• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Resolved fail2ban do not start

  • Thread starter Deleted member 188409
  • Start date
D

Deleted member 188409

Guest
Hey,

my fail2ban doenst want to start. :( I'am not sure what are the next steps.

Plesk says:
Code:
Fehler: Die Einstellungen können nicht gespeichert werden: f2bmng failed: Synchronizing state of fail2ban.service with SysV init with /lib/systemd/systemd-sysv-install...
Executing /lib/systemd/systemd-sysv-install enable fail2ban
Job for fail2ban.service failed because the control process exited with error code. See "systemctl status fail2ban.service" and "journalctl -xe" for details.
ERROR:__main__:Failed to start fail2ban service.

systemctl status fail2ban.service
Code:
fail2ban.service - Fail2Ban Service
Loaded: loaded (/lib/systemd/system/fail2ban.service; enabled; vendor preset: enabled)
Active: failed (Result: start-limit-hit) since So 2019-01-13 20:31:03 CET; 2s ago
Docs: man:fail2ban(1)
Process: 18881 ExecStart=/usr/bin/fail2ban-client -x start (code=exited, status=255)

journalctl -xe
Code:
Jan 14 10:24:47 xxx.yyy.tld /usr/lib/plesk-9.0/psa-pc-remote[356]: Message aborted.
Jan 14 10:24:52 xxx.yyy.tld plesk_saslauthd[27139]: select timeout, exiting
Jan 14 10:25:01 xxx.yyy.tld CRON[27185]: pam_unix(cron:session): session opened for user root by (uid=0)
Jan 14 10:25:01 xxx.yyy.tld CRON[27184]: pam_unix(cron:session): session opened for user root by (uid=0)
Jan 14 10:25:01 xxx.yyy.tld CRON[27187]: (root) CMD (/opt/psa/admin/bin/php -dauto_prepend_file=sdk.php '/opt/psa/admin/plib/modules/revisium-antivirus/scripts/ra_executor_run.php')
Jan 14 10:25:01 xxx.yyy.tld CRON[27186]: (root) CMD (/opt/psa/admin/bin/php -dauto_prepend_file=sdk.php '/opt/psa/admin/plib/modules/magicspam/scripts/ms_clean_queue.php')
Jan 14 10:25:01 xxx.yyy.tld sshd[27182]: Invalid user adela from 159.89.180.93
Jan 14 10:25:01 xxx.yyy.tld sshd[27182]: input_userauth_request: invalid user adela [preauth]
Jan 14 10:25:01 xxx.yyy.tld sshd[27182]: pam_unix(sshd:auth): check pass; user unknown
Jan 14 10:25:01 xxx.yyy.tld sshd[27182]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=159.89.180.93
Jan 14 10:25:01 xxx.yyy.tld CRON[27184]: pam_unix(cron:session): session closed for user root
Jan 14 10:25:01 xxx.yyy.tld CRON[27185]: pam_unix(cron:session): session closed for user root
Jan 14 10:25:02 xxx.yyy.tld sshd[27182]: Failed password for invalid user adela from 159.89.180.93 port 41452 ssh2
Jan 14 10:25:03 xxx.yyy.tld sshd[27182]: Received disconnect from 159.89.180.93 port 41452:11: Bye Bye [preauth]
Jan 14 10:25:03 xxx.yyy.tld sshd[27182]: Disconnected from 159.89.180.93 port 41452 [preauth]
Jan 14 10:25:04 xxx.yyy.tld postfix/smtpd[27137]: connect from unknown[151.80.238.201]
Jan 14 10:25:04 xxx.yyy.tld plesk_saslauthd[27226]: listen=6, status=5, dbpath='/plesk/passwd.db', keypath='/plesk/passwd_db_key', chroot=1, unprivileged=1
