fail2ban wont ban ssh from local hostsWatchguard - passwordless SSH login to block/ban IP addressesWhy fail2ban 0.8 doesn't start properly on Debain 7 Wheezy x64?SSH to local without passwordFail2Ban is not adding iptables rulesCan't ssh from CentOS 6.5 to SUSE LINUX 10.1ssh hanging, but *not* ServerAliveIntervalRemote SSH login blocked without local Gnome loginSSH allowing remote hosts to connect to local forwarded portsSecuring linux servers: iptables vs fail2banMySqld Service wont start on Redhat7 after a yum update

usage of mir gefallen

Changing the PK column of a data extension without completely recreating it

Manager wants to hire me, HR do not, how to proceed?

How to make this Scala method return the same generic as the input?

How to import .txt file with missing data?

I sent an angry e-mail to my interviewers about a conflict at my home institution. Could this affect my application?

Am I being scammed by a sugar daddy?

Class A Amplifier Design: Emitter Resistance Voltage Drop

Approach sick days in feedback meeting

New Site Design!

As easy as Three, Two, One... How fast can you go from Five to Four?

Idiom for 'person who gets violent when drunk"

Why would a home insurer offer a discount based on credit score?

Are athlete's college degrees discounted by employers and graduate school admissions?

My mom's return ticket is 3 days after I-94 expires

What do I need to do, tax-wise, for a sudden windfall?

How was nut milk made before blenders?

Realistic, logical way for men with medieval-era weaponry to compete with much larger and physically stronger foes

Can a non-diagonal 2x2 matrix with just one eigenvalue be diagonalizable?

Commencez à vous connecter -- I don't understand the phrasing of this

Can an open source licence be revoked if it violates employer's IP?

Is Jesus the last Prophet?

David slept with Bathsheba because she was pure?? What does that mean?

Do gold quality wild crops yield better seeds?



fail2ban wont ban ssh from local hosts


Watchguard - passwordless SSH login to block/ban IP addressesWhy fail2ban 0.8 doesn't start properly on Debain 7 Wheezy x64?SSH to local without passwordFail2Ban is not adding iptables rulesCan't ssh from CentOS 6.5 to SUSE LINUX 10.1ssh hanging, but *not* ServerAliveIntervalRemote SSH login blocked without local Gnome loginSSH allowing remote hosts to connect to local forwarded portsSecuring linux servers: iptables vs fail2banMySqld Service wont start on Redhat7 after a yum update






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








0















I'm trying to configure fail2ban to block ssh from a local hosts. Fail2ban is install on CentOS 7 with firewall (Linux 3.10.0-229.4.2.el7.x86_64 x86_64 ). I have copied the jail.conf to jail.local i have change the following parameters in jail.local:



banaction = firewallcmd-new
[sshd]
enabled = true
maxretry = 5
port = ssh
logpath = /var/log/secure
action = firewallcmd-ipset


And i have no results. Any idea ?



Some log info:



Jun 23 07:21:33 localhost.localdomain fail2ban-client[2486]: 2015-06-23 07:21:33,351 fail2ban.server [2487]: INFO Starting Fail2ban v0.9.1
Jun 23 07:21:33 localhost.localdomain fail2ban-client[2486]: 2015-06-23 07:21:33,351 fail2ban.server [2487]: INFO Starting in daemon mode
Jun 23 07:21:33 localhost.localdomain systemd[1]: Started Fail2Ban Service.

