You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Fail2ban Postfix aggressive模式无法检测SASL认证失败的配置问题

配置Fail2ban Postfix Aggressive模式同时检测SMTP拒绝与SASL认证失败

问题背景

需要配置Fail2ban保护Postfix服务器,启用aggressive模式,同时基于常规SMTP拒绝行为和SASL认证失败行为封禁恶意主机。现有配置测试后发现SASL认证失败规则无命中,合并规则时还出现「组名重定义」错误。

现有配置

/etc/fail2ban/filter.d/postfix.conf

[INCLUDES]
before = common.conf

[Definition]
_daemon = postfix(-\w+)?/\w+(?:/smtp[ds])?
_port = (?::\d+)?
_pref = [A-Z]{4}
prefregex = ^%(__prefix_line)s<mdpr-<mode>> <F-CONTENT>.+</F-CONTENT>$
exre-user = |[Uu](?:ser unknown|ndeliverable address)
mdpr-normal = (?:\w+: (?:milter-)?reject:|(?:improper command pipelining|too many errors) after \S+)
mdre-normal=^%(_pref)s from [^[]*\[<HOST>\]%(_port)s: [45][50][04] [45]\.\d\.\d+ (?:(?:<[^>]*>)? : )?(?:(?:Helo command|(?:Sender|Recipient) address) rejected: )?(?:Service unavailable|(?:Client host|Command|Data command) rejected|Relay access denied|(?:Host|Domain) not found|need fully-qualified hostname|match%(exre-user)s)\b
^from [^[]*\[<HOST>\]%(_port)s:?
mdpr-auth = warning:
mdre-auth = ^[^[]*\[<HOST>\]%(_port)s: SASL ((?i)LOGIN|PLAIN|(?:CRAM|DIGEST)-MD5) authentication failed:(?! Connection lost to authentication server| Invalid authentication mechanism)
mdre-auth2= ^[^[]*\[<HOST>\]%(_port)s: SASL ((?i)LOGIN|PLAIN|(?:CRAM|DIGEST)-MD5) authentication failed:(?! Connection lost to authentication server)
mdpr-rbl = %(mdpr-normal)s
mdre-rbl  = ^%(_pref)s from [^[]*\[<HOST>\]%(_port)s: [45]54 [45]\.7\.1 Service unavailable; Client host \[\S+\] blocked\b
mdpr-more = %(mdpr-normal)s
mdre-more = %(mdre-normal)s
mdpr-ddos = (?:lost connection after(?! DATA) [A-Z]+|disconnect(?= from \S+(?: \S+=\d+)* auth=0/(?:[1-9]|\d\d+))|(?:PREGREET \d+|HANGUP) after \S+|COMMAND (?:TIME|COUNT|LENGTH) LIMIT)
mdre-ddos = ^from [^[]*\[<HOST>\]%(_port)s:?
mdpr-extra = (?:%(mdpr-auth)s|%(mdpr-normal)s)
mdre-extra = %(mdre-auth)s
%(mdre-normal)s
mdpr-aggressive = (?:%(mdpr-auth)s|%(mdpr-normal)s|%(mdpr-ddos)s)
mdre-aggressive = %(mdre-auth2)s|%(mdre-normal)s
mdpr-errors = too many errors after \S+
mdre-errors = ^from [^[]*\[<HOST>\]%(_port)s$
failregex = <mdre-<mode>>
failregex[mode=aggressive] = %(mdre-auth2)s
failregex[mode=aggressive] = %(failregex[mode=aggressive])s|%(mdre-normal)s
mode = more
ignoreregex =
[Init]
journalmatch = _SYSTEMD_UNIT=postfix.service

/etc/fail2ban/jail.local(相关部分)

[postfix]
enabled = true
port = smtp,ssmtp,smtps,submission
filter = postfix[mode=aggressive]
logpath = /var/log/mail.log
maxretry = 3
bantime   = 48h
action = iptables-multiport[name=postfix, port="smtp,ssmtp,smtps,submission", protocol=tcp]

问题现象

  • fail2ban-regex测试显示仅mdre-normal规则有命中,mdre-auth2的SASL认证失败规则命中数为0。
  • 直接用|合并mdre-auth2和mdre-normal定义mdre-aggressive时,触发「组名重定义」错误。
  • 切换至auth/auth2模式未改善SASL规则的命中情况。

解决方案

1. 修正aggressive模式的规则加载逻辑

组名重定义错误是因为合并正则时,多个规则中的<HOST>捕获组重复定义。解决方法是将不同规则拆分为独立的failregex条目,而非用|合并。修改postfix.conf中的failregex[mode=aggressive]部分:

# 替换原有aggressive模式的failregex定义
failregex[mode=aggressive] = %(mdre-auth2)s
failregex[mode=aggressive] = %(mdre-normal)s
failregex[mode=aggressive] = %(mdre-ddos)s

同时移除mdre-aggressive的合并定义(因为不再需要):

# 删除这一行
# mdre-aggressive = %(mdre-auth2)s|%(mdre-normal)s

2. 验证并调整SASL正则匹配

若SASL规则仍无命中,先单独测试正则是否匹配日志:

fail2ban-regex /var/log/mail.log '%(mdre-auth2)s' --print-all-matched

如果无匹配,检查Postfix日志中SASL失败的实际格式,例如日志行可能是:

Oct 10 12:34:56 server postfix/smtpd[12345]: warning: [192.168.1.100]:54321: SASL LOGIN authentication failed: authentication failure

此时需要微调mdre-auth2正则,确保包含日志前缀:

mdre-auth2= ^%(_pref)s warning: \[<HOST>\]%(_port)s: SASL ((?i)LOGIN|PLAIN|(?:CRAM|DIGEST)-MD5) authentication failed:(?! Connection lost to authentication server)

3. 重启Fail2ban生效

systemctl restart fail2ban

验证

再次运行测试命令确认规则命中情况:

fail2ban-regex /var/log/mail.log /etc/fail2ban/filter.d/postfix.conf --mode=aggressive

内容的提问来源于stack exchange,提问作者klaucode

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 15:07:09