Now when i restart the service and i go to check my fail2ban.log files i get a entry full of this
fail2ban.server : ERROR Unexpected communication error
I know fail2ban is working for SSH:
2009-06-03 16:14:35,291 fail2ban.actions: WARNING [ssh] Ban 202.169.224.202
But its not working for proftpd, i have tried a few times, any ideas?
These are the errors i get on the fail2ban log's:
2009-06-03 16:14:33,277 fail2ban.server : INFO Exiting Fail2ban
2009-06-03 16:14:33,808 fail2ban.server : INFO Changed logging target to /var/log/fail2ban.log for Fail2ban v0.8.3
2009-06-03 16:14:33,809 fail2ban.jail : INFO Creating new jail 'ssh'
2009-06-03 16:14:33,810 fail2ban.jail : INFO Jail 'ssh' uses poller
2009-06-03 16:14:33,847 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:33,848 fail2ban.filter : INFO Added logfile = /var/log/auth.log
2009-06-03 16:14:33,849 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:33,850 fail2ban.filter : INFO Set maxRetry = 6
2009-06-03 16:14:33,850 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:33,852 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:33,853 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:33,854 fail2ban.filter : INFO Set findtime = 600
2009-06-03 16:14:33,855 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:33,855 fail2ban.actions: INFO Set banTime = 600
2009-06-03 16:14:33,856 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:33,867 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:33,874 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:33,881 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:33,889 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:33,897 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:33,907 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:33,919 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:33,933 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:33,950 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:33,967 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:33,986 fail2ban.jail : INFO Creating new jail 'apache'
2009-06-03 16:14:33,986 fail2ban.jail : INFO Jail 'apache' uses poller
2009-06-03 16:14:33,988 fail2ban.filter : INFO Added logfile = /var/log/apache2/other_vhosts_access.log
2009-06-03 16:14:33,989 fail2ban.filter : INFO Added logfile = /var/log/apache2/access.log
2009-06-03 16:14:33,991 fail2ban.filter : INFO Set maxRetry = 6
2009-06-03 16:14:33,994 fail2ban.filter : INFO Set findtime = 600
2009-06-03 16:14:33,995 fail2ban.actions: INFO Set banTime = 600
2009-06-03 16:14:34,000 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,003 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,004 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,005 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,007 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,008 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,010 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,011 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,012 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,014 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,015 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,016 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,018 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,020 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,022 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,023 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,024 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,026 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,027 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,028 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,029 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,030 fail2ban.jail : INFO Creating new jail 'proftpd'
2009-06-03 16:14:34,030 fail2ban.jail : INFO Jail 'proftpd' uses poller
2009-06-03 16:14:34,032 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,033 fail2ban.filter : INFO Added logfile = /var/log/proftpd/proftpd.log
2009-06-03 16:14:34,034 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,034 fail2ban.filter : INFO Set maxRetry = 6
2009-06-03 16:14:34,035 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,036 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,038 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,038 fail2ban.filter : INFO Set findtime = 600
2009-06-03 16:14:34,039 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,040 fail2ban.actions: INFO Set banTime = 600
2009-06-03 16:14:34,041 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,044 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,047 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,051 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,054 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,055 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,057 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,058 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,060 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,061 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,062 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,064 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,065 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,066 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,068 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,070 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,072 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,073 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,074 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,076 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,077 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,078 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,080 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,081 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,156 fail2ban.jail : INFO Jail 'ssh' started
2009-06-03 16:14:34,162 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,240 fail2ban.jail : INFO Jail 'apache' started
2009-06-03 16:14:34,241 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:34,290 fail2ban.jail : INFO Jail 'proftpd' started
2009-06-03 16:14:34,344 fail2ban.server : ERROR Unexpected communication error
2009-06-03 16:14:35,291 fail2ban.actions: WARNING [ssh] Ban 202.169.224.202
Also this is my iptables, i can see one person has been blocked, but why dont people on ftp that i know are brute forcing, not getting blocked?
infotech@infotechserver:/etc/fail2ban$ sudo iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destination
fail2ban-proftpd tcp -- anywhere anywhere multiport dports ftp
fail2ban-apache tcp -- anywhere anywhere multiport dports www
fail2ban-ssh tcp -- anywhere anywhere multiport dports ssh
Chain FORWARD (policy ACCEPT)
target prot opt source destination
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
Chain fail2ban-apache (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere
Chain fail2ban-proftpd (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere
Chain fail2ban-ssh (1 references)
target prot opt source destination
DROP all -- host-202-169-224-202.jmn.net.id anywhere
RETURN all -- anywhere anywhere
Edited by wilo300zx, 03 June 2009 - 01:24 AM.