2015-06-23 07:14:27,571 fail2ban.server [1926]: INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.9.1
2015-06-23 07:14:27,710 fail2ban.database [1926]: INFO Connected to fail2ban persistent database '/var/lib/fail2ban/fail2ban.sqlite3'
2015-06-23 07:14:27,788 fail2ban.jail [1926]: INFO Creating new jail 'sshd'
2015-06-23 07:14:27,923 fail2ban.jail [1926]: INFO Jail 'sshd' uses poller
2015-06-23 07:14:27,985 fail2ban.filter [1926]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:14:27,985 fail2ban.jail [1926]: INFO Initiated 'polling' backend
2015-06-23 07:14:28,063 fail2ban.filter [1926]: INFO Added logfile = /var/log/secure
2015-06-23 07:14:28,064 fail2ban.filter [1926]: INFO Set maxRetry = 2
2015-06-23 07:14:28,066 fail2ban.filter [1926]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:14:28,066 fail2ban.actions [1926]: INFO Set banTime = 86400
2015-06-23 07:14:28,067 fail2ban.filter [1926]: INFO Set findtime = 600
2015-06-23 07:14:28,068 fail2ban.filter [1926]: INFO Set maxlines = 10
2015-06-23 07:14:28,158 fail2ban.server [1926]: INFO Jail sshd is not a JournalFilter instance
2015-06-23 07:14:28,459 fail2ban.jail [1926]: INFO Jail 'sshd' started
2015-06-23 07:21:32,667 fail2ban.server [1926]: INFO Stopping all jails
2015-06-23 07:21:33,181 fail2ban.jail [1926]: INFO Jail 'sshd' stopped
2015-06-23 07:21:33,188 fail2ban.server [1926]: INFO Exiting Fail2ban
2015-06-23 07:21:33,404 fail2ban.server [2489]: INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.9.1
2015-06-23 07:21:33,406 fail2ban.database [2489]: INFO Connected to fail2ban persistent database '/var/lib/fail2ban/fail2ban.sqlite3'
2015-06-23 07:21:33,409 fail2ban.jail [2489]: INFO Creating new jail 'sshd'
2015-06-23 07:21:33,413 fail2ban.jail [2489]: INFO Jail 'sshd' uses poller
2015-06-23 07:21:33,433 fail2ban.filter [2489]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:21:33,433 fail2ban.jail [2489]: INFO Initiated 'polling' backend
2015-06-23 07:21:33,438 fail2ban.filter [2489]: INFO Added logfile = /var/log/secure
2015-06-23 07:21:33,439 fail2ban.filter [2489]: INFO Set maxRetry = 3
2015-06-23 07:21:33,440 fail2ban.filter [2489]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:21:33,441 fail2ban.actions [2489]: INFO Set banTime = 86400
2015-06-23 07:21:33,442 fail2ban.filter [2489]: INFO Set findtime = 600
2015-06-23 07:21:33,442 fail2ban.filter [2489]: INFO Set maxlines = 10
2015-06-23 07:21:33,501 fail2ban.server [2489]: INFO Jail sshd is not a JournalFilter instance
2015-06-23 07:21:33,599 fail2ban.jail [2489]: INFO Jail 'sshd' started


And SELinux is disabled.










share|improve this question
























  • What on earth would you need to firewall off as a fail2ban from local host on ssh for..? We can answer more effectively if you clarify this

    – Timothy Frew
    Jan 24 at 0:18

















0















I'm trying to configure fail2ban to block ssh from a local hosts. Fail2ban is install on CentOS 7 with firewall (Linux 3.10.0-229.4.2.el7.x86_64 x86_64 ). I have copied the jail.conf to jail.local i have change the following parameters in jail.local:



banaction = firewallcmd-new
[sshd]
enabled = true
maxretry = 5
port = ssh
logpath = /var/log/secure
action = firewallcmd-ipset


And i have no results. Any idea ?



Some log info:



Jun 23 07:21:33 localhost.localdomain fail2ban-client[2486]: 2015-06-23 07:21:33,351 fail2ban.server [2487]: INFO Starting Fail2ban v0.9.1
Jun 23 07:21:33 localhost.localdomain fail2ban-client[2486]: 2015-06-23 07:21:33,351 fail2ban.server [2487]: INFO Starting in daemon mode
Jun 23 07:21:33 localhost.localdomain systemd[1]: Started Fail2Ban Service.

