Re: [Puppet Users] puppetlabs/firewall and fail2ban

2013-10-29 Thread Donald Hoffman
On Oct 29, 2013, at 8:41 AM, Daniele Sluijters wrote: > Hello, > > A while back I wanted to switch our home-brewed iptables module to the > puppetlabs/firewall module but I couldn't figure out > how to tell puppetlabs/firewall to leave the fail2ban chains alone. > > I was curious if someone

Re: [Puppet Users] puppetlabs/firewall and fail2ban

2013-10-29 Thread Donald Hoffman
On Oct 29, 2013, at 12:00 PM, Daniele Sluijters wrote: > Hi, > > DenyHosts is not an option for me since I can't predict which hosts will be > connecting from the outside. Fail2ban solves that issue by looking for odd > behaviour instead of asking me to whitelist. > > Thanks for the suggesti

Re: [Puppet Users] puppetlabs/firewall and fail2ban

2013-10-29 Thread Donald Hoffman
On reading your message, I think you are perhaps confusing the static Linux /etc/host.deny mechanism with the DenyHosts project. See http://denyhosts.sourceforg.net Don On Oct 29, 2013, at 5:32 PM, Donald Hoffman wrote: > On Oct 29, 2013, at 12:00 PM, Daniele Sluijters > wrote: &g