[Samba] Fail2Ban for AD

Philippe LeCavalier support at plecavalier.com
Sun Dec 12 03:35:57 UTC 2021


On Sat, Dec 11, 2021 at 5:48 AM mj via samba <samba at lists.samba.org> wrote:

>
>
> Op 11-12-2021 om 10:21 schreef Andrea Venturoli via samba:
> > Or ransomware protection?
> > Like:
> > https://github.com/CanaryTek/ransomware-samba-tools
> >
> > I've had a look at the latter, although I didn't get to the end yet.
>
> We are running it, although slightly adjisted to our needs/environment.
>
> It works as promised, adding yet another layer of protection aganst
> ransomware :-)
>
> MJ
>
Thanks. I was going to follow this[1] but I'm a little confused about this
"Validate that log redirection is activated in the file smb.conf" comment.
Is it just a matter of installing and configuring fail2ban or must I
"redirect" my log sys to rsyslog?

ref.
[1]
https://samba.tranquil.it/doc/en/samba_advanced_methods/samba_ad_fail2ban.html


More information about the samba mailing list