Hi,
this problem was present on my up to date system after following the ispconfig3 guide for ubuntu 9.10 and google says some debian users had a similar problem too.(bug 573314)
If you want to block smtp brute force attempts you have to enable the sasl filter in jail.conf and change failregex in /etc/fail2ban/filter.d/sasl.conf to
Code:
failregex = (?i): warning: [-._\w]+\[<HOST>\]: SASL (?:LOGIN|PLAIN|(?:CRAM|DIGEST)-MD5) authentication failed
To test it:
Code:
fail2ban-regex /var/log/mail.log /etc/fail2ban/filter.d/sasl.conf
This is a "works for me solution"
Thanks for the great guide, Ispconfig makes things so easy....
Recent comments
7 hours 35 min ago
12 hours 34 min ago
14 hours 46 sec ago
14 hours 53 min ago
16 hours 36 min ago
21 hours 17 sec ago
21 hours 52 min ago
1 day 5 min ago
1 day 13 hours ago
1 day 14 hours ago