|
From: Kevin Z. <kev...@gm...> - 2015-08-10 21:05:32
|
On 08/10/2015 14:58, James Harris wrote: > This is how the iptables backend works. Sshguard puts all rules into a > table 'sshguard' it is then left to the user to use that table in the > correct place. Which as pointed out, is one rule. Personally I like this > design as it requires a level of interaction and understanding by the > user. It also means sshguard can run in a completely normal mode of > operation but not actually block during an evaluation period. I think I like this option the most. This is already what the 'pf' backend does. The reason I was considering automatically adding the rules was because that's what the original 'ipfw' backend did, but seeing that it now uses tables that is no longer necessary. Best, Kevin Zheng -- Kevin Zheng kev...@gm... | ke...@kd... | PGP: 0xC22E1090 |