<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[iRedMail 开源邮件服务解决方案 - fail2ban 的 dovecot.iredmail.conf 未阻擋到該擋的IP]]></title>
		<link>https://bbs.iredmail.org/topic3409-fail2ban-dovecotiredmailconf-ip.html</link>
		<atom:link href="https://bbs.iredmail.org/feed-rss-topic3409.xml" rel="self" type="application/rss+xml" />
		<description><![CDATA[fail2ban 的 dovecot.iredmail.conf 未阻擋到該擋的IP 里最新回复的文章]]></description>
		<lastBuildDate>Mon, 16 Jan 2017 02:23:58 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[回复: fail2ban 的 dovecot.iredmail.conf 未阻擋到該擋的IP]]></title>
			<link>https://bbs.iredmail.org/post15061.html#p15061</link>
			<description><![CDATA[<div class="quotebox"><cite>ZhangHuangbin 写道:</cite><blockquote><p>dovecot 在非 debug 模式应该不会记录 ldap(xxx): 才对</p></blockquote></div><p>是的, 我今查看dovecot.log 14,15,16&nbsp; 這三天確實沒 ldap 的log 出現 .<br />故可不用啟動此參數 .</p><p>感謝不厭其煩回覆. Thank&#039;s.</p>]]></description>
			<author><![CDATA[null@example.com (rain6966)]]></author>
			<pubDate>Mon, 16 Jan 2017 02:23:58 +0000</pubDate>
			<guid>https://bbs.iredmail.org/post15061.html#p15061</guid>
		</item>
		<item>
			<title><![CDATA[回复: fail2ban 的 dovecot.iredmail.conf 未阻擋到該擋的IP]]></title>
			<link>https://bbs.iredmail.org/post15059.html#p15059</link>
			<description><![CDATA[<p>dovecot 在非 debug 模式应该不会记录 ldap(xxx): 才对，可否使用 logrotate 先将现有 log files 归零，然后再测试一次？</p><p>我刚才尝试用不存在的用户做 imap 和 smtp 验证，均无法得到 ldap(xxx) 这样的 log。</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Sat, 14 Jan 2017 06:58:14 +0000</pubDate>
			<guid>https://bbs.iredmail.org/post15059.html#p15059</guid>
		</item>
		<item>
			<title><![CDATA[回复: fail2ban 的 dovecot.iredmail.conf 未阻擋到該擋的IP]]></title>
			<link>https://bbs.iredmail.org/post15056.html#p15056</link>
			<description><![CDATA[<p>感謝版主回覆.<br /> 我可能未說清楚 .<br />1.<br /># grep &#039;98.158.177.98&#039; /var/log/maillog|wc -l<br />5236<br />我是想說 在 postfix 下的maillog 有出現過幾次 .</p><p>2.<br /># fail2ban-regex -v /var/log/maillog /etc/fail2ban/filter.d/postfix.iredmail.conf</p><p>部分內容可看到有抓到,該擋的IP:</p><p>Results<br />=======<br />Failregex: 3607 total<br />|-&nbsp; #) [# of hits] regular expression<br />|&nbsp; &nbsp;1) [2372] \[&lt;HOST&gt;\]: SASL (PLAIN|LOGIN) authentication failed</p><p>|&nbsp; &nbsp; &nbsp; 45.63.34.194&nbsp; Wed Jan 04 17:41:05 2017<br />|&nbsp; &nbsp; &nbsp; 45.63.34.194&nbsp; Wed Jan 04 17:41:19 2017<br />|&nbsp; &nbsp; &nbsp; 45.63.34.194&nbsp; Wed Jan 04 17:41:38 2017<br />|&nbsp; &nbsp; &nbsp; 45.63.34.194&nbsp; Wed Jan 04 17:41:48 2017<br />|&nbsp; &nbsp; &nbsp; 45.63.34.194&nbsp; Wed Jan 04 17:42:00 2017<br />|&nbsp; &nbsp; &nbsp; 45.63.34.194&nbsp; Wed Jan 04 17:42:15 2017</p><p>|&nbsp; &nbsp; &nbsp; 98.158.177.98&nbsp; Thu Jan 05 20:12:12 2017<br />|&nbsp; &nbsp; &nbsp; 98.158.177.98&nbsp; Thu Jan 05 20:12:22 2017<br />|&nbsp; &nbsp; &nbsp; 98.158.177.98&nbsp; Thu Jan 05 20:12:22 2017<br />|&nbsp; &nbsp; &nbsp; 98.158.177.98&nbsp; Thu Jan 05 20:12:22 2017<br />|&nbsp; &nbsp; &nbsp; 98.158.177.98&nbsp; Thu Jan 05 20:12:35 2017<br />|&nbsp; &nbsp; &nbsp; 98.158.177.98&nbsp; Thu Jan 05 20:12:35 2017<br />|&nbsp; &nbsp; &nbsp; 98.158.177.98&nbsp; Thu Jan 05 20:12:35 2017<br />|&nbsp; &nbsp; &nbsp; 98.158.177.98&nbsp; Thu Jan 05 20:12:50 2017<br />|&nbsp; &nbsp; &nbsp; 98.158.177.98&nbsp; Thu Jan 05 20:12:50 2017<br />|&nbsp; &nbsp; &nbsp; 98.158.177.98&nbsp; Thu Jan 05 20:12:50 2017<br />|&nbsp; &nbsp; &nbsp; 98.158.177.98&nbsp; Thu Jan 05 20:13:09 2017<br />|&nbsp; &nbsp; &nbsp; 98.158.177.98&nbsp; Thu Jan 05 20:13:09 2017</p><p>3. <br />正如版主說的: &quot;如果在非 debug mode 也有这些 log，我们可以添加上去&quot;</p><p>所以我還是安全起見: <br />在 dovecot.iredmail.conf<br />再加入原先修正的條件<br />(pam|passwd-file|ldap)\(\S*,&lt;HOST&gt;(\)|\S*\)): (invalid credentials|unknown user|Login attempt with empty password)\s*$.</p><p>再次感謝版主回覆 ; 此po 文可關掉了.</p><p>PS: 剛再查了一下 ;在關掉 dovecot debug mode 後仍有如下log </p><p>#&nbsp; grep &#039;176.123.1.251&#039; /var/log/dovecot.log</p><p>Jan 13 02:29:04 auth: Info: ldap(mail@mydomain.com,176.123.1.251): unknown user<br />Jan 13 02:29:04 auth: Info: ldap(a@mydomain.com,176.123.1.251): unknown user<br />Jan 13 02:29:04 auth: Info: ldap(mail.mydomain.com@mydomain,176.123.1.251): unknown user<br />13 02:29:04 auth: Info: ldap(mydomain.com@mydomain.com,176.123.1.251): unknown user<br />Jan 13 02:29:04 auth: Info: ldap(mydomain@mysomain.com,176.123.1.251): unknown user</p><p> fail2ban-regex -v /var/log/dovecot.log /etc/fail2ban/filter.d/dov-ired.conf</p><p>|&nbsp; &nbsp; &nbsp; 98.158.177.98&nbsp; Sat Jan 07 00:13:22 2017<br />|&nbsp; &nbsp; &nbsp; 98.158.177.98&nbsp; Sat Jan 07 00:13:40 2017<br />|&nbsp; &nbsp; &nbsp; 176.123.1.251&nbsp; Fri Jan 13 02:29:04 2017<br />|&nbsp; &nbsp; &nbsp; 176.123.1.251&nbsp; Fri Jan 13 02:29:04 2017<br />|&nbsp; &nbsp; &nbsp; 176.123.1.251&nbsp; Fri Jan 13 02:29:04 2017<br />|&nbsp; &nbsp; &nbsp; 176.123.1.251&nbsp; Fri Jan 13 02:29:04 2017<br />|&nbsp; &nbsp; &nbsp; 176.123.1.251&nbsp; Fri Jan 13 02:29:04 2017</p><p>所以應該要啟用此參數. 在 postfix.iredmail.conf 一樣抓得到此IP .</p>]]></description>
			<author><![CDATA[null@example.com (rain6966)]]></author>
			<pubDate>Fri, 13 Jan 2017 02:11:07 +0000</pubDate>
			<guid>https://bbs.iredmail.org/post15056.html#p15056</guid>
		</item>
		<item>
			<title><![CDATA[回复: fail2ban 的 dovecot.iredmail.conf 未阻擋到該擋的IP]]></title>
			<link>https://bbs.iredmail.org/post15052.html#p15052</link>
			<description><![CDATA[<div class="quotebox"><cite>rain6966 写道:</cite><blockquote><p># grep &#039;45.63.34.194&#039; /var/log/maillog|wc -l<br />434<br /># grep &#039;98.158.177.98&#039; /var/log/maillog|wc -l<br />5236</p></blockquote></div><p>用 IP 地址做匹配，无法证明使用的 fail2ban regex 有效啊。<br />如果在非 debug mode 也有这些 log，我们可以添加上去，但只有 debug 模式才有的则不会添加。</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Thu, 12 Jan 2017 08:16:29 +0000</pubDate>
			<guid>https://bbs.iredmail.org/post15052.html#p15052</guid>
		</item>
		<item>
			<title><![CDATA[回复: fail2ban 的 dovecot.iredmail.conf 未阻擋到該擋的IP]]></title>
			<link>https://bbs.iredmail.org/post15051.html#p15051</link>
			<description><![CDATA[<p>在maillog 裡 是可抓到<br /># grep &#039;45.63.34.194&#039; /var/log/maillog|wc -l<br />434<br /># grep &#039;98.158.177.98&#039; /var/log/maillog|wc -l<br />5236</p><p># fail2ban-regex -v /var/log/maillog /etc/fail2ban/filter.d/postfix.iredmail.conf </p><p>Thank&#039;s</p>]]></description>
			<author><![CDATA[null@example.com (rain6966)]]></author>
			<pubDate>Wed, 11 Jan 2017 05:14:30 +0000</pubDate>
			<guid>https://bbs.iredmail.org/post15051.html#p15051</guid>
		</item>
		<item>
			<title><![CDATA[回复: fail2ban 的 dovecot.iredmail.conf 未阻擋到該擋的IP]]></title>
			<link>https://bbs.iredmail.org/post15049.html#p15049</link>
			<description><![CDATA[<p>在正常使用时是不开启 debug mode 的，所以这些日志都不会出现。而 unknown user 这类行为，在非 debug mode 应该有对应的 log，我们应该去抓非 debug mode 时的 log。</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Wed, 11 Jan 2017 01:24:44 +0000</pubDate>
