Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Ubuntu 18.04.2 LTS
- fail2ban/bionic,bionic,now 0.10.2-2 all [installed]
- only changed /etc/fail2ban/jail.d/defaults-debian.conf to:
- [sshd]
- enabled = true
- port = 22
- action = iptables-multiport
- logpath = /var/log/auth.log
- maxretry = 2
- bantime = 3600
- restarted the daemon with sysctemctl
- then trying to fail 2+ attempts from the same ext IP and it doesn't quite seem to work:
- $:/etc/fail2ban/jail.d# fail2ban-client status sshd
- Status for the jail: sshd
- |- Filter
- | |- Currently failed: 0
- | |- Total failed: 0
- | `- File list: /var/log/auth.log
- `- Actions
- |- Currently banned: 0
- |- Total banned: 0
- `- Banned IP list:
- log upon service restart says:
- 2019-04-29 15:13:33,406 fail2ban.transmitter [2797]: WARNING Command ['status', 'ssh'] has failed. Received UnknownJailException('ssh',)
- 2019-04-29 15:14:46,624 fail2ban.server [2797]: INFO Shutdown in progress...
- 2019-04-29 15:14:46,624 fail2ban.server [2797]: INFO Stopping all jails
- 2019-04-29 15:14:46,625 fail2ban.filter [2797]: INFO Removed logfile: '/var/log/auth.log'
- 2019-04-29 15:14:46,984 fail2ban.actions [2797]: NOTICE [sshd] Flush ticket(s) with iptables-multiport
- 2019-04-29 15:14:46,985 fail2ban.jail [2797]: INFO Jail 'sshd' stopped
- 2019-04-29 15:14:46,985 fail2ban.database [2797]: INFO Connection to database closed.
- 2019-04-29 15:14:46,985 fail2ban.server [2797]: INFO Exiting Fail2ban
- 2019-04-29 15:14:47,114 fail2ban.server [3075]: INFO --------------------------------------------------
- 2019-04-29 15:14:47,115 fail2ban.server [3075]: INFO Starting Fail2ban v0.10.2
- 2019-04-29 15:14:47,116 fail2ban.database [3075]: INFO Connected to fail2ban persistent database '/var/lib/fail2ban/fail2ban.sqlite3'
- 2019-04-29 15:14:47,117 fail2ban.jail [3075]: INFO Creating new jail 'sshd'
- 2019-04-29 15:14:47,119 fail2ban.jail [3075]: INFO Jail 'sshd' uses poller {}
- 2019-04-29 15:14:47,119 fail2ban.jail [3075]: INFO Initiated 'polling' backend
- 2019-04-29 15:14:47,120 fail2ban.filter [3075]: INFO maxLines: 1
- 2019-04-29 15:14:47,140 fail2ban.server [3075]: INFO Jail sshd is not a JournalFilter instance
- 2019-04-29 15:14:47,140 fail2ban.filter [3075]: INFO Added logfile: '/var/log/auth.log' (pos = 7070725, hash = 3000f5568634f4f210c166b92c6a0e5f9047f0f3)
- 2019-04-29 15:14:47,140 fail2ban.filter [3075]: INFO encoding: UTF-8
- 2019-04-29 15:14:47,141 fail2ban.filter [3075]: INFO maxRetry: 2
- 2019-04-29 15:14:47,141 fail2ban.filter [3075]: INFO findtime: 600
- 2019-04-29 15:14:47,141 fail2ban.actions [3075]: INFO banTime: 3600
- 2019-04-29 15:14:47,142 fail2ban.jail [3075]: INFO Jail 'sshd' started
- and I don't see anything in IPTABLES, well expected in this case. yet:
- Chain INPUT (policy ACCEPT)
- target prot opt source destination
- Chain FORWARD (policy ACCEPT)
- target prot opt source destination
- Chain OUTPUT (policy ACCEPT)
- target prot opt source destination
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement