• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Issue LogBrowser, Fail2ban and SASL filter

OverWolf

Regular Pleskian
Server operating system version
Almalinux 9.7
Plesk version and microupdate number
18.0.74 Update #3
Good morning,
I've read a lot about 'problems' with Fail2ban sals filter, and the "solution" was to use postfix[mode=auth], but in my case it doesn't work.
After a little troubleshooting, I have found this inconsistency beetween what is showed on LoBbrowser and what I found on maillog:

LogBrowser
warning: cm-72-241-202-104.buckeyecom.net[72.241.202.104]: SASL CRAM-MD5 authentication failed: authentication failure, sasl_username=xxxx

maillog
postfix/smtpd[53528]: warning: SASL authentication failure: incorrect digest response

As you can see, on maillog isn't present the same syntax and even less the IP (HOST), so the sasl filter (old or new with postfix mode) cannot catch the entry.

Now, I ask to you, is there the possibility to catch this IP and block it ?Where I can find the LogBrowser entry so I can configure Fail2ban filter to look at that log ? Should I must set a different journalmatch ?

Thank you for your support.
 
Back
Top