Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

fail2ban should be avoided. It does not support IPv6, so should be considered legacy software.

EDIT: Source: https://github.com/fail2ban/fail2ban/issues/1123

It appears they have moved forward a little in supporting IPv6, but it's still incomplete. It's unacceptable to not support it fully in 2020.



It looks like ipv6 matching is supported since late 2017 (version 10.0 [0]), although the changelog states that "not all ban actions are IPv6-capable now". As for IPv6 capabilities, I don't have any recent experience with the software.

[0]: https://github.com/fail2ban/fail2ban/blob/0.11.1/ChangeLog


With IPv6 every user gets an IPv4 internet worth of addresses for himself which makes fail2ban useless.


Couldn't you just ban the /64 and call it good? It's not like they get a random selection of addresses, they're all going to be the same CIDR. Or am I overlooking something here?


it does more than just scanning iptables logs..




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: