Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Using shell to automatically add abnormal IP to iptables blacklist

Shulou Source: shulou.com Published: 2022-06-01 03:42:30 10月04日 Update

In daily work, there is always an exception IP to create a large number of TCP connections, resulting in slow response or inaccessibility of the server.

At this point, you can use scripts to add these abnormal IP to the iptables blacklist.

Count exception IP and add blacklist script:

#! / bin/bashnetstat-na | grep ESTAB | awk'{print $5}'| awk-F:'{print $1}'| egrep-v '192.168 | 127.0' | uniq-c | awk' {if ($2null null & $1 > 1) {print $2}}'> / root/dropip.txtfor I in $(cat / root/dropip.txt) do/sbin/iptables-An INPUT-s $I-j DROPecho "$I" > > / root/dropip.logdone

Automatic execution every 3 minutes in combination with task scheduling:

[root@lvs02 account_tcp] # crontab-l#tcp connection is limit*/3 * / root/account_tcp/drop_ip.sh & > / dev/null

Tags: Blacklist blackname script task general server speed work service statistics Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Redmi Shulou Tech Info MariaDB Xiaomi OPPO Reno