diff --git a/README.md b/README.md index 9f2dce7..b1b21d3 100644 --- a/README.md +++ b/README.md @@ -99,6 +99,23 @@ The `router-drop.sh` script requires two configuration steps: * configure the `ROUTER` variable to a SSH string for root login to the router (e.g. *root@gw.example.com*) * install SSH keys to actually log in; the keys need to be installed on root account as this is where active response script are running +Example configuration: + + + router-drop + router-drop.sh + srcip + no + + + + router-drop + local + 51004 + + +Event 51004 is defined in `/var/ossec/rules/dropbear_rules.xml` and triggered by a series of unsuccessful password logins. Don't forget to add your trusted networks to `` entries to prevent locking yourself out! + ## Samples Number of blacklisted IP addresses: