Mosquitto最大认证尝试次数设置及防暴力破解方案咨询
Great question—securing your Mosquitto broker against brute-force attempts is crucial, especially if you're exposing it to untrusted networks. Let's break down both built-in options and external tools/plugins to handle this:
Built-in Mosquitto Configurations
While Mosquitto doesn't have a direct "max authentication attempts per user/IP" setting out of the box, you can use these built-in features to slow down and mitigate brute-force risks:
- Disable anonymous access: First and foremost, set
allow_anonymous falsein yourmosquitto.conf—this forces all clients to authenticate, blocking random unauthenticated brute-force probes entirely. - Add delays for failed auth attempts: Use the
auth_opt_deny_delayparameter (available in Mosquitto 2.0+) to add a delay before rejecting failed authentication requests. This slows down brute-force bots by making each attempt take longer. Example config:
This adds a 5-second delay to failed auth responses.auth_plugin /usr/lib/mosquitto_dynamic_security.so auth_opt_deny_delay 5 - Per-listener security settings: Use
per_listener_settings trueto apply stricter rules to public-facing listeners (e.g., port 1883 or 8883) while keeping internal listeners more permissive.
External Plugins for Granular Control
For proper "max auth attempt" limits and account locking, these plugins are your best bet:
- Mosquitto Dynamic Security Plugin (Official): This official plugin lets you manage users, roles, and ACLs dynamically. You can configure it to lock a user account after a set number of failed login attempts. To set this up:
- Enable the plugin in
mosquitto.conf:plugin /usr/lib/mosquitto_dynamic_security.so plugin_opt_config_file /etc/mosquitto/dynamic-security.json - Use the
mosquitto_ctrlcommand to set login failure limits. For example, to lock a user namedmyuserafter 3 failed attempts:mosquitto_ctrl dynsec setClientLimits myuser --maxLoginAttempts 3
- Enable the plugin in
- mosquitto-auth-plug (Community): This flexible community plugin supports multiple backends (Redis, PostgreSQL, etc.) and can track failed auth attempts. You can configure it to block a user/IP after a threshold of failed tries by leveraging a Redis cache to count attempts and enforce temporary or permanent bans.
Additional Brute-Force Mitigation Tools
Even with plugin-based controls, adding these layers makes your broker far more resilient:
- Fail2ban: Monitor Mosquitto's log files (usually at
/var/log/mosquitto/mosquitto.log) for failed auth messages, then automatically ban IPs that exceed a set threshold. You'll need to create a custom Fail2ban filter that matches lines likeClient <client-id> disconnected, not authorised. - Firewall Rules: Use
iptablesorufwto limit the number of incoming connections from a single IP. For example, withufw, you can allow only 5 connections per minute to port 1883:ufw limit 1883/tcp
Final Notes
Always keep your Mosquitto broker updated to the latest version—new security features are added regularly. Also, use strong, unique passwords for all MQTT clients, and consider using TLS/SSL (port 8883) to encrypt authentication traffic and prevent credential sniffing.
内容的提问来源于stack exchange,提问作者Salman R