Jan 14 10:25:04 xxx.yyy.tld plesk_saslauthd[27226]: privileges set to (108:114) (effective 108:114)
Jan 14 10:25:04 xxx.yyy.tld plesk_saslauthd[27226]: No such user '[email protected]' in mail authorization database
Jan 14 10:25:04 xxx.yyy.tld plesk_saslauthd[27226]: failed mail authentication attempt for user '[email protected]' (password len=12)
Jan 14 10:25:04 xxx.yyy.tld postfix/smtpd[27137]: warning: unknown[151.80.238.201]: SASL LOGIN authentication failed: authentication failure
Jan 14 10:25:04 xxx.yyy.tld postfix/smtpd[27137]: lost connection after AUTH from unknown[151.80.238.201]
Jan 14 10:25:04 xxx.yyy.tld postfix/smtpd[27137]: disconnect from unknown[151.80.238.201] ehlo=1 auth=0/1 commands=1/2
Jan 14 10:25:34 xxx.yyy.tld plesk_saslauthd[27226]: select timeout, exiting
Jan 14 10:25:47 xxx.yyy.tld postfix/smtpd[27137]: connect from unknown[178.62.196.23]
Jan 14 10:25:47 xxx.yyy.tld plesk_saslauthd[27229]: listen=6, status=5, dbpath='/plesk/passwd.db', keypath='/plesk/passwd_db_key', chroot=1, unprivileged=1
Jan 14 10:25:47 xxx.yyy.tld plesk_saslauthd[27229]: privileges set to (108:114) (effective 108:114)
Jan 14 10:25:47 xxx.yyy.tld plesk_saslauthd[27229]: failed mail authentication attempt for user 'web97p74' (password len=1)
Jan 14 10:25:47 xxx.yyy.tld postfix/smtpd[27137]: warning: unknown[178.62.196.23]: SASL LOGIN authentication failed: authentication failure
Jan 14 10:25:47 xxx.yyy.tld postfix/smtpd[27137]: disconnect from unknown[178.62.196.23] ehlo=1 auth=0/1 quit=1 commands=2/3
Jan 14 10:26:01 xxx.yyy.tld CRON[27230]: pam_unix(cron:session): session opened for user root by (uid=0)
Jan 14 10:26:01 xxx.yyy.tld CRON[27231]: pam_unix(cron:session): session opened for user root by (uid=0)
Jan 14 10:26:01 xxx.yyy.tld CRON[27232]: (root) CMD ([ -x /opt/psa/admin/sbin/backupmng ] && /opt/psa/admin/sbin/backupmng >/dev/null 2>&1)
Jan 14 10:26:01 xxx.yyy.tld CRON[27233]: (root) CMD (/opt/psa/admin/bin/php -dauto_prepend_file=sdk.php '/opt/psa/admin/plib/modules/revisium-antivirus/scripts/ra_executor_run.php')
Jan 14 10:26:01 xxx.yyy.tld CRON[27230]: pam_unix(cron:session): session closed for user root
Jan 14 10:26:02 xxx.yyy.tld CRON[27231]: pam_unix(cron:session): session closed for user root
Jan 14 10:26:05 xxx.yyy.tld postfix/smtpd[27137]: warning: hostname control.v545-5d8e5d8e.bid does not resolve to address 51.254.58.226
Jan 14 10:26:05 xxx.yyy.tld postfix/smtpd[27137]: connect from unknown[51.254.58.226]
Jan 14 10:26:05 xxx.yyy.tld plesk_saslauthd[27229]: No such user '[email protected]' in mail authorization database
Jan 14 10:26:05 xxx.yyy.tld plesk_saslauthd[27229]: failed mail authentication attempt for user '[email protected]' (password len=7)
Jan 14 10:26:05 xxx.yyy.tld postfix/smtpd[27137]: warning: unknown[51.254.58.226]: SASL LOGIN authentication failed: authentication failure
