• We value your experience with Plesk during 2025
    Plesk strives to perform even better in 2026. To help us improve further, please answer a few questions about your experience with Plesk Obsidian 2025.
    Please take this short survey:

    https://survey.webpros.com/
  • On Plesk for Linux mod_status is disabled on upgrades to improve Apache security.
    This is a one-time operation that occurs during an upgrade. You can manually enable mod_status later if needed.

Issue LogBrowser, Fail2ban and SASL filter

OverWolf

Regular Pleskian
Server operating system version
Almalinux 9.7
Plesk version and microupdate number
18.0.74 Update #3
Good morning,
I've read a lot about 'problems' with Fail2ban sals filter, and the "solution" was to use postfix[mode=auth], but in my case it doesn't work.
After a little troubleshooting, I have found this inconsistency beetween what is showed on LoBbrowser and what I found on maillog:

LogBrowser
warning: cm-72-241-202-104.buckeyecom.net[72.241.202.104]: SASL CRAM-MD5 authentication failed: authentication failure, sasl_username=xxxx

maillog
postfix/smtpd[53528]: warning: SASL authentication failure: incorrect digest response

As you can see, on maillog isn't present the same syntax and even less the IP (HOST), so the sasl filter (old or new with postfix mode) cannot catch the entry.

Now, I ask to you, is there the possibility to catch this IP and block it ?Where I can find the LogBrowser entry so I can configure Fail2ban filter to look at that log ? Should I must set a different journalmatch ?

Thank you for your support.
 
Back
Top