2015-06-23 07:14:27,571 fail2ban.server [1926]: INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.9.1
2015-06-23 07:14:27,710 fail2ban.database [1926]: INFO Connected to fail2ban persistent database '/var/lib/fail2ban/fail2ban.sqlite3'
2015-06-23 07:14:27,788 fail2ban.jail [1926]: INFO Creating new jail 'sshd'
2015-06-23 07:14:27,923 fail2ban.jail [1926]: INFO Jail 'sshd' uses poller
2015-06-23 07:14:27,985 fail2ban.filter [1926]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:14:27,985 fail2ban.jail [1926]: INFO Initiated 'polling' backend
2015-06-23 07:14:28,063 fail2ban.filter [1926]: INFO Added logfile = /var/log/secure
2015-06-23 07:14:28,064 fail2ban.filter [1926]: INFO Set maxRetry = 2
2015-06-23 07:14:28,066 fail2ban.filter [1926]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:14:28,066 fail2ban.actions [1926]: INFO Set banTime = 86400
2015-06-23 07:14:28,067 fail2ban.filter [1926]: INFO Set findtime = 600
2015-06-23 07:14:28,068 fail2ban.filter [1926]: INFO Set maxlines = 10
2015-06-23 07:14:28,158 fail2ban.server [1926]: INFO Jail sshd is not a JournalFilter instance
2015-06-23 07:14:28,459 fail2ban.jail [1926]: INFO Jail 'sshd' started
2015-06-23 07:21:32,667 fail2ban.server [1926]: INFO Stopping all jails
2015-06-23 07:21:33,181 fail2ban.jail [1926]: INFO Jail 'sshd' stopped
2015-06-23 07:21:33,188 fail2ban.server [1926]: INFO Exiting Fail2ban
2015-06-23 07:21:33,404 fail2ban.server [2489]: INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.9.1
2015-06-23 07:21:33,406 fail2ban.database [2489]: INFO Connected to fail2ban persistent database '/var/lib/fail2ban/fail2ban.sqlite3'
2015-06-23 07:21:33,409 fail2ban.jail [2489]: INFO Creating new jail 'sshd'
2015-06-23 07:21:33,413 fail2ban.jail [2489]: INFO Jail 'sshd' uses poller
2015-06-23 07:21:33,433 fail2ban.filter [2489]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:21:33,433 fail2ban.jail [2489]: INFO Initiated 'polling' backend
2015-06-23 07:21:33,438 fail2ban.filter [2489]: INFO Added logfile = /var/log/secure
2015-06-23 07:21:33,439 fail2ban.filter [2489]: INFO Set maxRetry = 3
2015-06-23 07:21:33,440 fail2ban.filter [2489]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:21:33,441 fail2ban.actions [2489]: INFO Set banTime = 86400
2015-06-23 07:21:33,442 fail2ban.filter [2489]: INFO Set findtime = 600
2015-06-23 07:21:33,442 fail2ban.filter [2489]: INFO Set maxlines = 10
2015-06-23 07:21:33,501 fail2ban.server [2489]: INFO Jail sshd is not a JournalFilter instance
2015-06-23 07:21:33,599 fail2ban.jail [2489]: INFO Jail 'sshd' started


And SELinux is disabled.










share|improve this question
























  • What on earth would you need to firewall off as a fail2ban from local host on ssh for..? We can answer more effectively if you clarify this

    – Timothy Frew
    Jan 24 at 0:18













0












0








0








I'm trying to configure fail2ban to block ssh from a local hosts. Fail2ban is install on CentOS 7 with firewall (Linux 3.10.0-229.4.2.el7.x86_64 x86_64 ). I have copied the jail.conf to jail.local i have change the following parameters in jail.local:



banaction = firewallcmd-new
[sshd]
enabled = true
maxretry = 5
port = ssh
logpath = /var/log/secure
action = firewallcmd-ipset


And i have no results. Any idea ?



Some log info:



Jun 23 07:21:33 localhost.localdomain fail2ban-client[2486]: 2015-06-23 07:21:33,351 fail2ban.server [2487]: INFO Starting Fail2ban v0.9.1
Jun 23 07:21:33 localhost.localdomain fail2ban-client[2486]: 2015-06-23 07:21:33,351 fail2ban.server [2487]: INFO Starting in daemon mode
Jun 23 07:21:33 localhost.localdomain systemd[1]: Started Fail2Ban Service.

