dimgr  
                
                  
                    May 23, 2024,  5:42am
                   
                  1 
               
             
            
              Hello. vps server with ubuntu 2204.
I get many messages about a problem with Fail2Ban. Echod read various solutions but I didn’t succeed. A help please.
2024-05-23 08:27:57,361 fail2ban.filter         [613]: INFO    [postfix-sasl] Found 194.169.175.17 - 2024-05-23 08:27:56
For email
The IP 194.169.175.17 has just been banned by Fail2Ban after
Here is more information about 194.169.175.17 :
missing whois program
Regards,
Fail2Ban
Hi,
The IP 194.169.175.20 has just been banned by Fail2Ban after
Here is more information about 194.169.175.20 :
missing whois program
Regards,
Fail2Ban
             
            
              
            
           
          
            
              
                jimr1  
                
                  
                    May 23, 2024,  5:47am
                   
                  2 
               
             
            
              
 dimgr:
 
missing whois program
 
 
have you got whois installed ?
             
            
              
            
           
          
            
            
              
Thats a notice from fail2ban, search for the IP in the mail log, do you see any connections to postfix/smtpd after the ban. If not then its been blocked.
             
            
              
            
           
          
            
              
                dimgr  
              
                  
                    May 23, 2024,  7:06am
                   
                  4 
               
             
            
              I have no definition, these are from the installation of virtualmin.
             
            
              
            
           
          
            
            
              Search for say 194.169.175.17
             
            
              
            
           
          
            
              
                dimgr  
              
                  
                    May 23, 2024,  7:16am
                   
                  7 
               
             
            
              The 2 ip 194.169.175.20 194.169.175.17 they seem banned, but I don’t understand why I’m getting these messages from Fail2Ban??
             
            
              
            
           
          
            
              
                dimgr  
              
                  
                    May 23, 2024,  7:20am
                   
                  8 
               
             
            
              I have these results
May 23 10:19:33 cp postfix/smtpd[44023]: warning: unknown[194.169.175.17]: SASL LOGIN authentication failed: authentication failure
             
            
              
            
           
          
            
            
              That’s not good.
             
            
              
            
           
          
            
              
                dimgr  
              
                  
                    May 23, 2024,  7:33am
                   
                  10 
               
             
            
              I’ve added this to the jail.local file and I’m getting emails!
[DEFAULT]email@to-receive-notifications.com 
 
            
              
            
           
          
            
            
              
 dimgr:
 
Firewall I have CSF
 
 
Ok, thats the issue, CSF uses iptable and turns off firewalld.
             
            
              
            
           
          
            
              
                dimgr  
              
                  
                    May 23, 2024,  7:46am
                   
                  12 
               
             
            
              Yes, that’s right, during the installation of csf, fail2ban disabled it. What should I do?   Can’t I have both for greater security?
             
            
              
            
           
          
            
            
              I’d tell if I was still running it, but been about a year and Ive forgotten 
Nope CSF uses iptables, I never even tried as CSF was doing a good job banning.
             
            
              
            
           
          
            
              
                dimgr  
              
                  
                    May 23, 2024,  7:56am
                   
                  14 
               
             
            
              Can csf block postfix attacks? Yes I installed the module in webmin
             
            
              
            
           
          
            
            
              
Sure can, you should be able to see bans?
             
            
              
            
           
          
            
            
              found a bit of a tutorial, you did turn off testing mode.
This one says you need to disable firewalld, I thought the script did that, I will test on a dev machine.
Yep off
             
            
              
            
           
          
            
              
                dimgr  
              
                  
                    May 23, 2024,  8:54am
                   
                  17 
               
             
            
              I did quick allow of 2 IP with csf and now I don’t have the messages. So Fail2Ban is not working properly?
             
            
              
            
           
          
            
            
              Thats correct, your firewallD need to be off and so is Fail2ban.
By default its off, you need to set LF_TRIGGER to be 1 to turn on.
             
            
              
            
           
          
            
              
                dimgr  
              
                  
                    May 23, 2024, 11:55am
                   
                  19 
               
             
            
              Thanks for trying to help me. Ok it was 0 and I made it 1. Now what should I see?
             
            
              
            
           
          
            
              
                dimgr  
              
                  
                    May 23, 2024, 12:11pm
                   
                  20 
               
             
            
              After restarting the vps, fail2ban.log has these errors. So maybe this is the problem?
2024-05-23 15:07:08,694 fail2ban.actions        [615]: ERROR   Failed to execute ban jail ‘postfix-sasl’ action ‘firewallcmd-ipset’ info ‘ActionInfo({‘ip’: ‘194.169.175.20’, ‘family’: ‘inet4’, ‘fid’: <function Actions.ActionInfo. at 0x7faea82a93f0>, ‘raw-ticket’: <function Actions.ActionInfo. at 0x7faea82a9ab0>})’: Error starting action Jail(‘postfix-sasl’)/firewallcmd-ipset: ‘Script error’