July 2017
Intermediate to advanced
434 pages
12h 59m
English
The Fail2Ban configuration must be tuned so that a large site is not accidentally kicked offline just because they are coming back online, causing all their phones to reregister at once. For example, if you have a rate limit Fail2Ban entry (eg a rule about quantity of "good" traffic, as opposed to "failed attempts" numbers), you would not want to set up Fail2Ban to block IP addresses if they happen to send 50 authentication requests in a 5 second period, because if the site has 50 phones and their power goes out, when their power comes back on all phones will attempt to register at once, resulting in them being banned. This is not the intent. Be careful in what you judge a "Denial of Service" traffic pattern. ...
Read now
Unlock full access