Submit
Path:
~
/
/
etc
/
fail2ban
/
action.d
/
File Content:
nsupdate.conf
# Fail2Ban configuration file # # Author: Andrew St. Jean # # Use nsupdate to perform dynamic DNS updates on a BIND zone file. # One may want to do this to update a local RBL with banned IP addresses. # # Options # # domain DNS domain that will appear in nsupdate add and delete # commands. # # ttl The time to live (TTL) in seconds of the TXT resource # record. # # rdata Data portion of the TXT resource record. # # nsupdatecmd Full path to the nsupdate command. # # keyfile Full path to TSIG key file used for authentication between # nsupdate and BIND. # # Create an nsupdate.local to set at least the <domain> and <keyfile> # options as they don't have default values. # # The ban and unban commands assume nsupdate will authenticate to the BIND # server using a TSIG key. The full path to the key file must be specified # in the <keyfile> parameter. Use this command to generate your TSIG key. # # dnssec-keygen -a HMAC-MD5 -b 256 -n HOST <key_name> # # Replace <key_name> with some meaningful name. # # This command will generate two files. Specify the .private file in the # <keyfile> option. Note that the .key file must also be present in the same # directory for nsupdate to use the key. # # Don't forget to add the key and appropriate allow-update or update-policy # option to your named.conf file. # [Definition] # Option: actionstart # Notes.: command executed on demand at the first ban (or at the start of Fail2Ban if actionstart_on_demand is set to false). # Values: CMD # actionstart = # Option: actionstop # Notes.: command executed at the stop of jail (or at the end of Fail2Ban) # Values: CMD # actionstop = # Option: actioncheck # Notes.: command executed once before each actionban command # Values: CMD # actioncheck = # Option: actionban # Notes.: command executed when banning an IP. Take care that the # command is executed with Fail2Ban user rights. # Tags: See jail.conf(5) man page # Values: CMD # actionban = echo <ip> | awk -F. '{print "prereq nxrrset "$4"."$3"."$2"."$1".<domain> TXT"; print "update add "$4"."$3"."$2"."$1".<domain> <ttl> IN TXT \"<rdata>\""; print "send"}' | <nsupdatecmd> -k <keyfile> # Option: actionunban # Notes.: command executed when unbanning an IP. Take care that the # command is executed with Fail2Ban user rights. # Tags: See jail.conf(5) man page # Values: CMD # actionunban = echo <ip> | awk -F. '{print "update delete "$4"."$3"."$2"."$1".<domain>"; print "send"}' | <nsupdatecmd> -k <keyfile> [Init] # Option: domain # Notes.: DNS domain that nsupdate will update. # Values: STRING # domain = # Option: ttl # Notes.: time to live (TTL) in seconds of TXT resource record # added by nsupdate. # Values: NUM # ttl = 60 # Option: rdata # Notes.: data portion of the TXT resource record added by nsupdate. # Values: STRING # rdata = Your IP has been banned # Option: nsupdatecmd # Notes.: specifies the full path to the nsupdate program that dynamically # updates BIND zone files. # Values: CMD # nsupdatecmd = /usr/bin/nsupdate # Option: keyfile # Notes.: specifies the full path to the file containing the # TSIG key for communicating with BIND. # Values: STRING # keyfile =
Edit
Rename
Chmod
Delete
FILE
FOLDER
Name
Size
Permission
Action
abuseipdb.conf
3748 bytes
0644
apf.conf
587 bytes
0644
badips.conf
629 bytes
0644
badips.py
11536 bytes
0644
blocklist_de.conf
2715 bytes
0644
bsd-ipfw.conf
3226 bytes
0644
cloudflare.conf
2970 bytes
0644
complain.conf
4757 bytes
0644
dshield.conf
7668 bytes
0644
dummy.conf
1717 bytes
0644
failcentral-dreamhost.conf
415 bytes
0644
firewallcmd-allports.conf
1501 bytes
0644
firewallcmd-common.conf
2649 bytes
0644
firewallcmd-ipset.conf
2719 bytes
0644
firewallcmd-multiport.conf
1322 bytes
0644
firewallcmd-new.conf
1950 bytes
0644
firewallcmd-rich-logging.conf
1021 bytes
0644
firewallcmd-rich-rules.conf
1801 bytes
0644
helpers-common.conf
592 bytes
0644
hostsdeny.conf
1657 bytes
0644
ipfilter.conf
1573 bytes
0644
ipfw.conf
1505 bytes
0644
iptables-allports.conf
1514 bytes
0644
iptables-common.conf
2738 bytes
0644
iptables-ipset-proto4.conf
2088 bytes
0644
iptables-ipset-proto6-allports.conf
2742 bytes
0644
iptables-ipset-proto6.conf
2785 bytes
0644
iptables-multiport-log.conf
2170 bytes
0644
iptables-multiport.conf
1508 bytes
0644
iptables-new.conf
1585 bytes
0644
iptables-string.conf
1369 bytes
0644
iptables-xt_recent-echo.conf
2672 bytes
0644
iptables.conf
1427 bytes
0644
mail-buffered.conf
2431 bytes
0644
mail-whois-common.conf
1051 bytes
0644
mail-whois-lines.conf
2443 bytes
0644
mail-whois.conf
1842 bytes
0644
mail.conf
1709 bytes
0644
mynetwatchman.conf
5321 bytes
0644
ndn-central-action.conf
291 bytes
0644
ndn-fail2ban-central.pl
3910 bytes
0755
netscaler.conf
1493 bytes
0644
nftables-allports.conf
383 bytes
0644
nftables-multiport.conf
384 bytes
0644
nftables.conf
6318 bytes
0644
nginx-block-map.conf
3746 bytes
0644
npf.conf
1524 bytes
0644
nsupdate.conf
3234 bytes
0644
osx-afctl.conf
497 bytes
0644
osx-ipfw.conf
2302 bytes
0644
pf.conf
3750 bytes
0644
route.conf
1023 bytes
0644
sendmail-buffered.conf
2806 bytes
0644
sendmail-common.conf
1938 bytes
0644
sendmail-geoip-lines.conf
1761 bytes
0644
sendmail-whois-ipjailmatches.conf
1055 bytes
0644
sendmail-whois-ipmatches.conf
1036 bytes
0644
sendmail-whois-lines.conf
1299 bytes
0644
sendmail-whois-matches.conf
1000 bytes
0644
sendmail-whois.conf
950 bytes
0644
sendmail.conf
829 bytes
0644
shorewall-ipset-proto6.conf
3521 bytes
0644
shorewall.conf
2156 bytes
0644
smtp.py
6277 bytes
0644
symbiosis-blacklist-allports.conf
1418 bytes
0644
ufw.conf
1045 bytes
0644
xarf-login-attack.conf
6443 bytes
0644
N4ST4R_ID | Naxtarrr