On Fri, 21 Jun 2019 at 01:14, Bill Shirley <bshir...@openmri-scottsboro.com 
<mailto:bshir...@openmri-scottsboro.com> > wrote:

I use an ipset so I'm not authoritative on this, but I think the chains are only
created when you get an actual ban.

 

yes and this is a change in 0.10 from previous versions of f2b, hence the OP's 
confusion.

 

Ah.  Thank you!  That would explain it.

 

Although, that doesn’t seem like a change for the better.  

 

I used to do a quick check after restarting fail2ban to verify the chains were 
in iptables.  That gave me at least a first level of confidence that fail2ban 
was able to manipulate the iptables rules properly.  That’s gone now.  So, I 
guess to do that type of basic check, I would first have to create a ban 
situation, which is tedious.  

 

What’s the logic behind this “improvement”? 

 

Thanks.

Michael

 

 

_______________________________________________
Fail2ban-users mailing list
Fail2ban-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/fail2ban-users

Reply via email to