Fail2Ban无法统计Samba登录失败次数,无法封禁恶意IP的问题排查求助
Fail2Ban无法统计Samba登录失败次数,无法封禁恶意IP的问题排查求助
大家好,我最近在配置Fail2Ban和Samba时遇到了个头疼的问题:Fail2Ban服务能正常启动,Samba的认证日志里明明能看到错误登录的记录,但Fail2Ban就是统计不到这些失败尝试,更别提封禁恶意IP了。我怀疑是正则表达式的问题,但试了好几个不同来源的正则,要么服务直接启动失败,要么就是像现在这样,服务能起来但完全不干活。实在没办法了,来求助各位大佬!
先给大家贴一下当前的状态和配置:
1. Fail2Ban状态查询结果
运行 fail2ban-client status samba 输出如下:
fail2ban-client status samba |- Filter | |- Currently failed: 0 | |- Total failed: 0 | `- File list: /var/log/samba/auth_json_audit.log `- Actions |- Currently banned: 0 |- Total banned: 0 `- Banned IP list:
2. Samba认证日志内容
/var/log/samba/auth_json_audit.log 里的错误登录记录(JSON格式):
{"timestamp": "2023-09-29T04:25:46.305161-0400", "type": "Authentication", "Authentication": {"version": {"major": 1, "minor": 2}, "eventId": 4625, "logonId": "0", "logonType": 3, "status": "NT_STATUS_NO_SUCH_USER", "localAddress": "ipv4:192.168.2.238:445", "remoteAddress": "ipv4:192.168.2.196:21997", "serviceDescription": "SMB2", "authDescription": null, "clientDomain": ".", "clientAccount": "wronguser", "workstation": "HOME", "becameAccount": null, "becameDomain": null, "becameSid": null, "mappedAccount": "wronguser", "mappedDomain": ".", "netlogonComputer": null, "netlogonTrustAccount": null, "netlogonNegotiateFlags": "0x00000000", "netlogonSecureChannelType": 0, "netlogonTrustAccountSid": null, "passwordType": "NTLMv2", "duration": 2776}}
3. Fail2Ban Jail配置(/etc/fail2ban/jail.d/samba.conf)
[samba] enabled = true port = 88,135,139,389,445,464,636,3328,3329 filter = samba logpath = /var/log/samba/auth_json_audit.log maxretry = 5 findtime = 600 bantime = 600
4. 当前使用的Filter正则(/etc/fail2ban/filter.d/samba.conf)
我试了两个正则,都没法统计失败次数:
[Definition] # 第一个正则,试了不行 #failregex = NT_STATUS_WRONG_PASSWORD.*remoteAddress": "ipv4:<HOST>:<PORT>" # 第二个正则,同样不行 failregex = NT_STATUS_NO_SUCH_USER.*remoteAddress": "ipv4:<HOST>:<PORT>"
5. Samba全局配置(/etc/samba/smb.conf)相关部分
[global] workgroup = WORKGROUP server string = Samba Server %v netbios name = rocky-8 security = user map to guest = bad user dns proxy = no ntlm auth = true encrypt passwords = yes guest account = nobody socket options = TCP_NODELAY IPTOS_LOWDELAY #log file = /var/log/samba/log.%m max log size = 1000 #hosts allow = 192.168.1. 127. #hosts deny = ALL log level = auth_json_audit:3@/var/log/samba/auth_json_audit.log
我猜核心问题还是正则匹配不上,但实在搞不懂哪里错了。另外我也试了其他文章里的正则,结果Fail2Ban直接启动失败,只有上面这两个正则能让服务起来,但就是不统计。有没有大佬能帮我看看这个正则该怎么写,或者有没有其他可能的问题点?
备注:内容来源于stack exchange,提问作者Ivan
相关产品推荐
相关产品推荐