Jan 14 10:26:05 xxx.yyy.tld postfix/smtpd[27137]: lost connection after AUTH from unknown[51.254.58.226]
Jan 14 10:26:05 xxx.yyy.tld postfix/smtpd[27137]: disconnect from unknown[51.254.58.226] ehlo=1 auth=0/1 commands=1/2
Jan 14 10:26:35 xxx.yyy.tld plesk_saslauthd[27229]: select timeout, exiting
Jan 14 10:26:40 xxx.yyy.tld dovecot[746]: imap-login: Login: user=<[email protected]>, method=PLAIN, rip=2.203.10.133, lip=81.169.193.28, mpid=27269, TLS, session=<VaZppGd/ccECywqF>
Jan 14 10:26:43 xxx.yyy.tld dovecot[746]: service=imap, [email protected], ip=[2.203.10.133]. Logged out rcvd=248, sent=1016
Jan 14 10:27:01 xxx.yyy.tld CRON[27272]: pam_unix(cron:session): session opened for user root by (uid=0)
Jan 14 10:27:01 xxx.yyy.tld CRON[27273]: pam_unix(cron:session): session opened for user root by (uid=0)
Jan 14 10:27:01 xxx.yyy.tld CRON[27274]: (root) CMD (/opt/psa/bin/sw-engine-pleskrun /opt/psa/admin/plib/DailyMaintainance/task-script.php StoreOutgoingMessagesStatistics >/dev/null 2>&1)
Jan 14 10:27:01 xxx.yyy.tld CRON[27275]: (root) CMD (/opt/psa/admin/bin/php -dauto_prepend_file=sdk.php '/opt/psa/admin/plib/modules/revisium-antivirus/scripts/ra_executor_run.php')
Jan 14 10:27:02 xxx.yyy.tld CRON[27273]: pam_unix(cron:session): session closed for user root
Jan 14 10:27:03 xxx.yyy.tld CRON[27272]: pam_unix(cron:session): session closed for user root
Jan 14 10:27:10 xxx.yyy.tld sshd[27309]: Invalid user stratos from 54.37.68.191
Jan 14 10:27:10 xxx.yyy.tld sshd[27309]: input_userauth_request: invalid user stratos [preauth]
Jan 14 10:27:10 xxx.yyy.tld sshd[27309]: pam_unix(sshd:auth): check pass; user unknown
Jan 14 10:27:10 xxx.yyy.tld sshd[27309]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=54.37.68.191
Jan 14 10:27:12 xxx.yyy.tld sshd[27309]: Failed password for invalid user stratos from 54.37.68.191 port 37928 ssh2
Jan 14 10:27:12 xxx.yyy.tld sshd[27309]: Received disconnect from 54.37.68.191 port 37928:11: Bye Bye [preauth]
Jan 14 10:27:12 xxx.yyy.tld sshd[27309]: Disconnected from 54.37.68.191 port 37928 [preauth]
Jan 14 10:27:45 xxx.yyy.tld fail2ban-client[27317]: ERROR  There is no directory /var/run/fail2ban to contain the socket file /var/run/fail2ban/fail2ban.sock.
Jan 14 10:27:45 xxx.yyy.tld fail2ban-client[27319]: ERROR  There is no directory /var/run/fail2ban to contain the socket file /var/run/fail2ban/fail2ban.sock.
Jan 14 10:27:45 xxx.yyy.tld fail2ban-client[27321]: ERROR  There is no directory /var/run/fail2ban to contain the socket file /var/run/fail2ban/fail2ban.sock.
Jan 14 10:27:46 xxx.yyy.tld fail2ban-client[27323]: ERROR  There is no directory /var/run/fail2ban to contain the socket file /var/run/fail2ban/fail2ban.sock.
Jan 14 10:27:46 xxx.yyy.tld fail2ban-client[27325]: ERROR  There is no directory /var/run/fail2ban to contain the socket file /var/run/fail2ban/fail2ban.sock.

Thanks for your help
 
I have solved the problem by my self.
Re-insall are helpful
 
Back
Top