Do not lock the good guys out!

The Fail2Ban configuration must be tuned so that a large site is not accidentally kicked offline just because they are coming back online, causing all their phones to reregister at once. For example, if you have a rate limit Fail2Ban entry (eg a rule about quantity of "good" traffic, as opposed to "failed attempts" numbers), you would not want to set up Fail2Ban to block IP addresses if they happen to send 50 authentication requests in a 5 second period, because if the site has 50 phones and their power goes out, when their power comes back on all phones will attempt to register at once, resulting in them being banned. This is not the intent. Be careful in what you judge a "Denial of Service" traffic pattern.

Care must be taken when setting up Fail2Ban to test for edge case scenarios like the power outage scenario just described.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset