EFW Support

Support => General Support => Topic started by: akehlert on Wednesday 02 December 2020, 09:38:07 pm



Title: Brute Force Attack - Non stop ssh login attempts
Post by: akehlert on Wednesday 02 December 2020, 09:38:07 pm
Brute Force Attack - Non stop ssh login attempts

I am running EFW, lastest up.
I am getting hit by a brute force atatck of constant ssh logins attempts.

How do I automatically block those IP's



Title: Re: Brute Force Attack - Non stop ssh login attempts
Post by: toka on Friday 04 December 2020, 01:20:43 am
EFW unfortunately does not have the ability to automatically block by the rules.
And it would be nice for the parameter of the number of connections from one IP in a certain period of time.


Title: Re: Brute Force Attack - Non stop ssh login attempts
Post by: akehlert on Wednesday 09 December 2020, 07:09:35 pm
Thank you, is there any way to install maybe something like fail2ban to block the attack?


Title: Re: Brute Force Attack - Non stop ssh login attempts
Post by: justme on Friday 19 February 2021, 08:40:11 pm
the free version does not support fail2ban, but it could be installed manually and run using /var/efw/inithooks/start.local at startup, then you can use CUSTOMINPUT to block things


Title: Re: Brute Force Attack - Non stop ssh login attempts
Post by: hadexx on Saturday 17 April 2021, 05:38:58 am
Brute Force Attack - Non stop ssh login attempts

I am running EFW, lastest up.
I am getting hit by a brute force atatck of constant ssh logins attempts.

How do I automatically block those IP's



 if you try to block access only to known IPs or at least only of your country.