Fail2ban, не запрещающий IP

Выполнение новой установки OpenSuse 13.2 (Работающий rsyslog)

Мой jail.conf файл содержит:

[ssh-iptables]

enabled  = true
filter   = sshd
action   = iptables[name=SSH, port=ssh, protocol=tcp]
       sendmail-whois[name=SSH, dest=mymail@gmail.com, sender=mymail@gmail.com,     sendername="Fail2Ban"]
logpath  = /var/log/messages
maxretry = 5

/var/log/messages:

2014-11-21T16:16:17.167566-05:00 suse sshd[31000]: error: PAM: Authentication failure for root from 62-210-172-145.rev.poneytelecom.eu
2014-11-21T16:16:17.232040-05:00 suse sshd[31000]: Received disconnect from 62.210.172.145: 11:  [preauth]
2014-11-21T16:16:17.863395-05:00 suse sshd[31007]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=62-210-172-145.rev.poneytelecom.eu  user=root

файл журнала fail2ban:

2014-11-21 21:10:06,426 fail2ban.server [30553]: INFO    Changed logging target to /var/log/fail2ban.log for Fail2ban v0.8.14
2014-11-21 21:10:06,428 fail2ban.jail   [30553]: INFO    Creating new jail 'ssh-iptables'
2014-11-21 21:10:06,479 fail2ban.jail   [30553]: INFO    Jail 'ssh-iptables' uses pyinotify
2014-11-21 21:10:06,526 fail2ban.jail   [30553]: INFO    Initiated 'pyinotify' backend
2014-11-21 21:10:06,529 fail2ban.filter [30553]: INFO    Added logfile = /var/log/messages
2014-11-21 21:10:06,532 fail2ban.filter [30553]: INFO    Set maxRetry = 5
2014-11-21 21:10:06,537 fail2ban.filter [30553]: INFO    Set findtime = 600
2014-11-21 21:10:06,539 fail2ban.actions[30553]: INFO    Set banTime = -1
2014-11-21 21:10:06,639 fail2ban.jail   [30553]: INFO    Jail 'ssh-iptables' started
2014-11-21 21:10:21,142 fail2ban.filter [30553]: WARNING Determined IP using DNS Lookup: 62-210-    172-145.rev.poneytelecom.eu = ['62.210.172.145']
2014-11-21 21:10:21,144 fail2ban.filter [30553]: WARNING Determined IP using DNS Lookup: 62-210-172-145.rev.poneytelecom.eu = ['62.210.172.145']
2014-11-21 21:10:21,147 fail2ban.filter [30553]: WARNING Determined IP using DNS Lookup: 62-210-172-145.rev.poneytelecom.eu = ['62.210.172.145']
2014-11-21 21:10:21,149 fail2ban.filter [30553]: WARNING Determined IP using DNS Lookup: 62-210-172-145.rev.poneytelecom.eu = ['62.210.172.145']
2014-11-21 21:10:21,151 fail2ban.filter [30553]: WARNING Determined IP using DNS Lookup: 62-210-172-145.rev.poneytelecom.eu = ['62.210.172.145']

Какие-либо идеи, почему не запрет IP?

server:/etc/fail2ban # fail2ban-client status ssh-iptables
Status for the jail: ssh-iptables   
|- filter
|  |- File list:        /var/log/messages
|  |- Currently failed: 0
|  `- Total failed:     0

Результаты fail2ban-regex

Results
=======

Failregex: 1256 total
|-  #) [# of hits] regular expression
|   1) [858] ^\s*(<[^.]+\.[^.]+>)?\s*(?:\S+ )?(?:kernel: \[ *\d+\.\d+\] )?(?:@vserver_\S+ )?(?:  (?:\[\d+\])?:\s+[\[\(]?sshd(?:\(\S+\))?[\]\)]?:?|[\[\(]?sshd(?:\(\S+\))?[\]\)]?:?(?:\[\d+\])?:?)? \s(?:\[ID \d+ \S+\])?\s*(?:error: PAM: )?[aA]uthentication (?:failure|error) for .* from <HOST>( via  \S+)?\s*$
|   2) [30] ^\s*(<[^.]+\.[^.]+>)?\s*(?:\S+ )?(?:kernel: \[ *\d+\.\d+\] )?(?:@vserver_\S+ )?(?:(?:\[\d+\])?:\s+[\[\(]?sshd(?:\(\S+\))?[\]\)]?:?|[\[\(]?sshd(?:\(\S+\))?[\]\)]?:?(?:\[\d+\])?:?)?\s(?:\[ID \d+ \S+\])?\s*(?:error: PAM: )?User not known to the underlying authentication module for  .* from <HOST>\s*$
|   3) [141] ^\s*(<[^.]+\.[^.]+>)?\s*(?:\S+ )?(?:kernel: \[ *\d+\.\d+\] )?(?:@vserver_\S+ )?(?:(?:\[\d+\])?:\s+[\[\(]?sshd(?:\(\S+\))?[\]\)]?:?|[\[\(]?sshd(?:\(\S+\))?[\]\)]?:?(?:\[\d+\])?:?)?\s(?:\[ID \d+ \S+\])?\s*Failed \S+ for .*? from <HOST>(?: port \d*)?(?: ssh\d*)?(: (ruser .*|(\S+ ID \S+ \(serial \d+\) CA )?\S+ (?:[\da-f]{2}:){15}[\da-f]{2}(, client user ".*", client host ".*")?))?\s*$
|   5) [227] ^\s*(<[^.]+\.[^.]+>)?\s*(?:\S+ )?(?:kernel: \[ *\d+\.\d+\] )?(?:@vserver_\S+ )?(?:(?:\[\d+\])?:\s+[\[\(]?sshd(?:\(\S+\))?[\]\)]?:?|[\[\(]?sshd(?:\(\S+\))?[\]\)]?:?(?:\[\d+\])?:?)?\s(?:\[ID \d+ \S+\])?\s*[iI](?:llegal|nvalid) user .* from <HOST>\s*$
`-

Ignoreregex: 0 total

Date template hits:
|- [# of hits] date format
|  [33235] ISO 8601
`-

Lines: 33235 lines, 0 ignored, 1256 matched, 31979 missed
Missed line(s): too many to print.  Use --print-all-missed to print all 31979 lines
2
задан 23 November 2014 в 20:05
1 ответ

Какую версию fail2ban вы используете? У меня была проблема с fail2ban, который поставляется с дистрибутивом OpenSuse по умолчанию. Даже совпадение с регулярным выражением не было запрещено. Теперь я использую fail2ban-0.8.14-2.24.1.noarch.rpm с OpenSue 13.1, и он работает нормально.

2
ответ дан 3 December 2019 в 11:40

Теги

Похожие вопросы