You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Mosquitto最大认证尝试次数设置及防暴力破解方案咨询

Securing Mosquitto Against Brute-Force Attacks & Setting Auth Attempt Limits

Great question—securing your Mosquitto broker against brute-force attempts is crucial, especially if you're exposing it to untrusted networks. Let's break down both built-in options and external tools/plugins to handle this:

Built-in Mosquitto Configurations

While Mosquitto doesn't have a direct "max authentication attempts per user/IP" setting out of the box, you can use these built-in features to slow down and mitigate brute-force risks:

  • Disable anonymous access: First and foremost, set allow_anonymous false in your mosquitto.conf—this forces all clients to authenticate, blocking random unauthenticated brute-force probes entirely.
  • Add delays for failed auth attempts: Use the auth_opt_deny_delay parameter (available in Mosquitto 2.0+) to add a delay before rejecting failed authentication requests. This slows down brute-force bots by making each attempt take longer. Example config:
    auth_plugin /usr/lib/mosquitto_dynamic_security.so
    auth_opt_deny_delay 5
    
    This adds a 5-second delay to failed auth responses.
  • Per-listener security settings: Use per_listener_settings true to apply stricter rules to public-facing listeners (e.g., port 1883 or 8883) while keeping internal listeners more permissive.

External Plugins for Granular Control

For proper "max auth attempt" limits and account locking, these plugins are your best bet:

  • Mosquitto Dynamic Security Plugin (Official): This official plugin lets you manage users, roles, and ACLs dynamically. You can configure it to lock a user account after a set number of failed login attempts. To set this up:
    1. Enable the plugin in mosquitto.conf:
      plugin /usr/lib/mosquitto_dynamic_security.so
      plugin_opt_config_file /etc/mosquitto/dynamic-security.json
      
    2. Use the mosquitto_ctrl command to set login failure limits. For example, to lock a user named myuser after 3 failed attempts:
      mosquitto_ctrl dynsec setClientLimits myuser --maxLoginAttempts 3
      
  • mosquitto-auth-plug (Community): This flexible community plugin supports multiple backends (Redis, PostgreSQL, etc.) and can track failed auth attempts. You can configure it to block a user/IP after a threshold of failed tries by leveraging a Redis cache to count attempts and enforce temporary or permanent bans.

Additional Brute-Force Mitigation Tools

Even with plugin-based controls, adding these layers makes your broker far more resilient:

  • Fail2ban: Monitor Mosquitto's log files (usually at /var/log/mosquitto/mosquitto.log) for failed auth messages, then automatically ban IPs that exceed a set threshold. You'll need to create a custom Fail2ban filter that matches lines like Client <client-id> disconnected, not authorised.
  • Firewall Rules: Use iptables or ufw to limit the number of incoming connections from a single IP. For example, with ufw, you can allow only 5 connections per minute to port 1883:
    ufw limit 1883/tcp
    

Final Notes

Always keep your Mosquitto broker updated to the latest version—new security features are added regularly. Also, use strong, unique passwords for all MQTT clients, and consider using TLS/SSL (port 8883) to encrypt authentication traffic and prevent credential sniffing.

内容的提问来源于stack exchange,提问作者Salman R

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:16:04