diff --git a/roles/nginxplus/files/fail2ban/nginx-bad-httpbots.conf b/roles/nginxplus/files/fail2ban/nginx-bad-httpbots.conf index 6bf2f8959f..0b2ea2a832 100644 --- a/roles/nginxplus/files/fail2ban/nginx-bad-httpbots.conf +++ b/roles/nginxplus/files/fail2ban/nginx-bad-httpbots.conf @@ -3,6 +3,6 @@ enabled = true port = http,https filter = nginx-f_inclusive logpath = /var/log/nginx/access.log -maxretry = 3 +maxretry = 10 findtime = 3600 bantime = 3600 diff --git a/roles/nginxplus/files/fail2ban/nginx-f_inclusive.conf b/roles/nginxplus/files/fail2ban/nginx-f_inclusive.conf index 02febb45b7..061834ccfb 100644 --- a/roles/nginxplus/files/fail2ban/nginx-f_inclusive.conf +++ b/roles/nginxplus/files/fail2ban/nginx-f_inclusive.conf @@ -1,3 +1,3 @@ [Definition] -failregex = ^\{\"remote_ip\"\: \"\".{45,80}\"uri\"\:.{4,}?(?:\&?f(?:_inclusive)?%%5B.{5,}?){20,} +failregex = ^\{\"remote_ip\"\: \"\".{45,80}\"uri\"\:.{4,}?(?:\&?f(?:_inclusive)?%%5B.{5,}?){15,} ignoreregex =