Trying to build a IP block on hack attempts.

Started by JH042, May 27, 2026, 04:18:53 AM

Previous topic - Next topic
I'm trying to set a rule to Record an IP address and AUTO block Alias list, it if someone attempts FTP or SSH into my firewall more than X times.

This works until they attempt it on a DNAT IP address.

The advanced rule has a great feature that allows you to add IP's to an Alias.   And a different rule higher up, block any IP in that Alias.

By setting a Rule on the WAN Interface, with a BLOCK action, Destination Port 21,22,23 (example) and then moving down to the "Max new Connections[c]" and "Max new connections" and setting those to Connections: 3 and Seconds: 60

If someone attempts to connect to your OPNsense 3 times within 60 on port 21,22,23 the IP will get recorded to whatever Alias you set in "Overload Table"

Can someone help please, any suggestions are appreciate.

NAT is applied before filter rules, so the destination address needs to be the internal DNAT target, not the public address on WAN.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

Quote from: JH042 on May 27, 2026, 04:18:53 AMI'm trying to set a rule to Record an IP address and AUTO block Alias list, it if someone attempts FTP or SSH into my firewall more than X times.
Why would you allow that in the first place ?!

Also :
- If you BLOCK traffic the attacker will know something is there !!
It's much better to simply DROP the traffic and keep quiet...
- For SSH there is stuff like Fail2Ban that pretty much does what you are looking for.

But the best would be to simply put all the stuff you want to access when away from home behind either Wireguard or OpenVPN ;)
Weird guy who likes everything Linux and *BSD on PC/Laptop/Tablet/Mobile and funny little ARM based boards :)