Replies: 1 comment 1 reply
-
See #3189 (comment) and below for similar issue. Hints:
Normally (since #2090, the pam-messages are ignored as no failure (it is just a helper to recognize IP for session-ID), because otherwise the filter would consider single attempt as 2 failures, so jail would ban double as fast than specified in
It would be good to know what exactly are that 9904 missed messages (maybe filter cannot recognize something here).
|
Beta Was this translation helpful? Give feedback.
-
Environment:
Fail2Ban version (including any possible distribution suffixes): 1.0.2
OS, including release name/version: Rocky Linux 8.9
☑️Fail2Ban installed via OS/distribution mechanisms
☑️You have not applied any additional foreign patches to the codebase
The issue:
fail2ban ignores every ssh authentication error.
jail.local
fail2ban-client status
fail2ban-client status sshd
fail2ban-regex systemd-journal sshd
fail2ban-regex systemd-journal sshd --print-all-ignored
lastb
Beta Was this translation helpful? Give feedback.
All reactions