SHARE
TWEET

Untitled

a guest Jul 19th, 2019 52 Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. 2019-07-19 14:18:20 ERROR: COMMAND_FAILED: Direct: '/usr/sbin/iptables-restore -w -n' failed: iptables-restore v1.4.21: Set fail2ban-ssh doesn't exist.
  2.  
  3. Error occurred at line: 2
  4. Try `iptables-restore -h' or 'iptables-restore --help' for more information.
  5.      
  6. firewalld[703]: WARNING: '/usr/sbin/iptables-restore --wait=2 -n' failed: iptables-restore v1.4.21: Set fail2ban-sshd doesn't exist.
  7.  
  8.                 Error occurred at line: 2
  9.                 Try 'iptables-restore -h' or 'iptables-restore --help' for more information.
  10. firewalld[703]: ERROR: COMMAND_FAILED
  11.      
  12. [DEFAULT]
  13. ignoreip = 127.0.0.0/8
  14. bantime  = 86400
  15. findtime = 86400
  16. maxretry = 5
  17.  
  18. # Override /etc/fail2ban/jail.d/00-firewalld.conf:
  19. banaction = firewallcmd-ipset
  20.  
  21. [sshd]
  22. enabled = true
  23.  
  24. [ssh]
  25. enabled  = true
  26. filter   = sshd
  27. action   = %(action_)s
  28. logpath  = /var/log/secure
  29. maxretry = 5
  30.      
  31. sudo yum install firewalld
  32. sudo systemctl start firewalld
  33. sudo firewall-cmd --permanent --add-service=ssh
  34. sudo firewall-cmd --permanent --add-service=http
  35. sudo firewall-cmd --permanent --add-service=https
  36. sudo firewall-cmd --permanent --remove-service=smtp
  37. sudo systemctl enable firewalld
  38.      
  39. # firewall-cmd --direct --get-all-rules
  40.      
  41. ipv4 filter INPUT 0 -p tcp -m multiport --dports ssh -m set --match-set fail2ban-sshd src -j REJECT --reject-with icmp-port-unreachable
  42. ipv4 filter INPUT 0 -p tcp -m multiport --dports 0:65535 -m set --match-set fail2ban-ssh src -j REJECT --reject-with icmp-port-unreachable
RAW Paste Data
We use cookies for various purposes including analytics. By continuing to use Pastebin, you agree to our use of cookies as described in the Cookies Policy. OK, I Understand
 
Top