summaryrefslogtreecommitdiff
path: root/modules/nixos/fail2ban.nix
diff options
context:
space:
mode:
Diffstat (limited to 'modules/nixos/fail2ban.nix')
-rw-r--r--modules/nixos/fail2ban.nix32
1 files changed, 32 insertions, 0 deletions
diff --git a/modules/nixos/fail2ban.nix b/modules/nixos/fail2ban.nix
new file mode 100644
index 0000000..5ac3c9c
--- /dev/null
+++ b/modules/nixos/fail2ban.nix
@@ -0,0 +1,32 @@
+{
+ config,
+ lib,
+ this,
+ ...
+}:
+with lib; let
+ cfg = config.nixfiles.modules.fail2ban;
+in {
+ options.nixfiles.modules.fail2ban.enable =
+ mkEnableOption "fail2ban";
+
+ config = mkIf cfg.enable {
+ services.fail2ban = {
+ enable = true;
+
+ bantime-increment = {
+ enable = true;
+ maxtime = "24h";
+ rndtime = "8m";
+ };
+
+ ignoreIP =
+ optionals (hasAttr "wireguard" this)
+ (with config.nixfiles.modules.wireguard; [ipv4.subnet ipv6.subnet]);
+
+ jails.DEFAULT = ''
+ blocktype = DROP
+ '';
+ };
+ };
+}