(By the way ... could it cause any problems if you change a cronjob time?)
As you can see there a several login attempts from IP address 139.162.250.136 but for some reason Fail2Ban doesn't block the IP address. It doesn't even give any notice.Jun 14 16:58:19 xxxxx postfix/smtpd[17668]: connect from li1535-136.members.linode.com[139.162.250.136]
Jun 14 16:58:20 xxxxx postfix/smtpd[17668]: SSL_accept error from li1535-136.members.linode.com[139.162.250.136]: Connection reset by peer
Jun 14 16:58:20 xxxxx postfix/smtpd[17668]: lost connection after CONNECT from li1535-136.members.linode.com[139.162.250.136]
Jun 14 16:58:21 xxxxx postfix/smtpd[17668]: disconnect from li1535-136.members.linode.com[139.162.250.136]
Jun 14 16:58:21 xxxxx postfix/smtpd[17668]: connect from li1535-136.members.linode.com[139.162.250.136]
Jun 14 16:58:22 xxxxx postfix/smtpd[17668]: SSL_accept error from li1535-136.members.linode.com[139.162.250.136]: Connection reset by peer
Jun 14 16:58:22 xxxxx postfix/smtpd[17668]: lost connection after CONNECT from li1535-136.members.linode.com[139.162.250.136]
Jun 14 16:58:22 xxxxx postfix/smtpd[17668]: disconnect from li1535-136.members.linode.com[139.162.250.136]
Jun 14 16:58:22 xxxxx postfix/smtpd[17668]: connect from li1535-136.members.linode.com[139.162.250.136]
Jun 14 16:58:24 xxxxx postfix/smtpd[17668]: SSL_accept error from li1535-136.members.linode.com[139.162.250.136]: Connection reset by peer
Jun 14 16:58:24 xxxxx postfix/smtpd[17668]: lost connection after CONNECT from li1535-136.members.linode.com[139.162.250.136]
Jun 14 16:58:24 xxxxx postfix/smtpd[17668]: disconnect from li1535-136.members.linode.com[139.162.250.136]
Jun 14 16:58:24 xxxxx postfix/smtpd[17668]: connect from li1535-136.members.linode.com[139.162.250.136]
Jun 14 16:58:24 xxxxx postfix/smtpd[17668]: SSL_accept error from li1535-136.members.linode.com[139.162.250.136]: -1
Jun 14 16:58:24 xxxxx postfix/smtpd[17668]: warning: TLS library problem: 17668:error:1408A10B:SSL routines:SSL3_GET_CLIENT_HELLO:wrong version number:s3_srvr.c:956:
Jun 14 16:58:24 xxxxx postfix/smtpd[17668]: lost connection after CONNECT from li1535-136.members.linode.com[139.162.250.136]
Jun 14 16:58:24 xxxxx postfix/smtpd[17668]: disconnect from li1535-136.members.linode.com[139.162.250.136]
Jun 14 16:58:24 xxxxx postfix/smtpd[17668]: connect from li1535-136.members.linode.com[139.162.250.136]
Jun 14 16:58:25 xxxxx postfix/smtpd[17668]: lost connection after CONNECT from li1535-136.members.linode.com[139.162.250.136]
Jun 14 16:58:25 xxxxx postfix/smtpd[17668]: disconnect from li1535-136.members.linode.com[139.162.250.136]
Jun 14 14:32:02 xxxxx postfix/smtpd[17366]: connect from 118-161-250-131.dynamic.hinet.net[118.161.250.131]
Jun 14 14:32:03 xxxxx postfix/smtpd[17366]: NOQUEUE: reject: RCPT from 118-161-250-131.dynamic.hinet.net[118.161.250.131]: 454 4.7.1 <[email protected]>: Relay access denied; from=<[email protected]> to=<[email protected]> proto=SMTP helo=<85.214.251.230>
Jun 14 14:32:04 xxxxx postfix/smtpd[17366]: lost connection after RCPT from 118-161-250-131.dynamic.hinet.net[118.161.250.131]
Jun 14 14:32:04 xxxxx postfix/smtpd[17366]: disconnect from 118-161-250-131.dynamic.hinet.net[118.161.250.131]
Jun 14 14:32:04 xxxxx /usr/lib64/plesk-9.0/psa-pc-remote[357]: Message aborted.
Jun 14 14:32:04 xxxxx /usr/lib64/plesk-9.0/psa-pc-remote[357]: Message aborted.
Jun 14 14:35:24 xxxxx postfix/anvil[17368]: statistics: max connection rate 1/60s for (smtp:118.161.250.131) at Jun 14 14:32:02
Jun 14 14:35:24 xxxxx postfix/anvil[17368]: statistics: max connection count 1 for (smtp:118.161.250.131) at Jun 14 14:32:02
Jun 14 14:35:24 xxxxx postfix/anvil[17368]: statistics: max cache size 1 at Jun 14 14:32:02
Jun 14 16:37:33 xxxxx postfix/smtpd[17629]: connect from 220-135-220-150.HINET-IP.hinet.net[220.135.220.150]
Jun 14 16:37:34 xxxxx postfix/smtpd[17629]: NOQUEUE: reject: RCPT from 220-135-220-150.HINET-IP.hinet.net[220.135.220.150]: 454 4.7.1 <[email protected]>: Relay access denied; from=<[email protected]> to=<[email protected]> proto=SMTP helo=<YYYYYYYYY>
Jun 14 16:37:34 xxxxx postfix/smtpd[17629]: lost connection after RCPT from 220-135-220-150.HINET-IP.hinet.net[220.135.220.150]
Jun 14 16:37:34 xxxxx postfix/smtpd[17629]: disconnect from 220-135-220-150.HINET-IP.hinet.net[220.135.220.150]
Jun 14 16:37:34 xxxxx /usr/lib64/plesk-9.0/psa-pc-remote[357]: Message aborted.
Jun 14 16:37:34 xxxxx /usr/lib64/plesk-9.0/psa-pc-remote[357]: Message aborted.
I understand that, but what I meant is ... if all of the VPS'es start connecting with the Plesk server at the exact same time (since the installations are all based on the same image file) maybe this causes a connection error.
I did this ... I even adjusted the max retry amount to 2, but Fail2Ban doesn't pick them up.
I fixed it.I don't see that "Mark Thread as Solved" link by the way.