feat(pillar.example,test/): add example and test for richrule ratelimit

Document and test the accept rate limiting of the rich rule.

Signed-off-by: Arnaud Patard <apatard@hupstream.com>
This commit is contained in:
Arnaud Patard 2021-01-21 11:39:55 +01:00
parent a2f4f3b36e
commit f25852637a
14 changed files with 99 additions and 0 deletions

View File

@ -126,6 +126,14 @@ firewalld:
name: fail2ban-ssh name: fail2ban-ssh
reject: reject:
type: icmp-port-unreachable type: icmp-port-unreachable
- accept:
limit: "3/m"
log:
level: warning
limit: "3/m"
prefix: "http fw limit 3/m"
service: http
ports: ports:
# {%- if grains['id'] == 'salt.example.com' %} # {%- if grains['id'] == 'salt.example.com' %}
- comment: salt-master - comment: salt-master

View File

@ -37,6 +37,13 @@ control 'zones/public.xml configuration' do
<source ipset="fail2ban-ssh" /> <source ipset="fail2ban-ssh" />
<reject type="icmp-port-unreachable" /> <reject type="icmp-port-unreachable" />
</rule> </rule>
<rule>
<service name="http" />
<log prefix="http fw limit 3/m" level="warning">
<limit value="3/m"/>
</log>
<accept> <limit value="3/m"/></accept>
</rule>
</zone> </zone>
ZONE_XML ZONE_XML
end end

View File

@ -134,6 +134,13 @@ values:
name: fail2ban-ssh name: fail2ban-ssh
reject: reject:
type: icmp-port-unreachable type: icmp-port-unreachable
- accept:
limit: "3/m"
log:
level: warning
limit: "3/m"
prefix: "http fw limit 3/m"
service: http
services: services:
- http - http
- https - https

View File

@ -134,6 +134,13 @@ values:
name: fail2ban-ssh name: fail2ban-ssh
reject: reject:
type: icmp-port-unreachable type: icmp-port-unreachable
- accept:
limit: "3/m"
log:
level: warning
limit: "3/m"
prefix: "http fw limit 3/m"
service: http
services: services:
- http - http
- https - https

View File

@ -134,6 +134,13 @@ values:
name: fail2ban-ssh name: fail2ban-ssh
reject: reject:
type: icmp-port-unreachable type: icmp-port-unreachable
- accept:
limit: "3/m"
log:
level: warning
limit: "3/m"
prefix: "http fw limit 3/m"
service: http
services: services:
- http - http
- https - https

View File

@ -134,6 +134,13 @@ values:
name: fail2ban-ssh name: fail2ban-ssh
reject: reject:
type: icmp-port-unreachable type: icmp-port-unreachable
- accept:
limit: "3/m"
log:
level: warning
limit: "3/m"
prefix: "http fw limit 3/m"
service: http
services: services:
- http - http
- https - https

View File

@ -134,6 +134,13 @@ values:
name: fail2ban-ssh name: fail2ban-ssh
reject: reject:
type: icmp-port-unreachable type: icmp-port-unreachable
- accept:
limit: "3/m"
log:
level: warning
limit: "3/m"
prefix: "http fw limit 3/m"
service: http
services: services:
- http - http
- https - https

View File

@ -134,6 +134,13 @@ values:
name: fail2ban-ssh name: fail2ban-ssh
reject: reject:
type: icmp-port-unreachable type: icmp-port-unreachable
- accept:
limit: "3/m"
log:
level: warning
limit: "3/m"
prefix: "http fw limit 3/m"
service: http
services: services:
- http - http
- https - https

View File

@ -134,6 +134,13 @@ values:
name: fail2ban-ssh name: fail2ban-ssh
reject: reject:
type: icmp-port-unreachable type: icmp-port-unreachable
- accept:
limit: "3/m"
log:
level: warning
limit: "3/m"
prefix: "http fw limit 3/m"
service: http
services: services:
- http - http
- https - https

View File

@ -134,6 +134,13 @@ values:
name: fail2ban-ssh name: fail2ban-ssh
reject: reject:
type: icmp-port-unreachable type: icmp-port-unreachable
- accept:
limit: "3/m"
log:
level: warning
limit: "3/m"
prefix: "http fw limit 3/m"
service: http
services: services:
- http - http
- https - https

View File

@ -134,6 +134,13 @@ values:
name: fail2ban-ssh name: fail2ban-ssh
reject: reject:
type: icmp-port-unreachable type: icmp-port-unreachable
- accept:
limit: "3/m"
log:
level: warning
limit: "3/m"
prefix: "http fw limit 3/m"
service: http
services: services:
- http - http
- https - https

View File

@ -134,6 +134,13 @@ values:
name: fail2ban-ssh name: fail2ban-ssh
reject: reject:
type: icmp-port-unreachable type: icmp-port-unreachable
- accept:
limit: "3/m"
log:
level: warning
limit: "3/m"
prefix: "http fw limit 3/m"
service: http
services: services:
- http - http
- https - https

View File

@ -134,6 +134,13 @@ values:
name: fail2ban-ssh name: fail2ban-ssh
reject: reject:
type: icmp-port-unreachable type: icmp-port-unreachable
- accept:
limit: "3/m"
log:
level: warning
limit: "3/m"
prefix: "http fw limit 3/m"
service: http
services: services:
- http - http
- https - https

View File

@ -134,6 +134,13 @@ values:
name: fail2ban-ssh name: fail2ban-ssh
reject: reject:
type: icmp-port-unreachable type: icmp-port-unreachable
- accept:
limit: "3/m"
log:
level: warning
limit: "3/m"
prefix: "http fw limit 3/m"
service: http
services: services:
- http - http
- https - https