[Fail2ban-users] help with understanding fail2ban regex south

2019-10-16 Thread lejeczek via Fail2ban-users
hi everybody, I'm a newbie so be easy on me please :) I have such a conf file: ... before = common.conf   [Definition]   _daemon = smbd   failregex = ^%(__prefix_line)sAuth: \[SMB[0-9]\,\(null\)\] user \[.+\]\\\[.+\] at \[.+\] with \[NTLMv2\] status \[NT_STATUS_WRONG_PASSWORD\] workstation \[.+

[Fail2ban-users] silent (complete) failure - centOS 9

2022-03-04 Thread lejeczek via Fail2ban-users
Hi guys I run off centOS 9 and have noticed a weird "misbehavior" and I wonder if you guys could confirm you have seen it too and/or perhaps would try to reproduce. I don't know inner working of f2b, don't know the code so I cannot say when, under what circumstances f2b creates 'table' but..

[Fail2ban-users] no active ban yet nftable holds entries

2023-09-08 Thread lejeczek via Fail2ban-users
Hi guys. my _fail2ban_ shows no banned ips at all, yet there are entries in nftables, eg.: -> $ fail2ban-client status dovecot Status for the jail: dovecot |- Filter |  |- Currently failed:    0 |  |- Total failed:    0 |  `- Journal matches:    _SYSTEMD_UNIT=dovecot.service `- Actions    |- C

Re: [Fail2ban-users] no active ban yet nftable holds entries

2023-09-10 Thread lejeczek via Fail2ban-users
On 08/09/2023 19:50, Tim Boneko via Fail2ban-users wrote: Am Freitag, dem 08.09.2023 um 15:42 +0200 schrieb lejeczek via  how can that be? Hello L.! Welcome to the list! We can help you more specific with more specific information. That IP address is from the 10.x.x.x range which is not reso

[Fail2ban-users] banaction = firewallcmd-rich-rules ?

2024-03-06 Thread lejeczek via Fail2ban-users
Hi guys. With banaction as above my _fail2ban_ inject rules into _default_ zone - is this by design or I misconfigured my setup? The way _fail2ban_ does it for me seems to me, is broken, defeats the purpose - no? _zone_ when in use will(should) use a given iface(s) - in my case it's a zone wit

[Fail2ban-users] unban does _not_ remove firewalld direct rules

2025-05-12 Thread lejeczek via Fail2ban-users
Hi guys. I'm on Centos 10 with Fail2Ban v1.1.0 and I am seeing peculiar misbehavior? I do: -> $ fail2ban-client unban 10.3.1.10 I search for IP, with a script -> $ __fail2ban | __grepColorIt 10.3.1 there is no IP of that subnet, that fail2ban reports back, yet... -> $ firewall-cmd --direct --