Jump to content

Fail2Ban not acting on attempts fast enough...


Recommended Posts

I have a small linux server setup with FreePBX on it.  I have it locked down with Fail2Ban and for some odd reason I keep getting major hack attempts.  I have the settings set to a pretty restrictive set 3 bad attempts in 30 minutes and you get banned for 1 hour.  This has helped knock down a ton of attempts on the system but there are a few who get way beyond the threshold I have setup.  I get emails from Fail2Ban that say things like "banned after 146 attempts, banned after 138 attempts, etc"  so why is it allowing that many attempts before banning the ip's.  Now if I notice many blocks to the same ip over the course of a few hours I will go in and permanently add that ip to the iptables drop list.  But that is not my concern, my concern is that Fail2Ban is allowing so many before dumping them into the abyss.  My passwords are super strong and not anything remotely available in any dictionary in the world and are notoriously 12-18 characters long with uppers, lowers, numbers and special characters all jumbled up in a fashion that I have laid out in my head and never written down.

 

Has anyone else gone thru this as well?

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.