• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

i need something like fail2ban do on linux on pfsense or backend servers

Scheduled Pinned Locked Moved pfSense Packages
6 Posts 3 Posters 655 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • L
    luisenrique
    last edited by Mar 14, 2019, 2:54 AM

    I have pfsense/haproxy, dovecot imap postfix smpt, apache and iis behind as backend servers ... I need some idea to block unsuccessful login attempts 3 or 5 more attempts like fail2ban on linux.
    I need some documents to read some links any help is appreciated...
    maybe this is not a question for pfsense, by the moment I googling and I will investigate
    regards!

    B 1 Reply Last reply Mar 14, 2019, 3:11 AM Reply Quote 0
    • B
      biggsy @luisenrique
      last edited by Mar 14, 2019, 3:11 AM

      @luisenrique

      Send your syslog records to a FreeBSD or OpenBSD server running Fail2ban and have it use openbgpd to send updates (IPs to block) back to pfSense.

      I do this with postfix now. I don't know how you would deal with IIS logs though.

      L 1 Reply Last reply Mar 14, 2019, 3:36 AM Reply Quote 0
      • L
        luisenrique @biggsy
        last edited by Mar 14, 2019, 3:36 AM

        @biggsy said in i need something like fail2ban do on linux on pfsense or backend servers:

        your syslog records to a FreeBSD

        Thanks... Let me understand.
        You tell me to send the syslog records of (dovecot/postfix/apache backend servers) to a freebsd server running Fail2ban and openbgpd at the same time to return the ip address to be blocked on pfsense/haproxy/openbgp frontend server Through a shared border gateway protocol between backend and fronend? It looks complicated for a small deployment but I will try and take into account that possible solution.
        thanks and sorry my english

        1 Reply Last reply Reply Quote 0
        • B
          biggsy
          last edited by biggsy Mar 15, 2019, 9:33 AM Mar 15, 2019, 9:33 AM

          I think you understood it very well.

          There are other things that can be done, as well, once you're collecting your syslog records to a single server.

          Happy to share what I have done.

          1 Reply Last reply Reply Quote 0
          • N
            NogBadTheBad
            last edited by Mar 15, 2019, 9:45 AM

            Are the backend servers running any form of BSD, look here if they are:-

            https://www.cyberciti.biz/faq/freebsd-openbsd-pf-stop-ftp-bruteforce-attacks/

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            1 Reply Last reply Reply Quote 0
            • L
              luisenrique
              last edited by Mar 15, 2019, 3:54 PM

              @nogbadthebad said in i need something like fail2ban do on linux on pfsense or backend servers:

              e the backend servers running any form of BSD, look here if they are:-

              thanks for reply!

              1 Reply Last reply Reply Quote 0
              6 out of 6
              • First post
                6/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received