diff --git a/defaults/main.yml b/defaults/main.yml index 041d1ba..621e915 100644 --- a/defaults/main.yml +++ b/defaults/main.yml @@ -49,10 +49,10 @@ vm_dirty_background_ratio: 5 vm_swappiness: "{{ proxmox_swapiness }}" # Fail2ban settings -f2b_bantime: 1800 # 30 minutes -f2b_findtime: 600 +f2b_bantime: 600 # 10 minutes +f2b_findtime: 1200 # 20 minutes f2b_maxretry: 5 -f2b_recidive_bantime: 86400 # 24 hours +f2b_recidive_bantime: 3600 # 1 hours f2b_recidive_findtime: 86400 # 24 hours f2b_recidive_maxretry: 3 f2b_ipset_name: f2b-blacklist diff --git a/handlers/main.yml b/handlers/main.yml index 600b186..dd5e59b 100644 --- a/handlers/main.yml +++ b/handlers/main.yml @@ -32,10 +32,18 @@ ansible.builtin.systemd: daemon_reload: true -- name: Restart fail2ban +- name: Reload fail2ban ansible.builtin.systemd: name: fail2ban state: reloaded + enabled: true + +- name: Restart fail2ban + ansible.builtin.systemd: + name: fail2ban + state: restarted + enabled: true + - name: Reload pve firewall ansible.builtin.command: pve-firewall reload