LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 10-10-2016, 04:41 PM   #1
grigory
Member
 
Registered: Oct 2015
Posts: 133

Rep: Reputation: Disabled
The endless cat and mouse game of fail2ban


Hello!

I'm not sure if it's a problem to begin with, but the situation is that run Postfix as a mail server on my computer. Almost a year ago because of numerous failed login attempts I installed fail2ban. It does its job. But it's kinda strange for my taste. It bans an IP, after a few hours unbans it, then after half an hour bans again etc. etc. Some bots try to log in once every 20 minutes to escape the ban.

The load average of the server seems to be fine. Approx 0,20

So my question is... Does it all fall within something normal or it requires some action on my part? Or a login attempt once in 20 minutes is something so light for the server so it's best to ignore it?
 
Old 10-11-2016, 03:16 AM   #2
c0wb0y
Member
 
Registered: Jan 2012
Location: Inside the oven
Distribution: Windows
Posts: 421

Rep: Reputation: 74
You can actually do a perma-ban. However, if the list of that goes too long, it might even have a negative impact on your server. I just ban them for 4-6hours and live with it.
 
Old 10-11-2016, 08:59 AM   #3
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Quote:
Originally Posted by c0wb0y View Post
You can actually do a perma-ban. However, if the list of that goes too long, it might even have a negative impact on your server. I just ban them for 4-6hours and live with it.


You can set it from c-line using (assuming postfix jail here)

perma-ban:
Code:
fail2ban-client set postfix bantime -1
10 minute ban:
Code:
fail2ban-client set postfix bantime 600
NOTE: These two^^ commands do not require a fail2ban service restart and the effect is immediate.
(You keep your current rules 'alive' where 'service fail2ban restart' likely will not)

Checking the setting is just as easy:
Code:
fail2ban-client get postfix bantime
Please let us know.
 
Old 10-11-2016, 12:41 PM   #4
grigory
Member
 
Registered: Oct 2015
Posts: 133

Original Poster
Rep: Reputation: Disabled
Thanks for your replies!

I don't use perma-ban, since I see lots of IPs and I'm not even sure how real are they. Perma-ban can jeopardize communication with the legit user, using the same banned IP. If it was the same IP over and over again causing problems, then maybe it's different.

So far fail2ban does its job OK, so I don't want to take any kind of revolutionary steps.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Elliott Associates and Novell: All About a Game of Cat and Mouse LXer Syndicated Linux News 0 03-04-2010 04:10 PM
help! the cat ate my mouse... salmanal SUSE / openSUSE 2 06-10-2007 12:25 PM
LXer: The ITU and ICANN: a Game of Internet Cat and Mouse LXer Syndicated Linux News 0 11-13-2006 10:21 AM
mouse not playing game stabu Linux - Newbie 0 10-05-2004 04:12 AM
the mouse scroll = an endless problem uday Slackware 21 07-06-2003 11:37 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 08:24 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration