./security/fail2ban, Scans log files and bans IP that makes too many password failures

[ Image CVSweb ] [ Image Homepage ] [ Image RSS ] [ Image Required by ]


Branch: CURRENT, Version: 1.1.1, Package name: fail2ban-1.1.1, Maintainer: nils

Fail2Ban scans log files like /var/log/pwdfail and bans IP
that makes too many password failures. It updates firewall
rules to reject the IP address. Theses rules can be defined by
the user. Fail2Ban can read multiple log files such as sshd
or Apache web server ones.


Required to run:
[databases/py-sqlite3] [lang/python37]

Required to build:
[textproc/py-sphinx] [textproc/py-numpydoc] [pkgtools/cwrappers]

Master sites:

Filesize: 612.428 KB

Version history: (Expand)


CVS history: (Expand)


   2026-09-26 09:39:41 by Thomas Klausner | Files touched by this commit (1)
Log message:
fail2ban: add missing tool
   2026-09-22 14:04:33 by Adam Ciarcinski | Files touched by this commit (4) | Package updated
Log message:
fail2ban: updated to 1.1.1

1.1.1

Compatibility

action.d/iptables.conf rewritten due to support of multiple chains (gh-3909), \ 
therefore user-level derivations (action including iptables-based action) may \ 
become incompatible, e. g. some tags if used need to be replaced, e. g. \ 
<chain> with $chain or <_ipt_for_proto-iter> with <_ipt-iter>;
filter.d/exim.conf - several rules of mode normal moved to new mode more, \ 
because of too risky handling (see gh-3940), to use it as before set mode = more \ 
for exim jail, but be aware of the consequences.

