netaddr=$1
shift
- echo "ban ${netaddr}"
+ echo "ban from ${netaddr}"
sudo firewall-cmd --zone=drop --add-source=${netaddr}
sudo firewall-cmd --permanent --zone=drop --add-source=${netaddr}
done
netaddr=$1
shift
- echo "ban ${netaddr}"
- sudo firewall-cmd --direct --add-rule ipv4 filter nabium-ssh ${prio} -s ${netaddr}
- sudo firewall-cmd --permanent --direct --add-rule ipv4 filter nabium-ssh ${prio} -s ${netaddr}
+ echo "ban ${netaddr} to SSH"
+ sudo firewall-cmd --direct --add-rule ipv4 filter nabium-ssh ${prio} -s ${netaddr} -j DROP
+ sudo firewall-cmd --permanent --direct --add-rule ipv4 filter nabium-ssh ${prio} -s ${netaddr} -j DROP
done
### ban per network
- sudo firewall-cmd --direct --add-rule ipv4 filter nabium-ssh 1 -s 63.224.0.0/13
- sudo firewall-cmd --permanent --direct --add-rule ipv4 filter nabium-ssh 1 -s 63.224.0.0/13
+ sudo firewall-cmd --direct --add-rule ipv4 filter nabium-ssh 1 -s 63.224.0.0/13 -j DROP
+ sudo firewall-cmd --permanent --direct --add-rule ipv4 filter nabium-ssh 1 -s 63.224.0.0/13 -j DROP
### unban per network
- sudo firewall-cmd --direct --remove-rule ipv4 filter nabium-ssh 1 -s 63.224.0.0/13
- sudo firewall-cmd --permanent --direct --remove-rule ipv4 filter nabium-ssh 1 -s 63.224.0.0/13
+ sudo firewall-cmd --direct --remove-rule ipv4 filter nabium-ssh 1 -s 63.224.0.0/13 -j DROP
+ sudo firewall-cmd --permanent --direct --remove-rule ipv4 filter nabium-ssh 1 -s 63.224.0.0/13 -j DROP
list banned
netaddr=$1
shift
- echo "ban ${netaddr}"
+ echo "unban from ${netaddr}"
sudo firewall-cmd --zone=drop --remove-source=${netaddr}
sudo firewall-cmd --permanent --zone=drop --remove-source=${netaddr}
done
netaddr=$1
shift
- echo "ban ${netaddr}"
- sudo firewall-cmd --direct --remove-rule ipv4 filter nabium-ssh ${prio} -s ${netaddr}
- sudo firewall-cmd --permanent --direct --remove-rule ipv4 filter nabium-ssh ${prio} -s ${netaddr}
+ echo "unban ${netaddr} to SSH"
+ sudo firewall-cmd --direct --remove-rule ipv4 filter nabium-ssh ${prio} -s ${netaddr} -j DROP
+ sudo firewall-cmd --permanent --direct --remove-rule ipv4 filter nabium-ssh ${prio} -s ${netaddr} -j DROP
done