AW
Уже с десяток разных вариантов конфигов пытался скормить fail2ban'у. Не реагирует.
При этом, брутфорсящие SSH - вполне успешно банятся.
Size: a a a
AW
IV
IV
AW
[asterisk]
enabled = true
filter = asterisk
logpath = /var/log/asterisk/messages
maxretry = 2
bantime = 864000
findtime = 86400
port = 5060,5061
action = iptables-allports[name=ASTERISK, protocol=all]
sendmail-whois[name=ASTERISK, dest=root, sender=fail2ban@asterisk]
ignoreip = 127.0.0.1/8
IV
AW
2021-04-16 12:07:46,249 fail2ban.filter [890024]: INFO [sshd] Found 58.229.240.81 - 2021-04-16 12:07:46
2021-04-16 12:07:46,252 fail2ban.filter [890024]: INFO [ssh] Found 58.229.240.81 - 2021-04-16 12:07:46
2021-04-16 12:07:48,459 fail2ban.filter [890024]: INFO [sshd] Found 58.229.240.81 - 2021-04-16 12:07:48
2021-04-16 12:07:48,460 fail2ban.filter [890024]: INFO [ssh] Found 58.229.240.81 - 2021-04-16 12:07:48
2021-04-16 12:07:48,907 fail2ban.actions [890024]: NOTICE [sshd] Ban 58.229.240.81
2021-04-16 12:07:48,914 fail2ban.actions [890024]: NOTICE [ssh] Ban 58.229.240.81
2021-04-16 12:08:53,104 fail2ban.actions [890024]: NOTICE [ssh] Unban 107.170.250.177
2021-04-16 12:10:55,367 fail2ban.actions [890024]: NOTICE [ssh] Unban 91.192.4.91
2021-04-16 12:16:24,248 fail2ban.filter [890024]: INFO [sshd] Found 210.211.116.204 - 2021-04-16 12:16:23
2021-04-16 12:16:24,249 fail2ban.filter [890024]: INFO [ssh] Found 210.211.116.204 - 2021-04-16 12:16:23
2021-04-16 12:16:25,743 fail2ban.filter [890024]: INFO [sshd] Found 210.211.116.204 - 2021-04-16 12:16:25
2021-04-16 12:16:25,746 fail2ban.filter [890024]: INFO [ssh] Found 210.211.116.204 - 2021-04-16 12:16:25
AW
IV
IV
AW
IV
Е
AW
A
ЕП
ЕП
AW
Lines: 3693637 lines, 0 ignored, 2422681 matched, 1270956 missedЭто что значит? Что он таки находит атаки в логах или нет?
[processed in 472.68 sec]
IV
AW
IV