{"id":736,"date":"2026-09-16T17:57:30","date_gmt":"2026-09-16T14:57:30","guid":{"rendered":"https:\/\/imaxis.ru\/?p=736"},"modified":"2026-09-16T17:57:30","modified_gmt":"2026-09-16T14:57:30","slug":"zaschita-servera-cherez-fail2ban-geoip-filtratsiya-na-ubuntu","status":"publish","type":"post","link":"https:\/\/imaxis.ru\/?p=736","title":{"rendered":"\u0417\u0430\u0449\u0438\u0442\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0447\u0435\u0440\u0435\u0437 Fail2ban + GeoIP-\u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u044f \u043d\u0430 Ubuntu"},"content":{"rendered":"<h1>\u0417\u0430\u0449\u0438\u0442\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0447\u0435\u0440\u0435\u0437 Fail2ban + GeoIP-\u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u044f \u043d\u0430 Ubuntu<\/h1>\n<p>\u041f\u0443\u0431\u043b\u0438\u0447\u043d\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u043f\u043e\u0441\u0442\u043e\u044f\u043d\u043d\u043e \u00ab\u0434\u043e\u043b\u0431\u044f\u0442\u00bb \u0431\u043e\u0442\u044b: \u043f\u0435\u0440\u0435\u0431\u043e\u0440 SSH, \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u044b \u0432\u0435\u0431-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439, \u0444\u043b\u0443\u0434. \u0414\u0432\u0430 \u043f\u0440\u043e\u0441\u0442\u044b\u0445 \u0438 \u044d\u0444\u0444\u0435\u043a\u0442\u0438\u0432\u043d\u044b\u0445 \u0441\u043f\u043e\u0441\u043e\u0431\u0430 \u043e\u0442\u0441\u0435\u0447\u044c \u0438\u0445 \u2014 <strong>Fail2ban<\/strong> (\u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0430 \u043f\u043e \u043f\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u044e) \u0438 <strong>GeoIP\/DankHosts<\/strong> (\u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0430 \u043f\u043e \u0441\u0442\u0440\u0430\u043d\u0435\/\u0441\u043f\u0438\u0441\u043a\u0443). \u0420\u0430\u0437\u0431\u0435\u0440\u0451\u043c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0443 \u043e\u0431\u043e\u0438\u0445 \u043d\u0430 Ubuntu.<\/p>\n<hr \/>\n<h2>\u0427\u0430\u0441\u0442\u044c 1. Fail2ban \u2014 \u0431\u043b\u043e\u043a\u0438\u0440\u0443\u0435\u043c \u043f\u043e \u043f\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u044e<\/h2>\n<p>Fail2ban \u0441\u043b\u0435\u0434\u0438\u0442 \u0437\u0430 \u043b\u043e\u0433\u0430\u043c\u0438, \u0441\u0447\u0438\u0442\u0430\u0435\u0442 \u043d\u0435\u0443\u0434\u0430\u0447\u043d\u044b\u0435 \u043f\u043e\u043f\u044b\u0442\u043a\u0438 \u0438 \u043f\u0440\u0438 \u043f\u0440\u0435\u0432\u044b\u0448\u0435\u043d\u0438\u0438 \u043f\u043e\u0440\u043e\u0433\u0430 \u0431\u0430\u043d\u0438\u0442 IP \u0447\u0435\u0440\u0435\u0437 firewall (iptables\/nftables) \u043d\u0430 \u0437\u0430\u0434\u0430\u043d\u043d\u043e\u0435 \u0432\u0440\u0435\u043c\u044f.<\/p>\n<h3>\u0428\u0430\u0433 1. \u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430<\/h3>\n<pre><code class=\"language-bash\">sudo apt update &amp;&amp; sudo apt install -y fail2ban\nsudo systemctl enable --now fail2ban\n<\/code><\/pre>\n<h3>\u0428\u0430\u0433 2. \u0411\u0430\u0437\u043e\u0432\u0430\u044f \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f<\/h3>\n<p>\u0421\u043e\u0437\u0434\u0430\u0439\u0442\u0435 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u044b\u0439 \u043a\u043e\u043d\u0444\u0438\u0433 <code>\/etc\/fail2ban\/jail.local<\/code> (\u043e\u043d \u043f\u0435\u0440\u0435\u043a\u0440\u044b\u0432\u0430\u0435\u0442 <code>jail.conf<\/code>):<\/p>\n<pre><code class=\"language-ini\">[DEFAULT]\n# \u0412\u0440\u0435\u043c\u044f \u0431\u0430\u043d\u0430: 1 \u0447\u0430\u0441 (86400 - \u0441\u0443\u0442\u043a\u0438)\nbantime  = 3600\n# \u0427\u0438\u0441\u043b\u043e \u043f\u043e\u043f\u044b\u0442\u043e\u043a \u0434\u043e \u0431\u0430\u043d\u0430\nmaxretry = 4\n# \u041e\u043a\u043d\u043e \u043f\u043e\u0434\u0441\u0447\u0451\u0442\u0430\nfindtime = 600\n# \u0411\u0430\u043d\u044f\u0449\u0438\u0439 backend\nbanaction = iptables-multiport\nbanaction_allports = iptables-allports\n# \u0418\u0433\u043d\u043e\u0440\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0441\u0432\u043e\u0438 \u0430\u0434\u0440\u0435\u0441\u0430\nignoreip = 127.0.0.1\/8 192.168.0.0\/16\n<\/code><\/pre>\n<h3>\u0428\u0430\u0433 3. \u0412\u043a\u043b\u044e\u0447\u0430\u0435\u043c \u0437\u0430\u0449\u0438\u0442\u044b<\/h3>\n<p>\u0421\u0435\u043a\u0446\u0438\u0438 \u0432 <code>\/etc\/fail2ban\/jail.local<\/code>:<\/p>\n<pre><code class=\"language-ini\">[sshd]\nenabled = true\nport = ssh\nlogpath = %(sshd_log)s\n\n[nginx-http-auth]\nenabled = true\nport = http,https\nlogpath = \/var\/log\/nginx\/error.log\n\n[nginx-limit-req]\nenabled = true\nport = http,https\nlogpath = \/var\/log\/nginx\/error.log\n\n[proftpd]\nenabled = false   # \u0432\u044b\u043a\u043b\u044e\u0447\u0438\u0442\u0435, \u0435\u0441\u043b\u0438 \u043d\u0435\u0442 FTP\n<\/code><\/pre>\n<p>\u0421\u043f\u0438\u0441\u043e\u043a \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b\u0445 \u0444\u0438\u043b\u044c\u0442\u0440\u043e\u0432 (\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043a\u0438\u043b\u043e\u043d\u0430\u0441\u0442\u0440\u043e\u0435\u043a \u0432\u043d\u0443\u0442\u0440\u0438):<\/p>\n<pre><code class=\"language-bash\">fail2ban-client dstatus sshd\nls \/etc\/fail2ban\/filter.d\/\n<\/code><\/pre>\n<h3>\u0428\u0430\u0433 4. \u041f\u0440\u043e\u0432\u0435\u0440\u043a\u0430<\/h3>\n<pre><code class=\"language-bash\">sudo fail2ban-client status sshd\n<\/code><\/pre>\n<p>\u041f\u043e\u043a\u0430\u0436\u0435\u0442 \u0430\u043a\u0442\u0438\u0432\u043d\u044b\u0435 \u0431\u0430\u043d\u044b. \u041f\u0440\u043e\u0441\u043c\u043e\u0442\u0440 \u0442\u0435\u043a\u0443\u0449\u0438\u0445:<\/p>\n<pre><code class=\"language-bash\">sudo fail2ban-client get sshd banned\nsudo iptables -L f2b-sshd -n\n<\/code><\/pre>\n<p>\u0421\u043d\u044f\u0442\u0438\u0435 \u0431\u0430\u043d\u0430 \u0432\u0440\u0443\u0447\u043d\u0443\u044e:<\/p>\n<pre><code class=\"language-bash\">sudo fail2ban-client set sshd unbanip 185.220.101.42\n<\/code><\/pre>\n<hr \/>\n<h2>\u0427\u0430\u0441\u0442\u044c 2. GeoIP \u2014 \u0431\u043b\u043e\u043a\u0438\u0440\u0443\u0435\u043c \u043d\u0435\u0436\u0435\u043b\u0430\u0442\u0435\u043b\u044c\u043d\u044b\u0435 \u0441\u0442\u0440\u0430\u043d\u044b<\/h2>\n<p>\u0415\u0441\u043b\u0438 \u043a \u0441\u0435\u0440\u0432\u0435\u0440\u0443 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0430\u044e\u0442\u0441\u044f \u0442\u043e\u043b\u044c\u043a\u043e \u0438\u0437 \u0420\u043e\u0441\u0441\u0438\u0438\/\u0421\u041d\u0413, \u0440\u0430\u0437\u0443\u043c\u043d\u043e \u0440\u0435\u0437\u0430\u0442\u044c \u0432\u0435\u0441\u044c \u043e\u0441\u0442\u0430\u043b\u044c\u043d\u043e\u0439 \u043c\u0438\u0440 \u043d\u0430 \u0432\u0445\u043e\u0434\u0435 \u0432 SSH\/\u0432\u0435\u0431. \u0414\u0432\u0430 \u043f\u043e\u0434\u0445\u043e\u0434\u0430.<\/p>\n<h3>\u0412\u0430\u0440\u0438\u0430\u043d\u0442 A. \u0427\u0435\u0440\u0435\u0437 nftables + geoip2-\u043c\u043e\u0434\u0443\u043b\u044c (\u0441\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0439)<\/h3>\n<p>\u0412 Ubuntu 22.04+ nftables \u0443\u043c\u0435\u0435\u0442 GeoIP \u043d\u0430\u0442\u0438\u0432\u043d\u043e \u0447\u0435\u0440\u0435\u0437 <code>geoip<\/code> (\u044f\u0434\u0440\u043e 5.11+):<\/p>\n<pre><code class=\"language-bash\">sudo modprobe nft_geoip\n<\/code><\/pre>\n<pre><code class=\"language-nft\">table inet filter {\n    set geo_block {\n        type ipv4_addr\n        elements = { 1.2.3.4, 5.6.7.8 }  # \u043f\u0440\u0438\u043c\u0435\u0440 - \u0440\u0435\u0430\u043b\u044c\u043d\u043e \u0433\u0435\u043d\u0435\u0440\u0438\u043c \u0441\u043f\u0438\u0441\u043a\u043e\u043c\n    }\n    chain input {\n        type filter hook input priority filter; policy accept;\n        ip daddr geoip country CN drop\n        ip daddr geoip country RU accept\n    }\n}\n<\/code><\/pre>\n<blockquote>\n<p>\u041c\u043e\u0434\u0443\u043b\u044c <code>nft_geoip<\/code> \u0442\u0440\u0435\u0431\u0443\u0435\u0442 \u043f\u0430\u043a\u0435\u0442 <code>linux-modules-extra<\/code>. \u041d\u0430 \u0442\u0438\u043f\u043e\u0432\u044b\u0445 VDS \u0440\u0435\u0434\u043a\u043e \u0432\u043a\u043b\u044e\u0447\u0451\u043d.<\/p>\n<\/blockquote>\n<h3>\u0412\u0430\u0440\u0438\u0430\u043d\u0442 B. \u0427\u0435\u0440\u0435\u0437 GeoIP DB + iptables + cron (\u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0430\u043b\u044c\u043d\u044b\u0439)<\/h3>\n<p>\u0421\u0430\u043c\u043e\u0435 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u043e\u0435: \u0441\u043a\u0430\u0447\u0438\u0432\u0430\u0435\u043c \u0431\u0430\u0437\u0443 \u0441\u0442\u0440\u0430\u043d \u0432 IP-\u0441\u043f\u0438\u0441\u043e\u043a, \u0437\u0430\u043b\u0438\u0432\u0430\u0435\u043c \u0432 nftables\/iptables, \u043e\u0431\u043d\u043e\u0432\u043b\u044f\u0435\u043c \u043f\u043e cron.<\/p>\n<p>\u0421\u0442\u0430\u0432\u0438\u043c \u0443\u0442\u0438\u043b\u0438\u0442\u0443 \u0441\u0431\u043e\u0440\u043a\u0438:<\/p>\n<pre><code class=\"language-bash\">sudo apt install -y curl ipset gzip\nsudo mkdir -p \/etc\/geoip\n<\/code><\/pre>\n<p>\u0421\u043a\u0440\u0438\u043f\u0442 <code>\/usr\/local\/bin\/geoip-block.sh<\/code>:<\/p>\n<pre><code class=\"language-bash\">#!\/bin\/bash\n# \u0413\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u044f \u0441\u043f\u0438\u0441\u043a\u0430 \u0437\u0430\u043f\u0440\u0435\u0449\u0451\u043d\u043d\u044b\u0445 \u043f\u043e\u0434\u0441\u0435\u0442\u0435\u0439 (\u043f\u0440\u0438\u043c\u0435\u0440 - RU + KG + KZ \u0440\u0430\u0437\u0440\u0435\u0448\u0435\u043d\u044b):\nGEO_URL=&quot;https:\/\/github.com\/herrbischoff\/country-ip-blocks\/raw\/master\/ipv4\/country_banned&quot;\nDROP_LIST=&quot;\/etc\/geoip\/banned.txt&quot;\n\ncurl -fsSL &quot;$GEO_URL&quot; -o &quot;$DROP_LIST&quot;\n\n# \u0417\u0430\u0433\u0440\u0443\u0437\u043a\u0430 \u0432 nftables (\u043f\u0440\u0438\u043c\u0435\u0440 \u0447\u0435\u0440\u0435\u0437 ipset + iptables)\nipset destroy geo-banned 2&gt;\/dev\/null || true\nipset create geo-banned hash:net\nwhile read -r net; do\n  [[ &quot;$net&quot; =~ ^[0-9]+.[0-9]+.[0-9]+.[0-9]+\/[0-9]+$ ]] &amp;&amp; ipset add geo-banned &quot;$net&quot;\ndone &lt; &quot;$DROP_LIST&quot;\n\n# iptables \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u0431\u043b\u043e\u043a\u0438\u0440\u0443\u0435\u0442 \u0432\u0445\u043e\u0434\u044f\u0449\u0438\u0435 \u0438\u0437 \u044d\u0442\u0438\u0445 \u043f\u043e\u0434\u0441\u0435\u0442\u0435\u0439\niptables -I INPUT -m set --match-set geo-banned src -j DROP\n<\/code><\/pre>\n<p>\u0417\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u043c:<\/p>\n<pre><code class=\"language-bash\">chmod +x \/usr\/local\/bin\/geoip-block.sh\nsudo \/usr\/local\/bin\/geoip-block.sh\nsudo crontab -e\n# \u0414\u043e\u0431\u0430\u0432\u0438\u0442\u044c: 0 3 * * * \/usr\/local\/bin\/geoip-block.sh\n<\/code><\/pre>\n<blockquote>\n<p>\u041f\u0435\u0440\u0435\u0434 \u043c\u0430\u0441\u0441\u043e\u0432\u043e\u0439 \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u043e\u0439 <strong>\u0443\u0431\u0435\u0434\u0438\u0442\u0435\u0441\u044c<\/strong>, \u0447\u0442\u043e \u0432\u0430\u0448 IP \u043d\u0435 \u043f\u043e\u043f\u0430\u043b \u0432 \u0441\u043f\u0438\u0441\u043e\u043a (\u043f\u0440\u043e\u0432\u0435\u0440\u044c\u0442\u0435 \u0442\u0435\u0440\u043c\u0438\u043d\u0430\u043b \u0441 \u0434\u0440\u0443\u0433\u043e\u0433\u043e \u041f\u041a).<\/p>\n<\/blockquote>\n<hr \/>\n<h2>\u0427\u0430\u0441\u0442\u044c 3. \u041a\u043e\u043c\u0431\u043e: Fail2ban + GeoIP \u043d\u0430 \u043f\u0440\u0430\u043a\u0442\u0438\u043a\u0435<\/h2>\n<p>\u0418\u0434\u0435\u0430\u043b\u044c\u043d\u0430\u044f \u043a\u043e\u043c\u0431\u0438\u043d\u0430\u0446\u0438\u044f:<\/p>\n<ol>\n<li><strong>GeoIP \u0431\u043b\u043e\u043a\u0438\u0440\u0443\u0435\u0442<\/strong> \u0432\u0445\u043e\u0434\u044f\u0449\u0438\u0439 \u0442\u0440\u0430\u0444\u0438\u043a \u0438\u0437 \u0441\u0442\u0440\u0430\u043d, \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0443 \u0432\u0430\u0441 \u043d\u0435\u0442.<\/li>\n<li><strong>Fail2ban \u0431\u0430\u043d\u0438\u0442<\/strong> \u043f\u043e \u043f\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u044e \u2014 \u043e\u0442 \u0442\u0435\u0445, \u043a\u0442\u043e \u043e\u0441\u0442\u0430\u043b\u0441\u044f (\u0441\u043a\u0430\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435, \u043f\u0435\u0440\u0435\u0431\u043e\u0440).<\/li>\n<li><strong>rate-limit \u0432 nginx<\/strong> \u0437\u0430\u0449\u0438\u0449\u0430\u0435\u0442 \u043e\u0442 \u0444\u043b\u0443\u0434\u0430 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 fail2ban \u043d\u0435 \u0432\u0438\u0434\u0438\u0442.<\/li>\n<\/ol>\n<h3>nginx rate-limit (\u0434\u043e\u043f\u043e\u043b\u043d\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u0439 \u0431\u0430\u0440\u044c\u0435\u0440)<\/h3>\n<pre><code class=\"language-nginx\"># \/etc\/nginx\/conf.d\/rate-limit.conf\nlimit_req_zone $binary_remote_addr zone=apilogin:10m rate=5r\/s;\n\nserver {\n    location \/login {\n        limit_req zone=apilogin burst=10 nodelay;\n    }\n}\n<\/code><\/pre>\n<h3>\u0422\u0435\u0441\u0442 \u043f\u043e\u0441\u043b\u0435 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438<\/h3>\n<pre><code class=\"language-bash\"># \u041f\u0440\u043e\u0432\u0435\u0440\u0438\u0442\u044c, \u0447\u0442\u043e SSH-\u043f\u043e\u0440\u0442 \u043d\u0435\u0434\u043e\u0441\u0442\u0443\u043f\u0435\u043d \u0438\u0437 \u0437\u0430\u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0439 \u0441\u0442\u0440\u0430\u043d\u044b\n# (\u0438\u0437 \u0434\u0440\u0443\u0433\u043e\u0433\u043e \u043a\u0430\u043d\u0430\u043b\u0430\/\u0412\u041f\u041d)\nssh admin@1.2.3.4   # \u0434\u043e\u043b\u0436\u043d\u043e \u00ab\u0437\u0430\u0432\u0438\u0441\u043d\u0443\u0442\u044c\u00bb\n<\/code><\/pre>\n<hr \/>\n<h2>\u0422\u043e\u043d\u043a\u043e\u0441\u0442\u0438 \u0438 \u043f\u043e\u0434\u0432\u043e\u0434\u043d\u044b\u0435 \u043a\u0430\u043c\u043d\u0438<\/h2>\n<ul>\n<li><strong>Fast-\u043f\u0435\u0440\u0435\u0431\u043e\u0440 \u0441 \u043c\u043d\u043e\u0433\u0438\u0445 IP<\/strong> \u2014 Fail2ban \u0431\u0430\u043d\u0438\u0442 \u043f\u043e \u043e\u0434\u043d\u043e\u043c\u0443 IP. \u0415\u0441\u043b\u0438 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0439 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0443 \u0442\u0438\u043f\u0430 \u0425ydra \u0438\u0437-\u043f\u043e\u0434 VPN \u2014 \u0431\u0430\u043d\u044b \u043d\u0435 \u043f\u043e\u043c\u043e\u0433\u0443\u0442. \u041d\u0443\u0436\u0435\u043d rate-limit.<\/li>\n<li><strong>Cloudflare-\u043f\u0440\u043e\u043a\u0441\u0438<\/strong> \u2014 \u0435\u0441\u043b\u0438 \u0441\u0430\u0439\u0442 \u0437\u0430 Cloudflare, fail2ban \u0443\u0432\u0438\u0434\u0438\u0442 IP Cloudflare, \u0430 \u043d\u0435 \u043f\u043e\u0441\u0435\u0442\u0438\u0442\u0435\u043b\u044f. Add filter \u0434\u043b\u044f <code>CF-Connecting-IP<\/code> \u0438\u043b\u0438 \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0439\u0442\u0435 \u0431\u0430\u043d\u044b \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 Cloudflare.<\/li>\n<li><strong>\u041b\u043e\u0436\u043d\u044b\u0435 \u0431\u0430\u043d\u044b<\/strong> \u2014 \u043d\u0435 \u0431\u0430\u043d\u0438\u043c \u0441\u0435\u0431\u044f: \u043e\u0431\u044f\u0437\u0430\u0442\u0435\u043b\u044c\u043d\u043e <code>ignoreip<\/code> \u0432\u0430\u0448\u0435\u0433\u043e \u043e\u0444\u0438\u0441\u043d\u043e\u0433\u043e IP\/\u043f\u043e\u0434\u0441\u0435\u0442\u0435\u0439.