Merge pull request #65453 from wahjava/master
sshguard: do not create ipset in post-start
This commit is contained in:
commit
618ecd930d
@ -107,8 +107,6 @@ in {
|
|||||||
path = with pkgs; [ iptables ipset iproute systemd ];
|
path = with pkgs; [ iptables ipset iproute systemd ];
|
||||||
|
|
||||||
postStart = ''
|
postStart = ''
|
||||||
${pkgs.ipset}/bin/ipset -quiet create -exist sshguard4 hash:ip family inet
|
|
||||||
${pkgs.ipset}/bin/ipset -quiet create -exist sshguard6 hash:ip family inet6
|
|
||||||
${pkgs.iptables}/bin/iptables -I INPUT -m set --match-set sshguard4 src -j DROP
|
${pkgs.iptables}/bin/iptables -I INPUT -m set --match-set sshguard4 src -j DROP
|
||||||
${pkgs.iptables}/bin/ip6tables -I INPUT -m set --match-set sshguard6 src -j DROP
|
${pkgs.iptables}/bin/ip6tables -I INPUT -m set --match-set sshguard6 src -j DROP
|
||||||
'';
|
'';
|
||||||
|
Loading…
x
Reference in New Issue
Block a user