ansible-role-reverse_proxy/templates/jail.local

49 lines
754 B
Text

# {{ ansible_managed }}
[DEFAULT]
ignoreip = 127.0.0.1/8 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16
destemail = {{ reverse_proxy_default_serveradmin_email }}
banaction = nftables-multiport
banaction_allports = nftables-allports
action = %(action_mwl)s
apache_error_log = /var/log/apache2/*error.log
apache_access_log = /var/log/apache2/*access.log
[sshd]
enabled = true
[apache-auth]
enabled = true
logpath = %(apache_error_log)s
[apache-badbots]
enabled = true
[apache-noscript]
enabled = true
[apache-overflows]
enabled = true
[apache-nohome]
enabled = true
[apache-botsearch]
enabled = true
[apache-fakegooglebot]
enabled = true
[apache-modsecurity]
enabled = true
[apache-shellshock]
enabled = true
[recidive]
enabled = true