Iptables configuration record
The number of connections to the same IP request exceeds 5 times in an hour, and the IP is blocked for 1 hour.
At the same time, limit the IP segment that initiates the request
# cat / etc/sysconfig/iptables# Firewall configuration written by system-config-firewall# Manual customization of this file is not recommended.*filter:INPUT ACCEPT [0:0]: FORWARD ACCEPT [0:0]: OUTPUT ACCEPT [0:0]-An INPUT-m state-- state ESTABLISHED RELATED-j ACCEPT-An INPUT-p icmp-j ACCEPT-An INPUT-I lo-j ACCEPT#-An INPUT-m state-- state NEW-m tcp-p tcp-- dport 22-j ACCEPT-N Recent_Block-A Recent_Block- p tcp-- dport 22-m state-- state NEW-m recent-- name SSHPOOL-rcheck-seconds 3600-hitcount 5-j DROP-A Recent_Block- p tcp-dport 22-m state-state NEW-m recent-name SSHPOOL-set -j ACCEPT-An INPUT-s 192.168.0 dport 24-p tcp-- dport 22-j Recent_Block-An INPUT-s 192.168.1.0 dport 24-p tcp-- dport 22-j Recent_Block-An INPUT-s 192.168.2.0 tcp-- dport 22-j Recent_Block-An INPUT-j REJECT-- reject-with icmp-host-prohibited-A FORWARD-j REJECT-- reject-with icmp-host-prohibitedCOMMIT
The path to access the log is:
/ proc/net/xt_recent/SSHPOOL