FAIL2BAN - Filter.d - http-403

From wiki.1001solutions.net


Filter.d

# /etc/fail2ban/filter.d/http.403.conf
#
#
[Definition]
failregex = <HOST> - - .*HTTP/[0-9]+(.[0-9]+)?" 403
            [client <HOST>] AH01797: client denied


Jail.conf

[http-403]
enabled = true
port = http,https
logpath = /var/log/nginx/*error*.log
          /var/log/nginx/*access*.log
bantime = 999999999
maxretry = 10
findtime = 600