You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

排查存在异常的IPTABLE规则及相关服务器服务故障

Let's work through this step by step—since you're new to Fail2Ban, UFW, and IPTables, we'll keep things clear and actionable. The rule you mentioned (-A INPUT -p tcp -m multiport --dports 22 -j f2b-ss...) is the key here: it's trying to route SSH traffic to a Fail2Ban-managed chain (likely f2b-sshd, truncated in your message), and if that chain doesn't exist, netfilter-persistent will fail to load your rules.

Step 1: Grab Detailed Failure Logs

First, let's get the exact error that's breaking the service. Run this command to pull detailed logs for netfilter-persistent:

sudo journalctl -u netfilter-persistent.service -xe

Look for lines mentioning "failed to load rules" or references to the f2b-ss... chain—this will tell us if the issue is a missing chain, syntax error, or something else.

Step 2: Verify Fail2Ban is Running and the Chain Exists

That f2b-ss... chain is created automatically by Fail2Ban when its SSH jail is active. If Fail2Ban isn't running, the chain won't exist, and netfilter-persistent can't apply the rule.

  1. Check Fail2Ban's current status:
sudo systemctl status fail2ban

If it shows "inactive (dead)", start it immediately:

sudo systemctl start fail2ban
  1. Confirm the Fail2Ban chain exists (replace f2b-sshd with the full chain name from your rule if it's different):
sudo iptables -L f2b-sshd -n

If you get an error like iptables: No chain/target/match by that name, that's the root cause—Fail2Ban hasn't created the required chain.

Step 3: Enable Fail2Ban's SSH Jail

If the chain is missing, check if Fail2Ban's SSH jail is turned on:

  1. Open the main Fail2Ban jail config (or check custom configs in /etc/fail2ban/jail.d/ if you have them):
sudo nano /etc/fail2ban/jail.conf
  1. Scroll to the [sshd] section and make sure enabled = true (if it's set to false, update it and save the file with Ctrl+O then Ctrl+X).

  2. Restart Fail2Ban to apply the change:

sudo systemctl restart fail2ban

Re-run the iptables -L f2b-sshd -n command to confirm the chain now exists.

Step 4: Fix the Rule (If Needed)

If the chain exists but you still get errors, double-check the rule's syntax:

  • Your rule uses multiport --dports 22—while this works, it's redundant for a single port. You could simplify it to:
-A INPUT -p tcp --dport 22 -j f2b-sshd

This isn't mandatory, but it cleans up the rule and eliminates any edge cases with the multiport module.

Step 5: Test netfilter-persistent Again

Once the chain is confirmed to exist, try starting the service again:

sudo systemctl start netfilter-persistent

Check its status to confirm it's running successfully:

sudo systemctl status netfilter-persistent

A quick note: netfilter-persistent loads rules from /etc/iptables/rules.v4 (for IPv4) by default. If you added that rule manually, make sure it's applied after Fail2Ban starts (or adjust service dependencies to ensure Fail2Ban launches before netfilter-persistent).

内容的提问来源于stack exchange,提问作者inspirednz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:33:54