2015-06-23 07:14:27,571 fail2ban.server [1926]: INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.9.1
2015-06-23 07:14:27,710 fail2ban.database [1926]: INFO Connected to fail2ban persistent database '/var/lib/fail2ban/fail2ban.sqlite3'
2015-06-23 07:14:27,788 fail2ban.jail [1926]: INFO Creating new jail 'sshd'
2015-06-23 07:14:27,923 fail2ban.jail [1926]: INFO Jail 'sshd' uses poller
2015-06-23 07:14:27,985 fail2ban.filter [1926]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:14:27,985 fail2ban.jail [1926]: INFO Initiated 'polling' backend
2015-06-23 07:14:28,063 fail2ban.filter [1926]: INFO Added logfile = /var/log/secure
2015-06-23 07:14:28,064 fail2ban.filter [1926]: INFO Set maxRetry = 2
2015-06-23 07:14:28,066 fail2ban.filter [1926]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:14:28,066 fail2ban.actions [1926]: INFO Set banTime = 86400
2015-06-23 07:14:28,067 fail2ban.filter [1926]: INFO Set findtime = 600
2015-06-23 07:14:28,068 fail2ban.filter [1926]: INFO Set maxlines = 10
2015-06-23 07:14:28,158 fail2ban.server [1926]: INFO Jail sshd is not a JournalFilter instance
2015-06-23 07:14:28,459 fail2ban.jail [1926]: INFO Jail 'sshd' started
2015-06-23 07:21:32,667 fail2ban.server [1926]: INFO Stopping all jails
2015-06-23 07:21:33,181 fail2ban.jail [1926]: INFO Jail 'sshd' stopped
2015-06-23 07:21:33,188 fail2ban.server [1926]: INFO Exiting Fail2ban
2015-06-23 07:21:33,404 fail2ban.server [2489]: INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.9.1
2015-06-23 07:21:33,406 fail2ban.database [2489]: INFO Connected to fail2ban persistent database '/var/lib/fail2ban/fail2ban.sqlite3'
2015-06-23 07:21:33,409 fail2ban.jail [2489]: INFO Creating new jail 'sshd'
2015-06-23 07:21:33,413 fail2ban.jail [2489]: INFO Jail 'sshd' uses poller
2015-06-23 07:21:33,433 fail2ban.filter [2489]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:21:33,433 fail2ban.jail [2489]: INFO Initiated 'polling' backend
2015-06-23 07:21:33,438 fail2ban.filter [2489]: INFO Added logfile = /var/log/secure
2015-06-23 07:21:33,439 fail2ban.filter [2489]: INFO Set maxRetry = 3
2015-06-23 07:21:33,440 fail2ban.filter [2489]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:21:33,441 fail2ban.actions [2489]: INFO Set banTime = 86400
2015-06-23 07:21:33,442 fail2ban.filter [2489]: INFO Set findtime = 600
2015-06-23 07:21:33,442 fail2ban.filter [2489]: INFO Set maxlines = 10
2015-06-23 07:21:33,501 fail2ban.server [2489]: INFO Jail sshd is not a JournalFilter instance
2015-06-23 07:21:33,599 fail2ban.jail [2489]: INFO Jail 'sshd' started


And SELinux is disabled.










share|improve this question
















I'm trying to configure fail2ban to block ssh from a local hosts. Fail2ban is install on CentOS 7 with firewall (Linux 3.10.0-229.4.2.el7.x86_64 x86_64 ). I have copied the jail.conf to jail.local i have change the following parameters in jail.local:



banaction = firewallcmd-new
[sshd]
enabled = true
maxretry = 5
port = ssh
logpath = /var/log/secure
action = firewallcmd-ipset


And i have no results. Any idea ?



Some log info:



Jun 23 07:21:33 localhost.localdomain fail2ban-client[2486]: 2015-06-23 07:21:33,351 fail2ban.server [2487]: INFO Starting Fail2ban v0.9.1
Jun 23 07:21:33 localhost.localdomain fail2ban-client[2486]: 2015-06-23 07:21:33,351 fail2ban.server [2487]: INFO Starting in daemon mode
Jun 23 07:21:33 localhost.localdomain systemd[1]: Started Fail2Ban Service.