<\/li>\n<li><strong>GeoIP-\u0441\u043f\u0438\u0441\u043a\u0438 \u043d\u0435 \u0438\u0434\u0435\u0430\u043b\u044c\u043d\u044b<\/strong> \u2014 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 \u0441\u043f\u043e\u043a\u043e\u0439\u043d\u043e \u0431\u0435\u0440\u0443\u0442 IP \u0432 \u0441\u043e\u0441\u0435\u0434\u043d\u0438\u0445 \u0441\u0442\u0440\u0430\u043d\u0430\u0445. \u0413\u0435\u043e\u0433\u0440\u0430\u0444\u0438\u044f \u2014 \u0444\u0438\u043b\u044c\u0442\u0440 \u0433\u0440\u0443\u0431\u043e\u0439 \u043e\u0447\u0438\u0441\u0442\u043a\u0438, \u043d\u0435 \u043f\u0430\u043d\u0430\u0446\u0435\u044f.<\/li>\n<li><strong>\u0421\u043c\u0435\u043d\u043d\u044b\u0439 IP \u0443 \u0432\u0430\u0441<\/strong> \u2014 \u0435\u0441\u043b\u0438 \u0443 \u0432\u0430\u0441 \u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438\u0439 IP, \u043d\u0435 \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0439\u0442\u0435 \u0441\u0432\u043e\u0439 \u0440\u0435\u0433\u0438\u043e\u043d \u0432 DROP \u0431\u0435\u0437 \u0438\u0441\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f <code>ignoreip<\/code>.<\/li>\n<li><strong>nftables geoip<\/strong> \u2014 \u043c\u043e\u0434\u0443\u043b\u044c \u043c\u043e\u0436\u0435\u0442 \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u043e\u0432\u0430\u0442\u044c \u043d\u0430 \u0434\u0435\u0444\u043e\u043b\u0442\u043d\u043e\u043c \u044f\u0434\u0440\u0435, \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0439\u0442\u0435 <code>modinfo nft_geoip<\/code>.<\/li>\n<\/ul>\n<hr \/>\n<h2>\u0428\u043f\u0430\u0440\u0433\u0430\u043b\u043a\u0430<\/h2>\n<pre><code class=\"language-bash\"># Fail2ban\nsudo apt install -y fail2ban\nfail2ban-client reload\nfail2ban-client status sshd\nfail2ban-client set sshd unbanip 1.2.3.4\n\n# GeoIP\nchmod +x \/usr\/local\/bin\/geoip-block.sh\n\/usr\/local\/bin\/geoip-block.sh\n(crontab -l; echo &quot;0 3 * * * \/usr\/local\/bin\/geoip-block.sh&quot;) | crontab -\n<\/code><\/pre>\n<p><em>\u041f\u0440\u043e\u0432\u0435\u0440\u0435\u043d\u043e \u043d\u0430: Ubuntu 22.04\/24.04.<\/em><br \/>\n<em>\u0414\u0430\u0442\u0430: \u0421\u0435\u043d\u0442\u044f\u0431\u0440\u044c 2026.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u0417\u0430\u0449\u0438\u0442\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0447\u0435\u0440\u0435\u0437 Fail2ban + GeoIP-\u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u044f \u043d\u0430 Ubuntu \u041f\u0443\u0431\u043b\u0438\u0447\u043d\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b<\/p>\n","protected":false},"author":0,"featured_media":737,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[3],"tags":[],"class_list":["post-736","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-linux"],"aioseo_notices":[],"views":7,"_links":{"self":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts\/736","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=736"}],"version-history":[{"count":2,"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts\/736\/revisions"}],"predecessor-version":[{"id":739,"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts\/736\/revisions\/739"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/media\/737"}],"wp:attachment":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=736"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=736"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=736"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}