logging_ipv[46].conf: add missing parameter 'log_blocked_ip'.

This commit is contained in:
Christoph 2025-02-15 10:59:53 +01:00
parent aab8585d90
commit 71e01e8413
4 changed files with 8 additions and 4 deletions

View File

@ -40,6 +40,8 @@ log_prohibited=false
log_voip=false log_voip=false
log_rejected=true log_rejected=true
log_blocked_ip=false
log_ssh=false log_ssh=false
# - logging messages # - logging messages

View File

@ -40,6 +40,8 @@ log_prohibited=false
log_voip=false log_voip=false
log_rejected=true log_rejected=true
log_blocked_ip=false
log_ssh=false log_ssh=false
# - logging messages # - logging messages

View File

@ -547,9 +547,9 @@ if [[ -f "$conf_ban_ipv6_list" ]] ; then
for _dev in ${ext_if_arr[@]} ; do for _dev in ${ext_if_arr[@]} ; do
if $log_blocked_ip || $log_all ; then if $log_blocked_ip || $log_all ; then
$ip6t -A INPUT -i $_dev -s $_ip -j $LOG_TARGET $tag_log_prefix "$log_prefix Blocked: " $ip6t -A INPUT -i $_dev -s $_ip -j $LOG_TARGET $tag_log_prefix "$log_prefix Blocked by ban_ipv6.list: "
if $kernel_forward_between_interfaces ; then if $kernel_forward_between_interfaces ; then
$ip6t -A FORWARD -i $_dev -s $_ip -j $LOG_TARGET $tag_log_prefix "$log_prefix Blocked: " $ip6t -A FORWARD -i $_dev -s $_ip -j $LOG_TARGET $tag_log_prefix "$log_prefix Blocked by ban_ipv6.list: "
fi fi
fi fi

View File

@ -675,9 +675,9 @@ if [[ -f "$conf_ban_ipv4_list" ]] ; then
for _dev in ${ext_if_arr[@]} ; do for _dev in ${ext_if_arr[@]} ; do
if $log_blocked_ip || $log_all ; then if $log_blocked_ip || $log_all ; then
$ipt -A INPUT -i $_dev -s $_ip -j $LOG_TARGET $tag_log_prefix "$log_prefix Blocked:" $ipt -A INPUT -i $_dev -s $_ip -j $LOG_TARGET $tag_log_prefix "$log_prefix Blocked by ban_ipv4.list:"
if $kernel_activate_forwarding ; then if $kernel_activate_forwarding ; then
$ipt -A FORWARD -i $_dev -s $_ip -j $LOG_TARGET $tag_log_prefix "$log_prefix Blocked:" $ipt -A FORWARD -i $_dev -s $_ip -j $LOG_TARGET $tag_log_prefix "$log_prefix Blocked by ban_ipv4.list::"
fi fi
fi fi
$ipt -A INPUT -i $_dev -s $_ip -j DROP $ipt -A INPUT -i $_dev -s $_ip -j DROP