2015-06-23 07:14:27,571 fail2ban.server [1926]: INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.9.1
2015-06-23 07:14:27,710 fail2ban.database [1926]: INFO Connected to fail2ban persistent database '/var/lib/fail2ban/fail2ban.sqlite3'
2015-06-23 07:14:27,788 fail2ban.jail [1926]: INFO Creating new jail 'sshd'
2015-06-23 07:14:27,923 fail2ban.jail [1926]: INFO Jail 'sshd' uses poller
2015-06-23 07:14:27,985 fail2ban.filter [1926]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:14:27,985 fail2ban.jail [1926]: INFO Initiated 'polling' backend
2015-06-23 07:14:28,063 fail2ban.filter [1926]: INFO Added logfile = /var/log/secure
2015-06-23 07:14:28,064 fail2ban.filter [1926]: INFO Set maxRetry = 2
2015-06-23 07:14:28,066 fail2ban.filter [1926]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:14:28,066 fail2ban.actions [1926]: INFO Set banTime = 86400
2015-06-23 07:14:28,067 fail2ban.filter [1926]: INFO Set findtime = 600
2015-06-23 07:14:28,068 fail2ban.filter [1926]: INFO Set maxlines = 10
2015-06-23 07:14:28,158 fail2ban.server [1926]: INFO Jail sshd is not a JournalFilter instance
2015-06-23 07:14:28,459 fail2ban.jail [1926]: INFO Jail 'sshd' started
2015-06-23 07:21:32,667 fail2ban.server [1926]: INFO Stopping all jails
2015-06-23 07:21:33,181 fail2ban.jail [1926]: INFO Jail 'sshd' stopped
2015-06-23 07:21:33,188 fail2ban.server [1926]: INFO Exiting Fail2ban
2015-06-23 07:21:33,404 fail2ban.server [2489]: INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.9.1
2015-06-23 07:21:33,406 fail2ban.database [2489]: INFO Connected to fail2ban persistent database '/var/lib/fail2ban/fail2ban.sqlite3'
2015-06-23 07:21:33,409 fail2ban.jail [2489]: INFO Creating new jail 'sshd'
2015-06-23 07:21:33,413 fail2ban.jail [2489]: INFO Jail 'sshd' uses poller
2015-06-23 07:21:33,433 fail2ban.filter [2489]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:21:33,433 fail2ban.jail [2489]: INFO Initiated 'polling' backend
2015-06-23 07:21:33,438 fail2ban.filter [2489]: INFO Added logfile = /var/log/secure
2015-06-23 07:21:33,439 fail2ban.filter [2489]: INFO Set maxRetry = 3
2015-06-23 07:21:33,440 fail2ban.filter [2489]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:21:33,441 fail2ban.actions [2489]: INFO Set banTime = 86400
2015-06-23 07:21:33,442 fail2ban.filter [2489]: INFO Set findtime = 600
2015-06-23 07:21:33,442 fail2ban.filter [2489]: INFO Set maxlines = 10
2015-06-23 07:21:33,501 fail2ban.server [2489]: INFO Jail sshd is not a JournalFilter instance
2015-06-23 07:21:33,599 fail2ban.jail [2489]: INFO Jail 'sshd' started


And SELinux is disabled.







linux ssh fail2ban






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Jun 23 '15 at 13:16







IvanCD

















asked Jun 23 '15 at 11:27









IvanCDIvanCD

97




97












  • What on earth would you need to firewall off as a fail2ban from local host on ssh for..? We can answer more effectively if you clarify this

    – Timothy Frew
    Jan 24 at 0:18

















  • What on earth would you need to firewall off as a fail2ban from local host on ssh for..? We can answer more effectively if you clarify this

    – Timothy Frew
    Jan 24 at 0:18
















What on earth would you need to firewall off as a fail2ban from local host on ssh for..? We can answer more effectively if you clarify this

– Timothy Frew
Jan 24 at 0:18





What on earth would you need to firewall off as a fail2ban from local host on ssh for..? We can answer more effectively if you clarify this

– Timothy Frew
Jan 24 at 0:18










1 Answer
1






active

oldest

votes


















0














In the file below,



/etc/fail2ban/jail.conf (note if you are using jail.local the same can be applied there also)
try changing auto to gamin or polling



Note:
if systemd backend is chosen as the default but you enable a jail
for which logs are present only in its own log files, specify some other
backend for that jail (e.g. polling) and provide empty value for
journalmatch. See https://github.com/fail2ban/fail2ban/issues/959#issuecomment-74901200



So, changing



backend = auto


to



backend = gamin 


or



backend = polling


Worked for me.






share|improve this answer

























    Your Answer








    StackExchange.ready(function()
    var channelOptions =
    tags: "".split(" "),
    id: "2"
    ;
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function()
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled)
    StackExchange.using("snippets", function()
    createEditor();
    );

    else
    createEditor();

    );

    function createEditor()
    StackExchange.prepareEditor(
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: true,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: 10,
    bindNavPrevention: true,
    postfix: "",
    imageUploader:
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    ,
    onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    );



    );













    draft saved

    draft discarded


















    StackExchange.ready(
    function ()
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f700952%2ffail2ban-wont-ban-ssh-from-local-hosts%23new-answer', 'question_page');

    );

