setup fail2ban

block tor exit nodes
This commit is contained in:
Lyn Fugmann 2023-10-04 18:49:12 +02:00
parent 23fb7747fb
commit d48fb6c13a
Signed by: fugi
GPG key ID: 4472A20091BFA792
2 changed files with 41 additions and 0 deletions

View file

@ -56,6 +56,7 @@
./modules/course-management.nix ./modules/course-management.nix
./modules/courses-phil.nix ./modules/courses-phil.nix
./modules/gitea.nix ./modules/gitea.nix
./modules/fail2ban.nix
{ {
sops.defaultSopsFile = ./secrets/quitte.yaml; sops.defaultSopsFile = ./secrets/quitte.yaml;
} }

40
modules/fail2ban.nix Normal file
View file

@ -0,0 +1,40 @@
{ config, lib, pkgs, ... }:
{
services.fail2ban = {
enable = true;
jails = {
tor = ''
enabled = true
bantime = 25h
action = iptables-allports[name=fail2banTOR, protocol=all]
'';
};
};
environment.etc = {
# dummy filter
"fail2ban/filter.d/tor.conf".text = ''
[Definition]
failregex =
ignoreregex =
'';
};
systemd.services."fail2ban-tor" = {
script = ''
${lib.getExe pkgs.curl} -fsSL "https://check.torproject.org/torbulkexitlist" | sed '/^#/d' | while read IP; do
${config.services.fail2ban.package}/bin/fail2ban-client set "tor" banip "$IP" > /dev/null
done
'';
};
systemd.timers."fail2ban-tor" = {
wantedBy = [ "timers.target" ];
timerConfig = {
OnCalendar = "daily";
Persistent = true;
Unit = "fail2ban-tor.service";
};
};
}