lt;br&gt;&#091;/code&#093;&lt;br&gt;&lt;br&gt;uname -a&lt;br&gt;&#091;/code&#093;&lt;br&gt;FreeBSD root 6.4-RELEASE FreeBSD 6.4-RELEASE&lt;br&gt;&#091;code&#093;&lt;br&gt;&lt;br&gt;cat /var/log/messages&lt;br&gt;&#091;code&#093;&lt;br&gt;Sep 24 11:25:48 root sshguard&#091;43628&#093;: Started successfully &#091;(a,p,s)=(3, 420, 1200)&#093;, now ready to scan.&lt;br&gt;Sep 24 11:25:48 root sshguard&#091;43628&#093;: Blocking 192.168.170.2:4 for &amp;gt;0secs: 10 danger in 1 attacks over 0 seconds (all: 10d in 1 abuses over 0s).&lt;br&gt;&#091;/code&#093;&lt;br&gt;&lt;br&gt;cat /etc/pf.conf&lt;br&gt;&#091;code&#093;&lt;br&gt;table &amp;lt;sshguard&amp;gt; persist&lt;br&gt;&lt;br&gt;nat on ng0 from &#123; 192.168.170.1/24, 192.168.180.1/24, 192.168.190.1/24 &#125; to any -&amp;gt; ng0&lt;br&gt;nat on rl0 from &#123;</description>

<item>
    <title>sshguard (михалыч)</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID1/95037.html#1</link>
    <pubDate>Tue, 24 Sep 2013 10:33:06 GMT</pubDate>
    <description>&amp;gt; pass in on ng0 proto tcp from &#123; 192.168.170.0/24 &#125;&lt;br&gt;&amp;gt; block in quick on &#123; ng0, rl0, rl1&#125; proto tcp from &amp;lt;sshguard&amp;gt; to any port 8022 label &quot;ssh bruteforce&quot;&lt;br&gt;&lt;br&gt;Поменять местами?&lt;br&gt;</description>
</item>

</channel>
</rss>
