fail2ban-https
==============

RealEd fail2ban jail that hard-bans abusive HTTPS clients via **refw**.

What it does
------------

- Watches Apache access logs (vhost-combined style: `host:443 client …`).
- On match, runs: `refw add fail2ban ban <ip> --timeout=<bantime>`
- Unban: `refw delete fail2ban ban <ip>`
- Enforcement is the nft set `@f2b_ban` (`ip saddr @f2b_ban drop` in
  `inet refw` / chain `screen`).

There is no iptables/ipset plumbing. Membership is volatile (kernel only);
fail2ban’s own DB tracks tickets. After `refw apply` (or a wiped table),
restart the jail so bans are restored into nft:

    fail2ban-client restart apache-https

Requirements
------------

- Package **refw** installed and applied (`refw apply`).
- Feature `fail2ban` enabled (default when `/etc/fail2ban` exists).
- Package **fail2ban**.

Files
-----

| Path | Role |
|------|------|
| `/etc/fail2ban/filter.d/apache-https.conf` | log match |
| `/etc/fail2ban/action.d/apache-https.conf` | ban via refw |
| `/etc/fail2ban/jail.d/apache-https.conf` | jail (written by postinst) |
| `/usr/share/doc/fail2ban-https/apache-https.conf` | jail template |

The postinst discovers Apache log paths and rewrites `logpath` in the jail
file. If an existing jail differs, it may write `.new` for review.

Operations
----------

    fail2ban-client status apache-https
    refw list fail2ban ban
    refw show                   # live members under “rule fail2ban”
    nft list set inet refw f2b_ban

Jail name is **apache-https** (not the package name fail2ban-https).

See also
--------

- `man 8 refw`
- Package **ratelimiter-realed** (soft crawl via `@f2b_ratelimit`)
