Re: Syncing iptables rules between two servers



Is there anyone that know about how I can "sync" iptables rules on two
different servers? The plan is to have (on one of the servers) a
script that automaticly block ip adresses with iptables depending on
different conditions. When that ip adress is blocked I want it to
automaticly be blocked on another server to.

Personally, I'd pursue an rsync / ssh -c solution. Rsync a straight-up
shell script that sets up your firewall rules, and then run it with ssh
-c. If you set up your public keys properly on the remote server, you
can run the whole thing from a script with no human intervention..

I have a very similar setup, but I copy the file over manually and run it.

I have a big iptables -F at the beginning of the firewall script, which
takes care of any deleted rules. You may or may not want to do this
sort of thing, depending on your setup, but it's necessary for me. The
firewall script runs so fast that the temporary connection loss is not a
problem. YMMV.

I wrote an ip blocking script (yes there are tons of these) that
monitors logs and blocks IPs based on certain conditions. For each log
type you need a handler to work out what to look for and what to
track. The ones I have are for SSH and apache (access log). In addition
it has a "sync" log, so if you're running this on multiple hosts then it
will use SSH (need to use rsa/dsa auth) to sync the list of banned IPs
across hosts - all hosts can work together to ban.

Some good things are it'll setup and maintain iptables for you,
auto expire blocks, white lists etc...

It's written with Perl and it's under the GPL:

http://jason.mindsocket.com.au/pages/linux/ipb-monitor/


Jason.



Relevant Pages

  • Re: Deny rules...
    ... services client I have not implemented it. ... Tony Su ... >The Script makes sure the ip to be blocked is not it´s ... >I have few outside servers to connect from to my servers ...
    (microsoft.public.isa)
  • Re: Software configuration management tool required
    ... If it automates ... and 100-ish servers, it's just not going to happen. ... you test it by running the rc?.d script that init will ... > because Oracle or some vendor tells them to do so. ...
    (comp.unix.admin)
  • Re: Syncing iptables rules between two servers
    ... Is there anyone that know about how I can "sync" iptables rules on two ... The plan is to have (on one of the servers) a ... shell script that sets up your firewall rules, and then run it with ssh -c. ... See why so many companies trust Spy Sweeper Enterprise to eradicate spyware from their networks. ...
    (Security-Basics)
  • Re: Syncing iptables rules between two servers
    ... I'v started making a script for doing this in bash ... Syncing iptables rules between two servers ... Try Webroot's Spy Sweeper Enterprisefor 30 days for FREE with no ...
    (Security-Basics)
  • Re: Syncing iptables rules between two servers
    ... The plan is to have (on one of the servers) a ... script that automaticly block ip adresses with iptables depending on ... shell script that sets up your firewall rules, and then run it with ssh ...
    (Security-Basics)