Dear martin f krafft, Although it seems to be a very minor wish (INPUT is "hardcoded" just in 3 commands: fw{start,end,check}), indeed there might be no harm of adding such an option. I am not sure on how much use would be to override it on per section basis but that will come for free...
Meanwhile, since this config allows "interpolations" you can add it yourself: just define variable in DEFAULTS fwchain=INPUT and then replace all occurrences of INPUT in the fw-rules with %(fwchain)s feel free to override it on per section basis ;-) Hope that helps P.S. Very soon fail2ban configs will be replaced with "split" config files (I have working version alrady but we together with upstream decided to go a bit beyound simply splitting them...), so upgrades will go smoother for people with custom modifications. Before that I am trying to stay away from modifying config file without necessity, so I will submit a fix for this wishlist if there is another change in config file to accompany. -- .-. =------------------------------ /v\ ----------------------------= Keep in touch // \\ (yoh@|www.)onerussian.com Yaroslav Halchenko /( )\ ICQ#: 60653192 Linux User ^^-^^ [175555]
pgpP7xLcCN0YP.pgp
Description: PGP signature