Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Next challenges

Recent achievements

  • Global
  • Personal

Recognition

  • Give kudos
  • Received
  • Given

Leaderboard

  • Global

Trophy case

Kudos (beta program)

Kudos logo

You've been invited into the Kudos (beta program) private group. Chat with others in the program, or give feedback to Atlassian.

View group

It's not the same without you

Join the community to find out what other Atlassian users are discussing, debating and creating.

Atlassian Community Hero Image Collage

fail2ban implementation for JIRA

Can anyone share your action and filter files for implementing fail2ban on JIRA.

I was trying to configure fail2ban on our system and looking for best methods for implementing it effectively.

Any help is highly appreciated.........

3 answers

Thanks for replying but there regular expressions will trigger only for almost every login page count
failregex = <HOST>.*"GET /login.jsp

but we need these alerts to be triggered based on incorrect counts and not on login page count.

For example if you use above failregex then count will be increased as soon as you open a new tab and enter JIRA login URL.

I had gone through Justin link as well and also added my question(comment) yesterday itself.

So I needed something which has better implementation of filters to encounter all intruders.

The confluence documentation (https://confluence.atlassian.com/adminjiraserver073/using-fail2ban-to-limit-login-attempts-861253903.html) is half-baked and might lock you out with successful login attempts. Also  the GET definition seems wrong.


The jail definition in filter.d will work with this (checked on v7.6.2 and Fail2ban 0.9.3)

----------
[Definition]
failregex = <HOST>.*"POST /rest/gadget/1.0/login HTTP/1.1" 200 219
            <HOST>.*"POST /login.jsp HTTP/1.1" 200
ignoreregex=
----------


#1: this is using the fact that the message size is 220 when it succeeds and 219 when it fails
#2: this is using the fact that a sucessful login will return 302 (redirect) while it returns 200 if the login fails

 

YMMV

Suggest an answer

Log in or Sign up to answer
TAGS

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you