# ============================================================================= # Web GUI portal brute-force detection (watches Apache access log for POST # /login failures). Installed by `php artisan pbx:deploy`. # # The logpath is written dynamically by PbxDeploy::setupWebLoginProtection() # based on whether the box uses HTTPS (pbx-ssl-access.log) or HTTP-only # (access.log). This template is the HTTPS default; the deploy step overwrites # the logpath line for HTTP-only boxes. # ============================================================================= [pbx-portal] enabled = true port = http,https filter = pbx-portal logpath = /var/log/apache2/pbx-ssl-access.log backend = polling maxretry = 5 findtime = 300 bantime = 3600