You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Fedora 37下Fail2ban结合ipset配置失败及后续疑问求助

Fedora 37下Fail2ban结合ipset配置失败及后续疑问求助

我听说用ipset搭配Fail2ban运行速度会更快,所以特意按照适配Fedora 37的说明,从Git上下载安装了ritsu/ipset-fail2ban。

之前我的banaction配置是这样的:

banaction_allports = firewallcmd-rich-rules[actiontype=]

当我尝试把它替换成下面的配置后,就开始报错了:

banaction = firewallcmd-ipset

具体报错日志

2023-04-09 15:51:46,130 fail2ban.actions        [986]: NOTICE  [postfix-auth] Restore Ban 117.69.159.181

2023-04-09 15:51:46,526 fail2ban.utils          [986]: ERROR   7f29c6bd0ea0 -- exec: ipset -exist create f2b-postfix-unv hash:ip timeout 0

firewall-cmd --direct --add-rule ipv4 filter INPUT_direct 0 -p tcp -m multiport --dports smtp,imap2,imap3,imaps,pop3,pop3s,465,587, submission -m set --match-set f2b-postfix-unv src -j REJECT --reject-with icmp-port-unreachable

2023-04-09 15:51:46,527 fail2ban.utils          [986]: ERROR   7f29c6bd0ea0 -- stderr: "Error: COMMAND_FAILED: '/usr/sbin/iptables-restore -w -n' failed: iptables-restore v1.8.8 (legacy): invalid port/service `' specified"

2023-04-09 15:51:46,527 fail2ban.utils          [986]: ERROR   7f29c6bd0ea0 -- stderr: 'Error occurred at line: 2'

2023-04-09 15:51:46,527 fail2ban.utils          [986]: ERROR   7f29c6bd0ea0 -- stderr: "Try `iptables-restore -h' or 'iptables-restore --help' for more information."

2023-04-09 15:51:46,527 fail2ban.utils          [986]: ERROR   7f29c6bd0ea0 -- stderr: ''

2023-04-09 15:51:46,527 fail2ban.utils          [986]: ERROR   7f29c6bd0ea0 -- returned 13

当前防火墙与iptables状态

  • 执行firewall-cmd --list-all-zones能看到已经被封禁的IP,但这些IP并没有出现在/etc/firewalld/zones目录下的任何zone文件里
  • 执行iptables -L得到的输出如下:
Chain INPUT (policy ACCEPT)
target     prot opt source               destination
DROP       all  --  anywhere             anywhere             match-set blacklist-fail2ban src

Chain FORWARD (policy ACCEPT)
target     prot opt source               destination

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination
DROP       tcp  --  anywhere             185.191.32.198       tcp dpt:http

想请教下各位,我到底哪里配置错了?


补充信息1

针对Ginnungagap提到的端口列表末尾逗号的疑问,我贴出自己jail.local里对应段的配置:

[postfix-unv]
enabled = true
filter = postfix-unv
port = smtp,imap2,imap3,imaps,pop3,pop3s,465,587, submission
logpath = /var/log/maillog
maxretry = 1
bantime = 604800

我检查了一遍,确实没有多余的逗号,实际过滤器里也没有。另外我也开始了解nftables相关的内容了。

补充信息2

按照建议修改banaction后,执行nft list ruleset看起来配置已经生效了。我重启了firewalld,没有看到新增的rich规则;重启fail2ban后,大概一分钟左右就加载完了所有封禁规则。

现在还有个小疑问:我之前从Git下载的那些ipset-fail2ban相关文件,现在还需要保留吗?

再次感谢Ginnungagap的帮助!

备注:内容来源于stack exchange,提问作者WSpivak

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.22 14:50:32