From 7680cb490687e5e80b9d3ce501bb538db8ee1776 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Mon, 20 Jul 2026 23:49:17 +0200 Subject: [PATCH] Ban-feed --- docs/config.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/config.md b/docs/config.md index 8b464369..828eae39 100644 --- a/docs/config.md +++ b/docs/config.md @@ -2129,7 +2129,7 @@ chain. The official ntfy.sh server uses fail2ban to ban IPs. Check out ntfy.sh's [Ansible fail2ban role](https://github.com/binwiederhier/ntfy-ansible/tree/main/roles/fail2ban) for details. Ban actors are banned for 1 hour initially, and up to 4 hours at a time for repeated offenses. IPv4 addresses are banned individually, while IPv6 addresses are banned by their `/56` prefix. -#### Ban-feed +### Ban-feed In addition to the fail2ban setup above, ntfy can detect abusive visitors itself and write their IP addresses to a file for fail2ban to ban from. ntfy keeps a per-prefix weighted "strike" budget, and each rejected request costs strikes based on its response code -- the ntfy error code, or its HTTP