fail2ban wont ban ssh from local hostsWatchguard - passwordless SSH login to block/ban IP addressesWhy fail2ban 0.8 doesn't start properly on Debain 7 Wheezy x64?SSH to local without passwordFail2Ban is not adding iptables rulesCan't ssh from CentOS 6.5 to SUSE LINUX 10.1ssh hanging, but *not* ServerAliveIntervalRemote SSH login blocked without local Gnome loginSSH allowing remote hosts to connect to local forwarded portsSecuring linux servers: iptables vs fail2banMySqld Service wont start on Redhat7 after a yum update
usage of mir gefallen
Changing the PK column of a data extension without completely recreating it
Manager wants to hire me, HR do not, how to proceed?
How to make this Scala method return the same generic as the input?
How to import .txt file with missing data?
I sent an angry e-mail to my interviewers about a conflict at my home institution. Could this affect my application?
Am I being scammed by a sugar daddy?
Class A Amplifier Design: Emitter Resistance Voltage Drop
Approach sick days in feedback meeting
New Site Design!
As easy as Three, Two, One... How fast can you go from Five to Four?
Idiom for 'person who gets violent when drunk"
Why would a home insurer offer a discount based on credit score?
Are athlete's college degrees discounted by employers and graduate school admissions?
My mom's return ticket is 3 days after I-94 expires
What do I need to do, tax-wise, for a sudden windfall?
How was nut milk made before blenders?
Realistic, logical way for men with medieval-era weaponry to compete with much larger and physically stronger foes
Can a non-diagonal 2x2 matrix with just one eigenvalue be diagonalizable?
Commencez à vous connecter -- I don't understand the phrasing of this
Can an open source licence be revoked if it violates employer's IP?
Is Jesus the last Prophet?
David slept with Bathsheba because she was pure?? What does that mean?
Do gold quality wild crops yield better seeds?
fail2ban wont ban ssh from local hosts
Watchguard - passwordless SSH login to block/ban IP addressesWhy fail2ban 0.8 doesn't start properly on Debain 7 Wheezy x64?SSH to local without passwordFail2Ban is not adding iptables rulesCan't ssh from CentOS 6.5 to SUSE LINUX 10.1ssh hanging, but *not* ServerAliveIntervalRemote SSH login blocked without local Gnome loginSSH allowing remote hosts to connect to local forwarded portsSecuring linux servers: iptables vs fail2banMySqld Service wont start on Redhat7 after a yum update
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;
I'm trying to configure fail2ban to block ssh from a local hosts. Fail2ban is install on CentOS 7 with firewall (Linux 3.10.0-229.4.2.el7.x86_64 x86_64 ). I have copied the jail.conf to jail.local i have change the following parameters in jail.local:
banaction = firewallcmd-new
[sshd]
enabled = true
maxretry = 5
port = ssh
logpath = /var/log/secure
action = firewallcmd-ipset
And i have no results. Any idea ?
Some log info:
Jun 23 07:21:33 localhost.localdomain fail2ban-client[2486]: 2015-06-23 07:21:33,351 fail2ban.server [2487]: INFO Starting Fail2ban v0.9.1
Jun 23 07:21:33 localhost.localdomain fail2ban-client[2486]: 2015-06-23 07:21:33,351 fail2ban.server [2487]: INFO Starting in daemon mode
Jun 23 07:21:33 localhost.localdomain systemd[1]: Started Fail2Ban Service.
2015-06-23 07:14:27,571 fail2ban.server [1926]: INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.9.1
2015-06-23 07:14:27,710 fail2ban.database [1926]: INFO Connected to fail2ban persistent database '/var/lib/fail2ban/fail2ban.sqlite3'
2015-06-23 07:14:27,788 fail2ban.jail [1926]: INFO Creating new jail 'sshd'
2015-06-23 07:14:27,923 fail2ban.jail [1926]: INFO Jail 'sshd' uses poller
2015-06-23 07:14:27,985 fail2ban.filter [1926]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:14:27,985 fail2ban.jail [1926]: INFO Initiated 'polling' backend
2015-06-23 07:14:28,063 fail2ban.filter [1926]: INFO Added logfile = /var/log/secure
2015-06-23 07:14:28,064 fail2ban.filter [1926]: INFO Set maxRetry = 2
2015-06-23 07:14:28,066 fail2ban.filter [1926]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:14:28,066 fail2ban.actions [1926]: INFO Set banTime = 86400
2015-06-23 07:14:28,067 fail2ban.filter [1926]: INFO Set findtime = 600
2015-06-23 07:14:28,068 fail2ban.filter [1926]: INFO Set maxlines = 10
2015-06-23 07:14:28,158 fail2ban.server [1926]: INFO Jail sshd is not a JournalFilter instance
2015-06-23 07:14:28,459 fail2ban.jail [1926]: INFO Jail 'sshd' started
2015-06-23 07:21:32,667 fail2ban.server [1926]: INFO Stopping all jails
2015-06-23 07:21:33,181 fail2ban.jail [1926]: INFO Jail 'sshd' stopped
2015-06-23 07:21:33,188 fail2ban.server [1926]: INFO Exiting Fail2ban
2015-06-23 07:21:33,404 fail2ban.server [2489]: INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.9.1
2015-06-23 07:21:33,406 fail2ban.database [2489]: INFO Connected to fail2ban persistent database '/var/lib/fail2ban/fail2ban.sqlite3'
2015-06-23 07:21:33,409 fail2ban.jail [2489]: INFO Creating new jail 'sshd'
2015-06-23 07:21:33,413 fail2ban.jail [2489]: INFO Jail 'sshd' uses poller
2015-06-23 07:21:33,433 fail2ban.filter [2489]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:21:33,433 fail2ban.jail [2489]: INFO Initiated 'polling' backend
2015-06-23 07:21:33,438 fail2ban.filter [2489]: INFO Added logfile = /var/log/secure
2015-06-23 07:21:33,439 fail2ban.filter [2489]: INFO Set maxRetry = 3
2015-06-23 07:21:33,440 fail2ban.filter [2489]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:21:33,441 fail2ban.actions [2489]: INFO Set banTime = 86400
2015-06-23 07:21:33,442 fail2ban.filter [2489]: INFO Set findtime = 600
2015-06-23 07:21:33,442 fail2ban.filter [2489]: INFO Set maxlines = 10
2015-06-23 07:21:33,501 fail2ban.server [2489]: INFO Jail sshd is not a JournalFilter instance
2015-06-23 07:21:33,599 fail2ban.jail [2489]: INFO Jail 'sshd' started
And SELinux is disabled.
linux ssh fail2ban
add a comment |
I'm trying to configure fail2ban to block ssh from a local hosts. Fail2ban is install on CentOS 7 with firewall (Linux 3.10.0-229.4.2.el7.x86_64 x86_64 ). I have copied the jail.conf to jail.local i have change the following parameters in jail.local:
banaction = firewallcmd-new
[sshd]
enabled = true
maxretry = 5
port = ssh
logpath = /var/log/secure
action = firewallcmd-ipset
And i have no results. Any idea ?
Some log info:
Jun 23 07:21:33 localhost.localdomain fail2ban-client[2486]: 2015-06-23 07:21:33,351 fail2ban.server [2487]: INFO Starting Fail2ban v0.9.1
Jun 23 07:21:33 localhost.localdomain fail2ban-client[2486]: 2015-06-23 07:21:33,351 fail2ban.server [2487]: INFO Starting in daemon mode
Jun 23 07:21:33 localhost.localdomain systemd[1]: Started Fail2Ban Service.
2015-06-23 07:14:27,571 fail2ban.server [1926]: INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.9.1
2015-06-23 07:14:27,710 fail2ban.database [1926]: INFO Connected to fail2ban persistent database '/var/lib/fail2ban/fail2ban.sqlite3'
2015-06-23 07:14:27,788 fail2ban.jail [1926]: INFO Creating new jail 'sshd'
2015-06-23 07:14:27,923 fail2ban.jail [1926]: INFO Jail 'sshd' uses poller
2015-06-23 07:14:27,985 fail2ban.filter [1926]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:14:27,985 fail2ban.jail [1926]: INFO Initiated 'polling' backend
2015-06-23 07:14:28,063 fail2ban.filter [1926]: INFO Added logfile = /var/log/secure
2015-06-23 07:14:28,064 fail2ban.filter [1926]: INFO Set maxRetry = 2
2015-06-23 07:14:28,066 fail2ban.filter [1926]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:14:28,066 fail2ban.actions [1926]: INFO Set banTime = 86400
2015-06-23 07:14:28,067 fail2ban.filter [1926]: INFO Set findtime = 600
2015-06-23 07:14:28,068 fail2ban.filter [1926]: INFO Set maxlines = 10
2015-06-23 07:14:28,158 fail2ban.server [1926]: INFO Jail sshd is not a JournalFilter instance
2015-06-23 07:14:28,459 fail2ban.jail [1926]: INFO Jail 'sshd' started
2015-06-23 07:21:32,667 fail2ban.server [1926]: INFO Stopping all jails
2015-06-23 07:21:33,181 fail2ban.jail [1926]: INFO Jail 'sshd' stopped
2015-06-23 07:21:33,188 fail2ban.server [1926]: INFO Exiting Fail2ban
2015-06-23 07:21:33,404 fail2ban.server [2489]: INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.9.1
2015-06-23 07:21:33,406 fail2ban.database [2489]: INFO Connected to fail2ban persistent database '/var/lib/fail2ban/fail2ban.sqlite3'
2015-06-23 07:21:33,409 fail2ban.jail [2489]: INFO Creating new jail 'sshd'
2015-06-23 07:21:33,413 fail2ban.jail [2489]: INFO Jail 'sshd' uses poller
2015-06-23 07:21:33,433 fail2ban.filter [2489]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:21:33,433 fail2ban.jail [2489]: INFO Initiated 'polling' backend
2015-06-23 07:21:33,438 fail2ban.filter [2489]: INFO Added logfile = /var/log/secure
2015-06-23 07:21:33,439 fail2ban.filter [2489]: INFO Set maxRetry = 3
2015-06-23 07:21:33,440 fail2ban.filter [2489]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:21:33,441 fail2ban.actions [2489]: INFO Set banTime = 86400
2015-06-23 07:21:33,442 fail2ban.filter [2489]: INFO Set findtime = 600
2015-06-23 07:21:33,442 fail2ban.filter [2489]: INFO Set maxlines = 10
2015-06-23 07:21:33,501 fail2ban.server [2489]: INFO Jail sshd is not a JournalFilter instance
2015-06-23 07:21:33,599 fail2ban.jail [2489]: INFO Jail 'sshd' started
And SELinux is disabled.
linux ssh fail2ban
What on earth would you need to firewall off as a fail2ban from local host on ssh for..? We can answer more effectively if you clarify this
– Timothy Frew
Jan 24 at 0:18
add a comment |
I'm trying to configure fail2ban to block ssh from a local hosts. Fail2ban is install on CentOS 7 with firewall (Linux 3.10.0-229.4.2.el7.x86_64 x86_64 ). I have copied the jail.conf to jail.local i have change the following parameters in jail.local:
banaction = firewallcmd-new
[sshd]
enabled = true
maxretry = 5
port = ssh
logpath = /var/log/secure
action = firewallcmd-ipset
And i have no results. Any idea ?
Some log info:
Jun 23 07:21:33 localhost.localdomain fail2ban-client[2486]: 2015-06-23 07:21:33,351 fail2ban.server [2487]: INFO Starting Fail2ban v0.9.1
Jun 23 07:21:33 localhost.localdomain fail2ban-client[2486]: 2015-06-23 07:21:33,351 fail2ban.server [2487]: INFO Starting in daemon mode
Jun 23 07:21:33 localhost.localdomain systemd[1]: Started Fail2Ban Service.
