Fail2ban Postfix aggressive模式无法检测SASL认证失败的配置问题
配置Fail2ban Postfix Aggressive模式同时检测SMTP拒绝与SASL认证失败
问题背景
需要配置Fail2ban保护Postfix服务器,启用aggressive模式,同时基于常规SMTP拒绝行为和SASL认证失败行为封禁恶意主机。现有配置测试后发现SASL认证失败规则无命中,合并规则时还出现「组名重定义」错误。
现有配置
/etc/fail2ban/filter.d/postfix.conf
[INCLUDES] before = common.conf [Definition] _daemon = postfix(-\w+)?/\w+(?:/smtp[ds])? _port = (?::\d+)? _pref = [A-Z]{4} prefregex = ^%(__prefix_line)s<mdpr-<mode>> <F-CONTENT>.+</F-CONTENT>$ exre-user = |[Uu](?:ser unknown|ndeliverable address) mdpr-normal = (?:\w+: (?:milter-)?reject:|(?:improper command pipelining|too many errors) after \S+) mdre-normal=^%(_pref)s from [^[]*\[<HOST>\]%(_port)s: [45][50][04] [45]\.\d\.\d+ (?:(?:<[^>]*>)? : )?(?:(?:Helo command|(?:Sender|Recipient) address) rejected: )?(?:Service unavailable|(?:Client host|Command|Data command) rejected|Relay access denied|(?:Host|Domain) not found|need fully-qualified hostname|match%(exre-user)s)\b ^from [^[]*\[<HOST>\]%(_port)s:? mdpr-auth = warning: mdre-auth = ^[^[]*\[<HOST>\]%(_port)s: SASL ((?i)LOGIN|PLAIN|(?:CRAM|DIGEST)-MD5) authentication failed:(?! Connection lost to authentication server| Invalid authentication mechanism) mdre-auth2= ^[^[]*\[<HOST>\]%(_port)s: SASL ((?i)LOGIN|PLAIN|(?:CRAM|DIGEST)-MD5) authentication failed:(?! Connection lost to authentication server) mdpr-rbl = %(mdpr-normal)s mdre-rbl = ^%(_pref)s from [^[]*\[<HOST>\]%(_port)s: [45]54 [45]\.7\.1 Service unavailable; Client host \[\S+\] blocked\b mdpr-more = %(mdpr-normal)s mdre-more = %(mdre-normal)s mdpr-ddos = (?:lost connection after(?! DATA) [A-Z]+|disconnect(?= from \S+(?: \S+=\d+)* auth=0/(?:[1-9]|\d\d+))|(?:PREGREET \d+|HANGUP) after \S+|COMMAND (?:TIME|COUNT|LENGTH) LIMIT) mdre-ddos = ^from [^[]*\[<HOST>\]%(_port)s:? mdpr-extra = (?:%(mdpr-auth)s|%(mdpr-normal)s) mdre-extra = %(mdre-auth)s %(mdre-normal)s mdpr-aggressive = (?:%(mdpr-auth)s|%(mdpr-normal)s|%(mdpr-ddos)s) mdre-aggressive = %(mdre-auth2)s|%(mdre-normal)s mdpr-errors = too many errors after \S+ mdre-errors = ^from [^[]*\[<HOST>\]%(_port)s$ failregex = <mdre-<mode>> failregex[mode=aggressive] = %(mdre-auth2)s failregex[mode=aggressive] = %(failregex[mode=aggressive])s|%(mdre-normal)s mode = more ignoreregex = [Init] journalmatch = _SYSTEMD_UNIT=postfix.service
/etc/fail2ban/jail.local(相关部分)
[postfix] enabled = true port = smtp,ssmtp,smtps,submission filter = postfix[mode=aggressive] logpath = /var/log/mail.log maxretry = 3 bantime = 48h action = iptables-multiport[name=postfix, port="smtp,ssmtp,smtps,submission", protocol=tcp]
问题现象
fail2ban-regex测试显示仅mdre-normal规则有命中,mdre-auth2的SASL认证失败规则命中数为0。- 直接用
|合并mdre-auth2和mdre-normal定义mdre-aggressive时,触发「组名重定义」错误。 - 切换至
auth/auth2模式未改善SASL规则的命中情况。
解决方案
1. 修正aggressive模式的规则加载逻辑
组名重定义错误是因为合并正则时,多个规则中的<HOST>捕获组重复定义。解决方法是将不同规则拆分为独立的failregex条目,而非用|合并。修改postfix.conf中的failregex[mode=aggressive]部分:
# 替换原有aggressive模式的failregex定义 failregex[mode=aggressive] = %(mdre-auth2)s failregex[mode=aggressive] = %(mdre-normal)s failregex[mode=aggressive] = %(mdre-ddos)s
同时移除mdre-aggressive的合并定义(因为不再需要):
# 删除这一行 # mdre-aggressive = %(mdre-auth2)s|%(mdre-normal)s
2. 验证并调整SASL正则匹配
若SASL规则仍无命中,先单独测试正则是否匹配日志:
fail2ban-regex /var/log/mail.log '%(mdre-auth2)s' --print-all-matched
如果无匹配,检查Postfix日志中SASL失败的实际格式,例如日志行可能是:
Oct 10 12:34:56 server postfix/smtpd[12345]: warning: [192.168.1.100]:54321: SASL LOGIN authentication failed: authentication failure
此时需要微调mdre-auth2正则,确保包含日志前缀:
mdre-auth2= ^%(_pref)s warning: \[<HOST>\]%(_port)s: SASL ((?i)LOGIN|PLAIN|(?:CRAM|DIGEST)-MD5) authentication failed:(?! Connection lost to authentication server)
3. 重启Fail2ban生效
systemctl restart fail2ban
验证
再次运行测试命令确认规则命中情况:
fail2ban-regex /var/log/mail.log /etc/fail2ban/filter.d/postfix.conf --mode=aggressive
内容的提问来源于stack exchange,提问作者klaucode
相关产品推荐
相关产品推荐