Fixes

fixes catastrophic backtracking explosion for REs in domino-smtp and dovecot \ 
filters (GHSA-33wh-ccjc-p397, gh-4221)
fixes systemd bug with missing journal descriptor after rotation by reopening of \ 
journal if it is recognized as not alive (gh-3929)
improve threaded clean-up of all filters, new thread functions afterStop (to \ 
force clean-up after stop) and done, invoking afterStop once
ensure journal-reader is always closed (additional prevention against leaks and \ 
"too many open files"), thereby avoid sporadic segfault in systemd \ 
module
fixes systemd causing "too many open files" error for a lot of journal \ 
files and large amount of systemd jails (see new parameter rotated below, \ 
gh-3391);
passing of arguments from jails to action or filter will affect conditional \ 
section too (gh-4069), e. g. setting blocktype="DROP" via jail for \ 
action would now apply for IPv4 and IPv6 chains, to submit different blocktype \ 
for IPv4 and IPv6 from jail, one can pass them like in this example: banaction = \ 
iptables-ipset[blocktype="...", \ 
blocktype?family=inet6="..."]
jail.conf:
default banactions need to be specified in paths-*.conf (maintainer level) now
since stock fail2ban includes paths-debian.conf by default, banactions are \ 
nftables (can be overwritten in jail.local by user)
paths-common.conf:
changed default mysql_log path (default logpath of mysqld-auth jail without \ 
maintainer overrides, gh-3932)
paths-debian.conf:
default banactions are nftables
sshd backend switched to systemd (gh-3292)
postfix backend switched to systemd (gh-3527)
action.d/firewallcmd-ipset.conf:
rename ipsettype to ipsetbackend (gh-2620), parameter ipsettype will be used now \ 
to the real set type (gh-3760)
action.d/nftables.conf:
action fixed for SELinux without execmem permission, rewrite capturing with grep \ 
-P using grep -E or sed (PCRE-JIT by grep -P may cause SELinux denial for \ 
execmem, see gh-4137)
action.d/xarf-login-attack.conf - ignore errors or warnings in output of dig \ 
provided as comment (gh-4068)
filter.d/apache-badbots.conf, filter.d/apache-fakegooglebot.conf:
regexs rewritten more strict (removed catch-alls, etc);
regexs fixed to match lines with vhost in accesslog (gh-1594)
filter.d/apache-noscript.conf - consider new log-format with "AH02811: \ 
stderr from /..." (gh-3900)
filter.d/apache-overflows.conf - consider AH10244: invalid URI path (gh-3778, \ 
gh-3900)
filter.d/asterisk.conf - fixed RE for "no matching endpoint" with \ 
retry info (like after X tries in Y ms) at end, loosening of end anchor (ignore \ 
any simple text tokens at end if no single quote found), gh-4037
filter.d/exim.conf:
several rules of mode normal moved to new mode more, because of too risky \ 
handling (gh-3940), thereby mode aggressive is not affected, because it fully \ 
includes mode more now;
mode aggressive extended to catch dropped by ACL failures, e.g. "ACL: \ 
Country is banned"
filter.d/freeswitch.conf - bypass some new info in prefix before [WARNING] \ 
(changed default _pref_line), FreeSWITCH log line prefix has changed in newer \ 
versions (gh-3143)
filter.d/lighttpd-auth.conf - fixed regex (if failures generated by \ 
systemd-journal), bypass several prefixes now (gh-3955)
filter.d/postfix.conf:
extended prefregex to capture username in postfix SASL failures (gh-4165)
consider CONNECT and other rejected commands as a valid _pref (gh-3800)
default _daemon in prefix-line is loosened - can match everything starting with \ 
word postfix, like postfix-example.com/smtpd (gh-3297)
add optional NOQUEUE: prefix to ddos regex (gh-4072)
internal parameter _pref is renamed to _cmd, _pref matches now optional prefix \ 
like NOQUEUE:  etc
modes ddos and aggressive extended to match rate limit exceeded for connection \ 
or message delivery request rates (gh-3265, gh-4073)
modes aggressive extended to match hostname does not resolve to address \ 
(gh-4218, gh-4078)
filter.d/dropbear.conf:
recognizes extra pid/timestamp if logged into stdout/journal, added journalmatch \ 
(gh-3597)
failregex extended to match different format of "Exit before auth" \ 
message (gh-3791)
filter.d/recidive.conf - restore possibility to set jail name in the filter, \ 
_jailname is positive now (gh-3769)
filter.d/roundcube-auth.conf - improved RE better matching log format of \ 
roundcube version 1.4+ (gh-3816)
filter.d/sendmail-reject.conf: (gh-4020)
support <F-MLFID> for BSD-style logfiles
add match for User unknown to default
the relay field may not always have a hostname before the ip address
mode aggressive enables match for lost input channel and Cannot resolve PTR record
filter.d/sshd.conf:
adapted to conform possible new daemon name sshd-session, since OpenSSH 9.8 \ 
several log messages will be tagged with as originating from a process named \ 
"sshd-session" rather than "sshd" (gh-3782)
ddos and aggressive modes: regex extended for timeout before authentication \ 
(optional connection from part, gh-3907)
filter.d/vsftpd.conf - fixed regex (if failures generated by systemd-journal, \ 
gh-3954)
filter.d/froxlor-auth.conf - updated the regex to the new logging situation for \ 
froxlor and changed logpath in jail.conf (gh-4075).
   2026-01-06 12:18:20 by Thomas Klausner | Files touched by this commit (51)
Log message:
*: forbid Python 3.11 for sphinx users

list from 'bob scan'
   2025-10-09 11:05:58 by Thomas Klausner | Files touched by this commit (1)
Log message:
fail2ban: fix pkglint
   2025-10-09 11:05:41 by Thomas Klausner | Files touched by this commit (1)
Log message:
fail2ban: mark as only for Python 3.11 and 3.12

3.10 is out due to py-sphinx, newer versions because this uses 2to3, which
was only part of Python up to 3.12.
   2025-10-09 09:58:14 by Thomas Klausner | Files touched by this commit (442)
Log message:
*: remove reference to (removed) Python 3.9
   2025-02-23 17:59:26 by Thomas Klausner | Files touched by this commit (79)
Log message:
*: py-sphinx 8.2 drops support for Python 3.10
   2024-10-14 08:46:10 by Thomas Klausner | Files touched by this commit (325)
Log message:
*: clean-up after python38 removal