LFD and PSAD — brute force and port scans Print

  • lsf, bruteforce
  • 0

LFD watches SSH, FTP, mail, Exim, cPanel and ModSecurity failures. Default: 5 hits in 300 seconds → 1 hour ban. Four temp bans in 24 hours become a permanent deny when LF_PERMBLOCK=1.

PSAD watches port scans. Default: 5 ports in 60 seconds → 24 hour ban.

IPs in lsf.ignore are never auto-banned. Do not run a Fail2ban jail on the same log as an enabled LF_WATCH_* switch.

lsf --log lfd
lsf --log psad
lsf --events 40

Was this answer helpful?

« Back

Χρώμα θέματος

Support