# Fail2Ban filter for PBX Web GUI login brute-force # Catches failed login attempts to the Laravel admin panel [INCLUDES] before = common.conf [Definition] # Match POST to /login that returns 302 (redirect back = failed login) # or 422 (validation error / CSRF) # Apache access log format: IP - - [date] "POST /login HTTP/1.1" 302 ... failregex = ^ -.*"POST /login HTTP.*" (302|422) .*$ ^ -.*"POST /login HTTP.*" 419 .*$ ignoreregex = ^ -.*"POST /login HTTP.*" 200 .*$ ^ -.*"GET /.*$