Pārlūkot izejas kodu

Merge pull request #336 from mariusv/master

fail2ban support for Trusty
Alex Payne 10 gadus atpakaļ
vecāks
revīzija
e26940569d

+ 5
- 0
roles/common/tasks/security.yml Parādīt failu

9
   template: src=etc_fail2ban_jail.local.j2 dest=/etc/fail2ban/jail.local
9
   template: src=etc_fail2ban_jail.local.j2 dest=/etc/fail2ban/jail.local
10
   notify: restart fail2ban
10
   notify: restart fail2ban
11
 
11
 
12
+- name: Copy fail2ban configuration into place for Ubuntu Trusty
13
+  template: src=etc_trusty_fail2ban_jail.local.j2 dest=/etc/fail2ban/jail.local
14
+  when: ansible_sistributon_release == 'trusty'
15
+  notify: restart fail2ban
16
+
12
 - name: Copy fail2ban dovecot configuration into place
17
 - name: Copy fail2ban dovecot configuration into place
13
   copy: src=etc_fail2ban_filter.d_dovecot-pop3imap.conf dest=/etc/fail2ban/filter.d/dovecot-pop3imap.conf
18
   copy: src=etc_fail2ban_filter.d_dovecot-pop3imap.conf dest=/etc/fail2ban/filter.d/dovecot-pop3imap.conf
14
   notify: restart fail2ban
19
   notify: restart fail2ban

+ 4
- 0
roles/common/templates/etc_fail2ban_jail.local.j2 Parādīt failu

28
 enabled = true
28
 enabled = true
29
 filter = dovecot-pop3imap
29
 filter = dovecot-pop3imap
30
 action = iptables-multiport[name=dovecot-pop3imap, port="pop3,imap,993,995", protocol=tcp]
30
 action = iptables-multiport[name=dovecot-pop3imap, port="pop3,imap,993,995", protocol=tcp]
31
+{% if ansible_distribution == 'Ubuntu' %}
32
+logpath = /var/log/mail.log
33
+{% else %}
31
 logpath = /var/log/maillog
34
 logpath = /var/log/maillog
35
+{% endif %}
32
 maxretry = 20
36
 maxretry = 20
33
 findtime = 1200
37
 findtime = 1200
34
 bantime = 1200
38
 bantime = 1200

Notiek ielāde…
Atcelt
Saglabāt