Debian 11 - FirewallD - Fail2Ban

Thank you very much for your comprehensive and precious help.

I think we can stop the troubleshooting now. I set up a new Debian 11 server and with your lines in the 00-firewalld.conf file it started banning right away. But not with the single line which comes out of the box. I have to guess, that something happened also in the installation process we do not know.

My Ubuntu 22.04 server has never banned, no matter what I set in place of your suggestions. His fail2band log goes bezerk. It generated sometimes more than 100 lines per second, it contains after 5 days in production 500MB. The firewalld log is almost empty.

So my final solution is for now: Setup a new server, never mind the derivative, and add the lines

[DEFAULT]
banaction = firewallcmd-rich-rules
banaction_allports = firewallcmd-rich-rules

in your /etc/fail2ban/jail.d/00-firewalld.conf

and everything is fine. And then open a fine bottle of whisky and enjoy life again.

Thank you guys!

1 Like