2015-06-23 07:14:27,571 fail2ban.server [1926]: INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.9.1
2015-06-23 07:14:27,710 fail2ban.database [1926]: INFO Connected to fail2ban persistent database '/var/lib/fail2ban/fail2ban.sqlite3'
2015-06-23 07:14:27,788 fail2ban.jail [1926]: INFO Creating new jail 'sshd'
2015-06-23 07:14:27,923 fail2ban.jail [1926]: INFO Jail 'sshd' uses poller
2015-06-23 07:14:27,985 fail2ban.filter [1926]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:14:27,985 fail2ban.jail [1926]: INFO Initiated 'polling' backend
2015-06-23 07:14:28,063 fail2ban.filter [1926]: INFO Added logfile = /var/log/secure
2015-06-23 07:14:28,064 fail2ban.filter [1926]: INFO Set maxRetry = 2
2015-06-23 07:14:28,066 fail2ban.filter [1926]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:14:28,066 fail2ban.actions [1926]: INFO Set banTime = 86400
2015-06-23 07:14:28,067 fail2ban.filter [1926]: INFO Set findtime = 600
2015-06-23 07:14:28,068 fail2ban.filter [1926]: INFO Set maxlines = 10
2015-06-23 07:14:28,158 fail2ban.server [1926]: INFO Jail sshd is not a JournalFilter instance
2015-06-23 07:14:28,459 fail2ban.jail [1926]: INFO Jail 'sshd' started
2015-06-23 07:21:32,667 fail2ban.server [1926]: INFO Stopping all jails
2015-06-23 07:21:33,181 fail2ban.jail [1926]: INFO Jail 'sshd' stopped
2015-06-23 07:21:33,188 fail2ban.server [1926]: INFO Exiting Fail2ban
2015-06-23 07:21:33,404 fail2ban.server [2489]: INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.9.1
2015-06-23 07:21:33,406 fail2ban.database [2489]: INFO Connected to fail2ban persistent database '/var/lib/fail2ban/fail2ban.sqlite3'
2015-06-23 07:21:33,409 fail2ban.jail [2489]: INFO Creating new jail 'sshd'
2015-06-23 07:21:33,413 fail2ban.jail [2489]: INFO Jail 'sshd' uses poller
2015-06-23 07:21:33,433 fail2ban.filter [2489]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:21:33,433 fail2ban.jail [2489]: INFO Initiated 'polling' backend
2015-06-23 07:21:33,438 fail2ban.filter [2489]: INFO Added logfile = /var/log/secure
2015-06-23 07:21:33,439 fail2ban.filter [2489]: INFO Set maxRetry = 3
2015-06-23 07:21:33,440 fail2ban.filter [2489]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:21:33,441 fail2ban.actions [2489]: INFO Set banTime = 86400
2015-06-23 07:21:33,442 fail2ban.filter [2489]: INFO Set findtime = 600
2015-06-23 07:21:33,442 fail2ban.filter [2489]: INFO Set maxlines = 10
2015-06-23 07:21:33,501 fail2ban.server [2489]: INFO Jail sshd is not a JournalFilter instance
2015-06-23 07:21:33,599 fail2ban.jail [2489]: INFO Jail 'sshd' started
And SELinux is disabled.
linux ssh fail2ban
I'm trying to configure fail2ban to block ssh from a local hosts. Fail2ban is install on CentOS 7 with firewall (Linux 3.10.0-229.4.2.el7.x86_64 x86_64 ). I have copied the jail.conf to jail.local i have change the following parameters in jail.local:
banaction = firewallcmd-new
[sshd]
enabled = true
maxretry = 5
port = ssh
logpath = /var/log/secure
action = firewallcmd-ipset
And i have no results. Any idea ?
Some log info:
Jun 23 07:21:33 localhost.localdomain fail2ban-client[2486]: 2015-06-23 07:21:33,351 fail2ban.server [2487]: INFO Starting Fail2ban v0.9.1
Jun 23 07:21:33 localhost.localdomain fail2ban-client[2486]: 2015-06-23 07:21:33,351 fail2ban.server [2487]: INFO Starting in daemon mode
Jun 23 07:21:33 localhost.localdomain systemd[1]: Started Fail2Ban Service.
2015-06-23 07:14:27,571 fail2ban.server [1926]: INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.9.1
2015-06-23 07:14:27,710 fail2ban.database [1926]: INFO Connected to fail2ban persistent database '/var/lib/fail2ban/fail2ban.sqlite3'
2015-06-23 07:14:27,788 fail2ban.jail [1926]: INFO Creating new jail 'sshd'
2015-06-23 07:14:27,923 fail2ban.jail [1926]: INFO Jail 'sshd' uses poller
2015-06-23 07:14:27,985 fail2ban.filter [1926]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:14:27,985 fail2ban.jail [1926]: INFO Initiated 'polling' backend
2015-06-23 07:14:28,063 fail2ban.filter [1926]: INFO Added logfile = /var/log/secure
2015-06-23 07:14:28,064 fail2ban.filter [1926]: INFO Set maxRetry = 2
2015-06-23 07:14:28,066 fail2ban.filter [1926]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:14:28,066 fail2ban.actions [1926]: INFO Set banTime = 86400
2015-06-23 07:14:28,067 fail2ban.filter [1926]: INFO Set findtime = 600
2015-06-23 07:14:28,068 fail2ban.filter [1926]: INFO Set maxlines = 10
2015-06-23 07:14:28,158 fail2ban.server [1926]: INFO Jail sshd is not a JournalFilter instance
2015-06-23 07:14:28,459 fail2ban.jail [1926]: INFO Jail 'sshd' started
2015-06-23 07:21:32,667 fail2ban.server [1926]: INFO Stopping all jails
2015-06-23 07:21:33,181 fail2ban.jail [1926]: INFO Jail 'sshd' stopped
2015-06-23 07:21:33,188 fail2ban.server [1926]: INFO Exiting Fail2ban
2015-06-23 07:21:33,404 fail2ban.server [2489]: INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.9.1
2015-06-23 07:21:33,406 fail2ban.database [2489]: INFO Connected to fail2ban persistent database '/var/lib/fail2ban/fail2ban.sqlite3'
2015-06-23 07:21:33,409 fail2ban.jail [2489]: INFO Creating new jail 'sshd'
2015-06-23 07:21:33,413 fail2ban.jail [2489]: INFO Jail 'sshd' uses poller
2015-06-23 07:21:33,433 fail2ban.filter [2489]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:21:33,433 fail2ban.jail [2489]: INFO Initiated 'polling' backend
2015-06-23 07:21:33,438 fail2ban.filter [2489]: INFO Added logfile = /var/log/secure
2015-06-23 07:21:33,439 fail2ban.filter [2489]: INFO Set maxRetry = 3
2015-06-23 07:21:33,440 fail2ban.filter [2489]: INFO Set jail log file encoding to UTF-8
2015-06-23 07:21:33,441 fail2ban.actions [2489]: INFO Set banTime = 86400
2015-06-23 07:21:33,442 fail2ban.filter [2489]: INFO Set findtime = 600
2015-06-23 07:21:33,442 fail2ban.filter [2489]: INFO Set maxlines = 10
2015-06-23 07:21:33,501 fail2ban.server [2489]: INFO Jail sshd is not a JournalFilter instance
2015-06-23 07:21:33,599 fail2ban.jail [2489]: INFO Jail 'sshd' started
And SELinux is disabled.
