You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Fail2Ban无法统计Samba登录失败次数,无法封禁恶意IP的问题排查求助

Fail2Ban无法统计Samba登录失败次数,无法封禁恶意IP的问题排查求助

大家好,我最近在配置Fail2Ban和Samba时遇到了个头疼的问题:Fail2Ban服务能正常启动,Samba的认证日志里明明能看到错误登录的记录,但Fail2Ban就是统计不到这些失败尝试,更别提封禁恶意IP了。我怀疑是正则表达式的问题,但试了好几个不同来源的正则,要么服务直接启动失败,要么就是像现在这样,服务能起来但完全不干活。实在没办法了,来求助各位大佬!

先给大家贴一下当前的状态和配置:

1. Fail2Ban状态查询结果

运行 fail2ban-client status samba 输出如下:

fail2ban-client status samba

|- Filter

|  |- Currently failed: 0

|  |- Total failed:     0

|  `- File list:        /var/log/samba/auth_json_audit.log

`- Actions

|- Currently banned: 0

|- Total banned:     0

`- Banned IP list:

2. Samba认证日志内容

/var/log/samba/auth_json_audit.log 里的错误登录记录(JSON格式):

{"timestamp": "2023-09-29T04:25:46.305161-0400", "type": "Authentication", "Authentication": {"version": {"major": 1, "minor": 2}, "eventId": 4625, "logonId": "0", "logonType": 3, "status": "NT_STATUS_NO_SUCH_USER", "localAddress": "ipv4:192.168.2.238:445", "remoteAddress": "ipv4:192.168.2.196:21997", "serviceDescription": "SMB2", "authDescription": null, "clientDomain": ".", "clientAccount": "wronguser", "workstation": "HOME", "becameAccount": null, "becameDomain": null, "becameSid": null, "mappedAccount": "wronguser", "mappedDomain": ".", "netlogonComputer": null, "netlogonTrustAccount": null, "netlogonNegotiateFlags": "0x00000000", "netlogonSecureChannelType": 0, "netlogonTrustAccountSid": null, "passwordType": "NTLMv2", "duration": 2776}}

3. Fail2Ban Jail配置(/etc/fail2ban/jail.d/samba.conf)

[samba]

enabled = true

port = 88,135,139,389,445,464,636,3328,3329

filter = samba

logpath = /var/log/samba/auth_json_audit.log

maxretry = 5

findtime = 600

bantime = 600

4. 当前使用的Filter正则(/etc/fail2ban/filter.d/samba.conf)

我试了两个正则,都没法统计失败次数:

[Definition]

# 第一个正则,试了不行
#failregex = NT_STATUS_WRONG_PASSWORD.*remoteAddress": "ipv4:<HOST>:<PORT>"

# 第二个正则,同样不行
failregex = NT_STATUS_NO_SUCH_USER.*remoteAddress": "ipv4:<HOST>:<PORT>"

5. Samba全局配置(/etc/samba/smb.conf)相关部分

[global]

workgroup = WORKGROUP

server string = Samba Server %v

netbios name = rocky-8

security = user

map to guest = bad user

dns proxy = no

ntlm auth = true

encrypt passwords = yes

guest account = nobody

socket options = TCP_NODELAY IPTOS_LOWDELAY

#log file = /var/log/samba/log.%m

max log size = 1000

#hosts allow = 192.168.1. 127.

#hosts deny = ALL

log level = auth_json_audit:3@/var/log/samba/auth_json_audit.log

我猜核心问题还是正则匹配不上,但实在搞不懂哪里错了。另外我也试了其他文章里的正则,结果Fail2Ban直接启动失败,只有上面这两个正则能让服务起来,但就是不统计。有没有大佬能帮我看看这个正则该怎么写,或者有没有其他可能的问题点?

备注:内容来源于stack exchange,提问作者Ivan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.21 12:39:37