    Post as a guest















    Required, but never shown

























    1 Answer
    1






    active

    oldest

    votes








    1 Answer
    1






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    0














    In the file below,



    /etc/fail2ban/jail.conf (note if you are using jail.local the same can be applied there also)
    try changing auto to gamin or polling



    Note:
    if systemd backend is chosen as the default but you enable a jail
    for which logs are present only in its own log files, specify some other
    backend for that jail (e.g. polling) and provide empty value for
    journalmatch. See https://github.com/fail2ban/fail2ban/issues/959#issuecomment-74901200



    So, changing



    backend = auto


    to



    backend = gamin 


    or



    backend = polling


    Worked for me.






    share|improve this answer





























      0














      In the file below,



      /etc/fail2ban/jail.conf (note if you are using jail.local the same can be applied there also)
      try changing auto to gamin or polling



      Note:
      if systemd backend is chosen as the default but you enable a jail
      for which logs are present only in its own log files, specify some other
      backend for that jail (e.g. polling) and provide empty value for
      journalmatch. See https://github.com/fail2ban/fail2ban/issues/959#issuecomment-74901200



      So, changing



      backend = auto


      to



      backend = gamin 


      or



      backend = polling


      Worked for me.






      share|improve this answer



























        0












        0








        0







        In the file below,



        /etc/fail2ban/jail.conf (note if you are using jail.local the same can be applied there also)
        try changing auto to gamin or polling



        Note:
        if systemd backend is chosen as the default but you enable a jail
        for which logs are present only in its own log files, specify some other
        backend for that jail (e.g. polling) and provide empty value for
        journalmatch. See https://github.com/fail2ban/fail2ban/issues/959#issuecomment-74901200



        So, changing



        backend = auto


        to



        backend = gamin 


        or



        backend = polling


        Worked for me.






        share|improve this answer















        In the file below,



        /etc/fail2ban/jail.conf (note if you are using jail.local the same can be applied there also)
        try changing auto to gamin or polling



        Note:
        if systemd backend is chosen as the default but you enable a jail
        for which logs are present only in its own log files, specify some other
        backend for that jail (e.g. polling) and provide empty value for
        journalmatch. See https://github.com/fail2ban/fail2ban/issues/959#issuecomment-74901200



        So, changing



        backend = auto


        to



        backend = gamin 


        or



        backend = polling


        Worked for me.







        share|improve this answer














        share|improve this answer



        share|improve this answer








        edited Mar 6 '16 at 19:30









        chicks

        3,09072033




        3,09072033










        answered Mar 6 '16 at 14:08









        MuhasinMuhasin

        11




        11



























            draft saved

            draft discarded
















































            Thanks for contributing an answer to Server Fault!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid


            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.

            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f700952%2ffail2ban-wont-ban-ssh-from-local-hosts%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            Popular posts from this blog

            Wikipedia:Vital articles Мазмуну Biography - Өмүр баян Philosophy and psychology - Философия жана психология Religion - Дин Social sciences - Коомдук илимдер Language and literature - Тил жана адабият Science - Илим Technology - Технология Arts and recreation - Искусство жана эс алуу History and geography - Тарых жана география Навигация менюсу

            Bruxelas-Capital Índice Historia | Composición | Situación lingüística | Clima | Cidades irmandadas | Notas | Véxase tamén | Menú de navegacióneO uso das linguas en Bruxelas e a situación do neerlandés"Rexión de Bruxelas Capital"o orixinalSitio da rexiónPáxina de Bruselas no sitio da Oficina de Promoción Turística de Valonia e BruxelasMapa Interactivo da Rexión de Bruxelas-CapitaleeWorldCat332144929079854441105155190212ID28008674080552-90000 0001 0666 3698n94104302ID540940339365017018237

            What should I write in an apology letter, since I have decided not to join a company after accepting an offer letterShould I keep looking after accepting a job offer?What should I do when I've been verbally told I would get an offer letter, but still haven't gotten one after 4 weeks?Do I accept an offer from a company that I am not likely to join?New job hasn't confirmed starting date and I want to give current employer as much notice as possibleHow should I address my manager in my resignation letter?HR delayed background verification, now jobless as resignedNo email communication after accepting a formal written offer. How should I phrase the call?What should I do if after receiving a verbal offer letter I am informed that my written job offer is put on hold due to some internal issues?Should I inform the current employer that I am about to resign within 1-2 weeks since I have signed the offer letter and waiting for visa?What company will do, if I send their offer letter to another company