Created
June 9, 2013 14:26
-
-
Save noqqe/5743740 to your computer and use it in GitHub Desktop.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
# Block anything | |
block in all | |
block out all | |
block return | |
# Anti SSH Bruteforce | |
table <bruteforce> persist | |
table <admins> { 1.2.3.4/32 } | |
# Disallow bruteforcing IPs except <admins> | |
pass in on $extif from <admins> to any port ssh | |
block quick from <bruteforce> | |
# Allow and track ssh brute force | |
pass in on $extif proto tcp from any to any port ssh \ | |
flags S/SA keep state \ | |
(max-src-conn 5, max-src-conn-rate 5/50, \ | |
overload <bruteforce> flush global) |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment