排查存在异常的IPTABLE规则及相关服务器服务故障
Let's work through this step by step—since you're new to Fail2Ban, UFW, and IPTables, we'll keep things clear and actionable. The rule you mentioned (-A INPUT -p tcp -m multiport --dports 22 -j f2b-ss...) is the key here: it's trying to route SSH traffic to a Fail2Ban-managed chain (likely f2b-sshd, truncated in your message), and if that chain doesn't exist, netfilter-persistent will fail to load your rules.
Step 1: Grab Detailed Failure Logs
First, let's get the exact error that's breaking the service. Run this command to pull detailed logs for netfilter-persistent:
sudo journalctl -u netfilter-persistent.service -xe
Look for lines mentioning "failed to load rules" or references to the f2b-ss... chain—this will tell us if the issue is a missing chain, syntax error, or something else.
Step 2: Verify Fail2Ban is Running and the Chain Exists
That f2b-ss... chain is created automatically by Fail2Ban when its SSH jail is active. If Fail2Ban isn't running, the chain won't exist, and netfilter-persistent can't apply the rule.
- Check Fail2Ban's current status:
sudo systemctl status fail2ban
If it shows "inactive (dead)", start it immediately:
sudo systemctl start fail2ban
- Confirm the Fail2Ban chain exists (replace
f2b-sshdwith the full chain name from your rule if it's different):
sudo iptables -L f2b-sshd -n
If you get an error like iptables: No chain/target/match by that name, that's the root cause—Fail2Ban hasn't created the required chain.
Step 3: Enable Fail2Ban's SSH Jail
If the chain is missing, check if Fail2Ban's SSH jail is turned on:
- Open the main Fail2Ban jail config (or check custom configs in
/etc/fail2ban/jail.d/if you have them):
sudo nano /etc/fail2ban/jail.conf
Scroll to the
[sshd]section and make sureenabled = true(if it's set tofalse, update it and save the file withCtrl+OthenCtrl+X).Restart Fail2Ban to apply the change:
sudo systemctl restart fail2ban
Re-run the iptables -L f2b-sshd -n command to confirm the chain now exists.
Step 4: Fix the Rule (If Needed)
If the chain exists but you still get errors, double-check the rule's syntax:
- Your rule uses
multiport --dports 22—while this works, it's redundant for a single port. You could simplify it to:
-A INPUT -p tcp --dport 22 -j f2b-sshd
This isn't mandatory, but it cleans up the rule and eliminates any edge cases with the multiport module.
Step 5: Test netfilter-persistent Again
Once the chain is confirmed to exist, try starting the service again:
sudo systemctl start netfilter-persistent
Check its status to confirm it's running successfully:
sudo systemctl status netfilter-persistent
A quick note: netfilter-persistent loads rules from /etc/iptables/rules.v4 (for IPv4) by default. If you added that rule manually, make sure it's applied after Fail2Ban starts (or adjust service dependencies to ensure Fail2Ban launches before netfilter-persistent).
内容的提问来源于stack exchange,提问作者inspirednz