			<guid>https://bbs.iredmail.org/post15049.html#p15049</guid>
		</item>
		<item>
			<title><![CDATA[回复: fail2ban 的 dovecot.iredmail.conf 未阻擋到該擋的IP]]></title>
			<link>https://bbs.iredmail.org/post15048.html#p15048</link>
			<description><![CDATA[<div class="quotebox"><cite>ZhangHuangbin 写道:</cite><blockquote><p>这些日志是否需要在 dovecot 里启用 debug mode？</p></blockquote></div><p>是的:<br /># Debug<br />mail_debug = yes<br />auth_verbose = yes</p>]]></description>
			<author><![CDATA[null@example.com (rain6966)]]></author>
			<pubDate>Wed, 11 Jan 2017 00:51:36 +0000</pubDate>
			<guid>https://bbs.iredmail.org/post15048.html#p15048</guid>
		</item>
		<item>
			<title><![CDATA[回复: fail2ban 的 dovecot.iredmail.conf 未阻擋到該擋的IP]]></title>
			<link>https://bbs.iredmail.org/post15047.html#p15047</link>
			<description><![CDATA[<div class="quotebox"><cite>rain6966 写道:</cite><blockquote><p>Jan 04 17:40:55 auth: Info: ldap(root@mydomain,45.63.34.194): unknown user</p></blockquote></div><p>这些日志是否需要在 dovecot 里启用 debug mode？</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Tue, 10 Jan 2017 11:38:42 +0000</pubDate>
			<guid>https://bbs.iredmail.org/post15047.html#p15047</guid>
		</item>
		<item>
			<title><![CDATA[fail2ban 的 dovecot.iredmail.conf 未阻擋到該擋的IP]]></title>
			<link>https://bbs.iredmail.org/post15045.html#p15045</link>
			<description><![CDATA[<p>==== 必填信息。没有填写将不予回复 ====<br />- iRedMail 版本号：iRedMail 0.9.5-1<br />- 使用哪个数据库存储用户帐号（OpenLDAP，MySQL，PostgreSQL）：OpenLDAP<br />- 使用的 Linux/BSD 发行版名称及版本号：CentOS 7<br />- 与您的问题相关的日志信息：<br />==== <br />#下面log 抓不到IP&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;(dovecot.log檔)</p><p>Jan 04 17:40:55 auth: Info: ldap(root@mydomain,45.63.34.194): unknown user<br />Jan 05 20:07:04 auth: Info: ldap(root@mydomain,98.158.177.98): unknown user<br />Jan 05 20:06:50 auth: Info: ldap(test@mydomain,98.158.177.98): Login attempt with empty password<br />Jan 05 20:08:45 auth: Info: ldap(backup@mydomain,98.158.177.98): unknown user<br />Jan 05 20:08:45 auth: Info: ldap(mail@mydomain,98.158.177.98): unknown user<br />Jan 05 20:08:45 auth: Info: ldap(smtp@mydomain,98.158.177.98): unknown user<br />Jan 05 20:12:25 auth: Info: ldap(postmaster@mydomain,98.158.177.98): Login attempt with empty password<br />Jan 05 20:12:40 auth: Info: ldap(postmaster@mydomain,98.158.177.98): invalid credentials</p><p>grep &#039;45.63.34.194&#039; dovecot.log|wc -l<br />110<br />grep &#039;98.158.177.98&#039; dovecot.log|wc -l<br />1648</p><p>dovecot.iredmail.conf 或預設安裝的 dovecot.conf 皆無法抓到以上兩IP</p><p>現使用dovecot.iredmail.conf&nbsp; <br />最後兩行合併為一行:<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;^%(__prefix_line)s(auth|auth-worker\(\d+\)): (pam|passwd-file)\(\S+,&lt;HOST&gt;\): unknown user\s*$<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ^%(__prefix_line)s(auth|auth-worker\(\d+\)): Info: ldap\(\S*,&lt;HOST&gt;,\S*\): invalid credentials\s*$</p><p>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;#改為<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; (pam|passwd-file|dap)\(\S*,&lt;HOST&gt;(\)|\S*\)): (invalid credentials|unknown user|Login attempt with empty password)\s*$.</p><p>是可抓到;<br />不知版主有何其他看法意見.</p><p>Thanks.</p>]]></description>
			<author><![CDATA[null@example.com (rain6966)]]></author>
			<pubDate>Tue, 10 Jan 2017 04:41:52 +0000</pubDate>
			<guid>https://bbs.iredmail.org/post15045.html#p15045</guid>
		</item>
	</channel>
</rss>
