Using shell to automatically add abnormal IP to iptables blacklist
In daily work, there is always an exception IP to create a large number of TCP connections, resulting in slow response or inaccessibility of the server.
At this point, you can use scripts to add these abnormal IP to the iptables blacklist.
Count exception IP and add blacklist script:
#! / bin/bashnetstat-na | grep ESTAB | awk'{print $5}'| awk-F:'{print $1}'| egrep-v '192.168 | 127.0' | uniq-c | awk' {if ($2null null & $1 > 1) {print $2}}'> / root/dropip.txtfor I in $(cat / root/dropip.txt) do/sbin/iptables-An INPUT-s $I-j DROPecho "$I" > > / root/dropip.logdone
Automatic execution every 3 minutes in combination with task scheduling:
[root@lvs02 account_tcp] # crontab-l#tcp connection is limit*/3 * / root/account_tcp/drop_ip.sh & > / dev/null