ratelimiter-realed
==================

RealEd fail2ban jail that puts chatty HTTP(S) clients into a **soft
rate-limit / crawl** via **refw** (not a hard ban).

What it does
------------

- Watches Apache access logs (default `access.log`, often a symlink to
  `other_vhosts_access.log` — see preinst).
- Trips when ≥30 matching hits in 60s (configurable in the jail).
- On trip: `refw add fail2ban ratelimit <ip> --timeout=<bantime>`
- Unban: `refw delete fail2ban ratelimit <ip>`

Enforcement lives entirely in **refw** (after `refw apply` with feature
`ratelimit`):

- **Inbound:** new TCP 80/443 from `@f2b_ratelimit` limited
  (10/minute burst 20) in chain `screen`.
- **Outbound crawl:** replies to those IPs get fwmark 1; **tc** HTB on
  the default-route interface shapes mark 1 to **1 mbit**.

This package no longer creates ipsets, iptables chains, or tc qdiscs.
Pre-2.0 leftovers (`RATELIMITED`, ipset `ratelimited`, mangle MARK) can be
removed with refw’s migration helper:

    /usr/share/refw/clean-legacy-iptables.sh --dry-run
    /usr/share/refw/clean-legacy-iptables.sh

Requirements
------------

- Package **refw** installed and applied (`refw apply`).
- Feature `ratelimit` (default when `/etc/fail2ban` exists).
- Package **fail2ban**.

Files
-----

| Path | Role |
|------|------|
| `/etc/fail2ban/filter.d/ratelimiter-realed.conf` | log match |
| `/etc/fail2ban/action.d/ratelimiter-realed.conf` | add/delete via refw |
| `/etc/fail2ban/jail.d/ratelimiter-realed.conf` | jail definition |
| `/etc/fail2ban/fail2ban.local` | `allowipv6 = auto` |

Operations
----------

    fail2ban-client status ratelimiter-realed
    refw list fail2ban ratelimit
    refw show                   # members under “rule ratelimit”
    nft list set inet refw f2b_ratelimit
    refw status                 # tc shape line when feature on

After a table wipe or fresh apply, restore fail2ban tickets into nft:

    fail2ban-client restart ratelimiter-realed

See also
--------

- `man 8 refw`
- Package **fail2ban-https** (hard ban via `@f2b_ban`)
