ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    [How to] Fail2ban on CentOS 7

    Scheduled Pinned Locked Moved IT Discussion
    24 Posts 9 Posters 9.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DanpD
      Danp @A Former User
      last edited by

      @Aaron-Studer You left out the steps that create the sshd.local file. Was this intentional?

      1 Reply Last reply Reply Quote 0
      • DanpD
        Danp
        last edited by

        Seems like Fail2Ban stops logging after a log rotation. Anyone else run into this?

        ? 1 Reply Last reply Reply Quote 0
        • ?
          A Former User @Danp
          last edited by

          @Danp said:

          Seems like Fail2Ban stops logging after a log rotation. Anyone else run into this?

          I don't think Fail2ban likes log rotate.

          DanpD 1 Reply Last reply Reply Quote 0
          • DanpD
            Danp @A Former User
            last edited by

            @thecreativeone91 said:

            I don't think Fail2ban likes log rotate.

            Looks that way. I found this, but it's for an older version of both F2B and Centos.

            1 Reply Last reply Reply Quote 0
            • DanpD
              Danp
              last edited by

              Added "copytruncate" to the F2B logrotate configuration file and then ran a manual log rotation. Seemed to work ok (system is still logging to fail2ban.log), but I will continue to monitor.

              1 Reply Last reply Reply Quote 1
              • S
                Sparkum
                last edited by

                When I do

                fail2ban-client status sshd

                I get

                [root@dc fail2ban]# fail2ban-client status sshd
                ERROR NOK: ('sshd',)
                Sorry but the jail 'sshd' does not exist

                When I check the audit logs I get logs....

                DanpD 1 Reply Last reply Reply Quote 0
                • DanpD
                  Danp @Sparkum
                  last edited by

                  @Sparkum What do you get when you enter the following?:

                  fail2ban-client status
                  
                  S 1 Reply Last reply Reply Quote 0
                  • S
                    Sparkum @Danp
                    last edited by Sparkum

                    @Danp

                    [root@dc fail2ban]# fail2ban-client status
                    Status
                    |- Number of jail: 0
                    `- Jail list:

                    1 Reply Last reply Reply Quote 0
                    • DanpD
                      Danp
                      last edited by

                      Did you follow the steps and create the jail.local file?

                      S 1 Reply Last reply Reply Quote 0
                      • S
                        Sparkum @Danp
                        last edited by

                        @Danp

                        Yep

                        fail.PNG

                        1 Reply Last reply Reply Quote 0
                        • S
                          Sparkum
                          last edited by

                          Noticed the problem happened below.

                          Changed "enabled" to "enable" and looks like it works.

                          Status for the jail: sshd
                          |- Filter
                          | |- Currently failed: 0
                          | |- Total failed: 0
                          | - File list: /var/log/secure - Actions
                          |- Currently banned: 0
                          |- Total banned: 0
                          `- Banned IP list:

                          Much appreciated thanks

                          DanpD 1 Reply Last reply Reply Quote 0
                          • DanpD
                            Danp @Sparkum
                            last edited by

                            @Sparkum That's strange, b/c I believe "enabled" is the correct entry.

                            1 Reply Last reply Reply Quote 0
                            • 1
                            • 2
                            • 1 / 2
                            • First post
                              Last post