linux ssh fail2ban
linux ssh fail2ban
edited Jun 23 '15 at 13:16
IvanCD
asked Jun 23 '15 at 11:27
IvanCDIvanCD
97
97
What on earth would you need to firewall off as a fail2ban from local host on ssh for..? We can answer more effectively if you clarify this
– Timothy Frew
Jan 24 at 0:18
add a comment |
What on earth would you need to firewall off as a fail2ban from local host on ssh for..? We can answer more effectively if you clarify this
– Timothy Frew
Jan 24 at 0:18
What on earth would you need to firewall off as a fail2ban from local host on ssh for..? We can answer more effectively if you clarify this
– Timothy Frew
Jan 24 at 0:18
What on earth would you need to firewall off as a fail2ban from local host on ssh for..? We can answer more effectively if you clarify this
– Timothy Frew
Jan 24 at 0:18
add a comment |
1 Answer
1
active
oldest
votes
In the file below,
/etc/fail2ban/jail.conf
(note if you are using jail.local
the same can be applied there also)
try changing auto
to gamin
or polling
Note:
if systemd
backend is chosen as the default but you enable a jail
for which logs are present only in its own log files, specify some other
backend for that jail (e.g. polling) and provide empty value forjournalmatch
. See https://github.com/fail2ban/fail2ban/issues/959#issuecomment-74901200
So, changing
backend = auto
to
backend = gamin
or
backend = polling
Worked for me.
add a comment |
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f700952%2ffail2ban-wont-ban-ssh-from-local-hosts%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
In the file below,
/etc/fail2ban/jail.conf
(note if you are using jail.local
the same can be applied there also)
try changing auto
to gamin
or polling
Note:
if systemd
backend is chosen as the default but you enable a jail
for which logs are present only in its own log files, specify some other
backend for that jail (e.g. polling) and provide empty value forjournalmatch
. See https://github.com/fail2ban/fail2ban/issues/959#issuecomment-74901200
So, changing
backend = auto
to
backend = gamin
or
backend = polling
Worked for me.
add a comment |
In the file below,
/etc/fail2ban/jail.conf
(note if you are using jail.local
the same can be applied there also)
try changing auto
to gamin
or polling
Note:
if systemd
backend is chosen as the default but you enable a jail
for which logs are present only in its own log files, specify some other
backend for that jail (e.g. polling) and provide empty value forjournalmatch
. See https://github.com/fail2ban/fail2ban/issues/959#issuecomment-74901200
So, changing
backend = auto
to
backend = gamin
or
backend = polling
Worked for me.
add a comment |
In the file below,
/etc/fail2ban/jail.conf
(note if you are using jail.local
the same can be applied there also)
try changing auto
to gamin
or polling
Note:
if systemd
backend is chosen as the default but you enable a jail
for which logs are present only in its own log files, specify some other
backend for that jail (e.g. polling) and provide empty value forjournalmatch
. See https://github.com/fail2ban/fail2ban/issues/959#issuecomment-74901200
So, changing
backend = auto
to
backend = gamin
or
backend = polling
Worked for me.
In the file below,
/etc/fail2ban/jail.conf
(note if you are using jail.local
the same can be applied there also)
try changing auto
to gamin
or polling
Note:
if systemd
backend is chosen as the default but you enable a jail
for which logs are present only in its own log files, specify some other
backend for that jail (e.g. polling) and provide empty value forjournalmatch
. See https://github.com/fail2ban/fail2ban/issues/959#issuecomment-74901200
So, changing
backend = auto
to
backend = gamin
or
backend = polling
Worked for me.
edited Mar 6 '16 at 19:30
chicks
3,09072033
3,09072033
answered Mar 6 '16 at 14:08
MuhasinMuhasin
11
11
add a comment |
add a comment |
Thanks for contributing an answer to Server Fault!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f700952%2ffail2ban-wont-ban-ssh-from-local-hosts%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
What on earth would you need to firewall off as a fail2ban from local host on ssh for..? We can answer more effectively if you clarify this
– Timothy Frew
Jan 24 at 0:18