You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何阻止Fail2ban封禁访问Plex服务器的外部IP?

问题

我用Fail2ban搭配NGINX Proxy Manager(NPM)搭建了环境,把Plex通过反向代理暴露到公网,没开Fail2ban时一切正常,但启用后外部IP访问Plex会立刻被封禁。查看代理主机访问日志发现有连续401错误,这些错误匹配了Fail2ban filter.d里的正则规则。

当前Filter配置

[INCLUDES]

[Definition]

failregex = ^.* (405|404|403|401|\-) (405|404|403|401) - .* \[Client <HOST>\] \[Length .*\] .* \[Sent-to <F-CONTAINER>.*</F-CONTAINER>\] <F-USERAGENT>".*"</F-USERAGENT> .*$
ignoreregex = ^.* (404|\-) (404) - .*".*(\.png|\.txt|\.jpg|\.ico|\.js|\.css)(/)*?" \[Client <HOST>\] \[Length .*\] ".*" .*$

当前Jail配置

[npm-docker]
enabled = true
ignoreip = 127.0.0.1/8 10.10.10.0/24 10.10.0.0/24
action = cloudflare-apiv4
         %(action_mwl)s
chain = INPUT
logpath = /log/npm/default-host_access.log
          /log/npm/proxy-host-*_access.log
          /log/npm/proxy-host-*_error.log
maxretry = 4
bantime  = -1
findtime = 86400
destemail = <My email address>
sender = fail2ban@notification
sendername = fail2ban

相关日志片段

[09/Jun/2023:19:24:58 -0700] - 200 200 - GET https <redacted url> "/?X-Plex-Language=en-US&X-Plex-Device-Name=iPhone" [Client <redacted ipv6>] [Length 4266] [Gzip -] [Sent-to 10.10.10.4] "PlexMobile/8.20 (iPhone; iOS 16.5; Scale/3.00)" "-"
[09/Jun/2023:19:24:58 -0700] - 401 401 - GET https <redacted url> "/media/subscriptions/scheduled?X-Plex-Language=en-US&X-Plex-Device-Name=iPhone" [Client <redacted ipv6>] [Length 82] [Gzip -] [Sent-to 10.10.10.4] "PlexMobile/8.20 (iPhone; iOS 16.5; Scale/3.00)" "-"
[09/Jun/2023:19:24:58 -0700] - 200 200 - GET https <redacted url> "/media/providers" [Client <redacted ipv6>] [Length 4849] [Gzip -] [Sent-to 10.10.10.4] "PlexMediaServer/1.29.0.6244-819d3678c" "-"
[09/Jun/2023:19:24:58 -0700] - 200 200 - GET https <redacted url> "/media/providers?includePreferences=1&X-Plex-Language=en-US&X-Plex-Device-Name=iPhone" [Client <redacted ipv6>] [Length 8849] [Gzip -] [Sent-to 10.10.10.4] "PlexMobile/8.20 (iPhone; iOS 16.5; Scale/3.00)" "-"
[09/Jun/2023:19:24:58 -0700] - 401 401 - GET https <redacted url> "/activities?X-Plex-Language=en-US&X-Plex-Device-Name=iPhone" [Client <redacted ipv6>] [Length 82] [Gzip -] [Sent-to 10.10.10.4] "PlexMobile/8.20 (iPhone; iOS 16.5; Scale/3.00)" "-"
[09/Jun/2023:19:24:58 -0700] - 401 401 - GET https <redacted url> "/media/subscriptions?includeGrabs=1&X-Plex-Language=en-US&X-Plex-Device-Name=iPhone" [Client <redacted ipv6>] [Length 82] [Gzip -] [Sent-to 10.10.10.4] "PlexMobile/8.20 (iPhone; iOS 16.5; Scale/3.00)" "-"
[09/Jun/2023:19:24:58 -0700] - 200 200 - GET https <redacted url> "/clients?X-Plex-Language=en-US&X-Plex-Device-Name=iPhone" [Client <redacted ipv6>] [Length 90] [Gzip -] [Sent-to 10.10.10.4] "PlexMobile/8.20 (iPhone; iOS 16.5; Scale/3.00)" "-"
[09/Jun/2023:19:24:58 -0700] - 401 401 - GET https <redacted url> "/activities?X-Plex-Language=en-US&X-Plex-Device-Name=iPhone" [Client <redacted ipv6>] [Length 82] [Gzip -] [Sent-to 10.10.10.4] "PlexMobile/8.20 (iPhone; iOS 16.5; Scale/3.00)" "-"
[09/Jun/2023:19:24:58 -0700] - 200 200 - GET https <redacted url> "/media/providers?includePreferences=1&X-Plex-Language=en-US&X-Plex-Device-Name=iPhone" [Client <redacted ipv6>] [Length 8849] [Gzip -] [Sent-to 10.10.10.4] "PlexMobile/8.20 (iPhone; iOS 16.5; Scale/3.00)" "-"

这些401错误不影响实际认证和访问,想知道是修改Fail2ban过滤器忽略这些条目,还是修改NPM配置更合适?如果是后者,具体怎么操作?


解决方案

方案一:修改Fail2ban过滤器(推荐)

直接在ignoreregex中添加规则,忽略来自Plex客户端的401请求。

修改Filter配置中的ignoreregex部分,追加匹配Plex客户端User-Agent的规则:

ignoreregex = ^.* (404|\-) (404) - .*".*(\.png|\.txt|\.jpg|\.ico|\.js|\.css)(/)*?" \[Client <HOST>\] \[Length .*\] ".*" .*$
              ^.* 401 401 - .* ".*Plex.*" \[Client <HOST>\] .*$

如果需要更精准匹配,可以分开写:

ignoreregex = ^.* (404|\-) (404) - .*".*(\.png|\.txt|\.jpg|\.ico|\.js|\.css)(/)*?" \[Client <HOST>\] \[Length .*\] ".*" .*$
              ^.* 401 401 - .* "PlexMobile/.*" \[Client <HOST>\] .*$
              ^.* 401 401 - .* "PlexMediaServer/.*" \[Client <HOST>\] .*$

修改完成后,重启Fail2ban生效:

sudo systemctl restart fail2ban

方案二:修改NGINX Proxy Manager配置

如果不想调整Fail2ban规则,可以在NPM的Plex代理配置中添加自定义NGINX规则,让NPM不记录这些Plex客户端的401请求到日志中,避免被Fail2ban捕获。

  1. 打开NPM面板,找到你的Plex代理主机,进入自定义配置标签页
  2. 添加以下配置(替换<你的Plex代理ID>为实际代理ID,可在代理列表URL中查看,如proxy-host/123中的123):
map $http_user_agent $plex_ignore {
    default 0;
    ~*Plex 1;
}

access_log /log/npm/proxy-host-<你的Plex代理ID>_access.log combined if=$plex_ignore=0;

该配置会让NPM仅记录非Plex客户端的请求日志,Plex客户端的401请求不会被写入日志,自然不会触发Fail2ban的封禁规则。


内容的提问来源于stack exchange,提问作者David Glass

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 08:57:24