- Server operating system version
- Debian 11
- Plesk version and microupdate number
- Plesk Obsidian 18.0.67 Update #3
Hello,
I have noticed that the IP addresses that are supposed to be banned in Recidive, actually still can access the server.
Here is an extract from the F2B logs for a specific attacking IP address:
2025-02-23 02:36:01,726 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-23 02:36:01
2025-02-23 02:37:38,237 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-23 02:37:38
2025-02-23 02:39:13,230 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-23 02:39:13
2025-02-23 02:39:13,613 fail2ban.actions [939832]: NOTICE [plesk-postfix] Ban 185.226.117.240
2025-02-23 02:39:13,614 fail2ban.filter [939832]: INFO [recidive] Found 185.226.117.240 - 2025-02-23 02:39:13
2025-02-23 03:39:13,243 fail2ban.actions [939832]: NOTICE [plesk-postfix] Unban 185.226.117.240
2025-02-23 03:39:15,657 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-23 03:39:15
2025-02-23 03:40:47,978 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-23 03:40:47
2025-02-23 03:42:23,482 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-23 03:42:23
2025-02-23 03:42:23,511 fail2ban.actions [939832]: NOTICE [plesk-postfix] Ban 185.226.117.240
2025-02-23 03:42:23,521 fail2ban.filter [939832]: INFO [recidive] Found 185.226.117.240 - 2025-02-23 03:42:23
2025-02-23 04:42:23,137 fail2ban.actions [939832]: NOTICE [plesk-postfix] Unban 185.226.117.240
2025-02-24 03:23:24,790 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-24 03:23:24
2025-02-24 03:24:52,367 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-24 03:24:52
2025-02-24 03:26:28,062 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-24 03:26:28
2025-02-24 03:26:28,392 fail2ban.actions [939832]: NOTICE [plesk-postfix] Ban 185.226.117.240
2025-02-24 03:26:28,401 fail2ban.filter [939832]: INFO [recidive] Found 185.226.117.240 - 2025-02-24 03:26:28
2025-02-24 04:26:28,378 fail2ban.actions [939832]: NOTICE [plesk-postfix] Unban 185.226.117.240
2025-02-24 04:27:45,311 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-24 04:27:45
2025-02-24 04:29:32,061 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-24 04:29:32
2025-02-24 04:31:20,203 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-24 04:31:20
2025-02-24 04:31:20,750 fail2ban.actions [939832]: NOTICE [plesk-postfix] Ban 185.226.117.240
2025-02-24 04:31:20,906 fail2ban.filter [939832]: INFO [recidive] Found 185.226.117.240 - 2025-02-24 04:31:20
2025-02-24 04:31:21,413 fail2ban.actions [939832]: NOTICE [recidive] Ban 185.226.117.240
2025-02-24 05:31:20,391 fail2ban.actions [939832]: NOTICE [plesk-postfix] Unban 185.226.117.240 <----------------------------------- !!!!!!!!!!!!!!!!!!!!
2025-02-24 06:25:46,311 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-24 06:25:46
2025-02-25 19:02:40,854 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-25 19:02:40
2025-02-25 19:02:47,885 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-25 19:02:47
2025-02-25 19:02:57,898 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-25 19:02:57
2025-02-25 19:02:57,925 fail2ban.actions [939832]: NOTICE [plesk-postfix] Ban 185.226.117.240
2025-02-25 19:02:57,933 fail2ban.filter [939832]: INFO [recidive] Found 185.226.117.240 - 2025-02-25 19:02:57
As you can see, everything works correctly at the beginning:
The address is banned a few times by the Postfix jail (for 1 hour), and the Recidive counter is running until this jail bans the address (for 1 week).
OK, but one hour later the Postfix jail unbans the address!
And the cycle starts again, making the Recidive jail completely useless.
Where did I go wrong in my configuration?
Regards,
François
I have noticed that the IP addresses that are supposed to be banned in Recidive, actually still can access the server.
Here is an extract from the F2B logs for a specific attacking IP address:
2025-02-23 02:36:01,726 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-23 02:36:01
2025-02-23 02:37:38,237 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-23 02:37:38
2025-02-23 02:39:13,230 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-23 02:39:13
2025-02-23 02:39:13,613 fail2ban.actions [939832]: NOTICE [plesk-postfix] Ban 185.226.117.240
2025-02-23 02:39:13,614 fail2ban.filter [939832]: INFO [recidive] Found 185.226.117.240 - 2025-02-23 02:39:13
2025-02-23 03:39:13,243 fail2ban.actions [939832]: NOTICE [plesk-postfix] Unban 185.226.117.240
2025-02-23 03:39:15,657 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-23 03:39:15
2025-02-23 03:40:47,978 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-23 03:40:47
2025-02-23 03:42:23,482 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-23 03:42:23
2025-02-23 03:42:23,511 fail2ban.actions [939832]: NOTICE [plesk-postfix] Ban 185.226.117.240
2025-02-23 03:42:23,521 fail2ban.filter [939832]: INFO [recidive] Found 185.226.117.240 - 2025-02-23 03:42:23
2025-02-23 04:42:23,137 fail2ban.actions [939832]: NOTICE [plesk-postfix] Unban 185.226.117.240
2025-02-24 03:23:24,790 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-24 03:23:24
2025-02-24 03:24:52,367 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-24 03:24:52
2025-02-24 03:26:28,062 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-24 03:26:28
2025-02-24 03:26:28,392 fail2ban.actions [939832]: NOTICE [plesk-postfix] Ban 185.226.117.240
2025-02-24 03:26:28,401 fail2ban.filter [939832]: INFO [recidive] Found 185.226.117.240 - 2025-02-24 03:26:28
2025-02-24 04:26:28,378 fail2ban.actions [939832]: NOTICE [plesk-postfix] Unban 185.226.117.240
2025-02-24 04:27:45,311 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-24 04:27:45
2025-02-24 04:29:32,061 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-24 04:29:32
2025-02-24 04:31:20,203 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-24 04:31:20
2025-02-24 04:31:20,750 fail2ban.actions [939832]: NOTICE [plesk-postfix] Ban 185.226.117.240
2025-02-24 04:31:20,906 fail2ban.filter [939832]: INFO [recidive] Found 185.226.117.240 - 2025-02-24 04:31:20
2025-02-24 04:31:21,413 fail2ban.actions [939832]: NOTICE [recidive] Ban 185.226.117.240
2025-02-24 05:31:20,391 fail2ban.actions [939832]: NOTICE [plesk-postfix] Unban 185.226.117.240 <----------------------------------- !!!!!!!!!!!!!!!!!!!!
2025-02-24 06:25:46,311 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-24 06:25:46
2025-02-25 19:02:40,854 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-25 19:02:40
2025-02-25 19:02:47,885 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-25 19:02:47
2025-02-25 19:02:57,898 fail2ban.filter [939832]: INFO [plesk-postfix] Found 185.226.117.240 - 2025-02-25 19:02:57
2025-02-25 19:02:57,925 fail2ban.actions [939832]: NOTICE [plesk-postfix] Ban 185.226.117.240
2025-02-25 19:02:57,933 fail2ban.filter [939832]: INFO [recidive] Found 185.226.117.240 - 2025-02-25 19:02:57
As you can see, everything works correctly at the beginning:
The address is banned a few times by the Postfix jail (for 1 hour), and the Recidive counter is running until this jail bans the address (for 1 week).
OK, but one hour later the Postfix jail unbans the address!
And the cycle starts again, making the Recidive jail completely useless.
Where did I go wrong in my configuration?
Regards,
François