From 278610c0c3357776518f30725fe4bbd5a2810cf3 Mon Sep 17 00:00:00 2001 From: jochen Date: Sun, 27 Sep 2026 16:55:34 +0200 Subject: [PATCH] fail2ban never bans a tunnel peer: ignoreip names the mesh range MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The jail.local [DEFAULT] gains ignoreip = 127.0.0.1/8 ::1 ${machine:mesh-range} — localhost plus the mesh's own private range, named through the placeholder rather than hardcoded (data is the mesh's, ADR 0112). Without it fail2ban could ban the mesh's own nodes on 10.10.0.0/24; on novox that rule survived only in memory from a now-deleted HAL file and would be lost on the next restart. --- modules/fail2ban/module.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/fail2ban/module.json b/modules/fail2ban/module.json index 9876432..d24a075 100644 --- a/modules/fail2ban/module.json +++ b/modules/fail2ban/module.json @@ -33,7 +33,7 @@ "type": "file", "path": "/etc/fail2ban/jail.local", "mode": "0644", - "content": "[INCLUDES]\n\nbefore = paths-arch.conf\n\n[DEFAULT]\n\nbantime = 10m\nfindtime = 10m\nmaxretry = 5\n\nbanaction = ufw\nbanaction_allports = iptables-allports\n\n[sshd]\nenabled = true\nport = ssh\nlogpath = %(sshd_log)s\nbackend = %(sshd_backend)s\n" + "content": "[INCLUDES]\n\nbefore = paths-arch.conf\n\n[DEFAULT]\n\n# Never act on the machine itself or on a tunnel peer: the mesh's private range is\n# ${machine:mesh-range}, named here rather than written as a value the module cannot\n# know (novox/hq ADR 0112). Without this, fail2ban could ban the mesh's own nodes.\nignoreip = 127.0.0.1/8 ::1 ${machine:mesh-range}\n\nbantime = 10m\nfindtime = 10m\nmaxretry = 5\n\nbanaction = ufw\nbanaction_allports = iptables-allports\n\n[sshd]\nenabled = true\nport = ssh\nlogpath = %(sshd_log)s\nbackend = %(sshd_backend)s\n" }, { "id": "jail-sshd", -- 2.54.0