Topic: NetData and Fail2Ban / PostFix Settings
==== REQUIRED BASIC INFO OF YOUR IREDMAIL SERVER ====
- iRedMail version: 1.2.1
- Deployed with: downloadable installer
- Linux/BSD distribution: Debian 10.4
- Store mail accounts in: LDAP
- Web server: Nginx
- Manage mail accounts with: iRedAdmin
====
So I’m noticing something on NetData. I see fail2ban is enabled, but I don’t see it showing a correlation with what Fail2Ban is actually doing.
See attachment, that NetData is showing NO JAILS or BANS.
But look at the output of Fail2Ban:
# fail2ban-client status | grep "Jail list:" | sed "s/ //g" | awk '{split($2,a,",");for(i in a) system("fail2ban-client status " a[i])}' | grep "Status\|IP list"
Status for the jail: dovecot-iredmail
`- Banned IP list:
Status for the jail: nginx-http-auth
`- Banned IP list:
Status for the jail: postfix-iredmail
`- Banned IP list:
Status for the jail: postfix-pregreet-iredmail
`- Banned IP list:
Status for the jail: roundcube-iredmail
`- Banned IP list:
Status for the jail: sogo-iredmail
`- Banned IP list:
Status for the jail: sshd
`- Banned IP list: 112.85.42.185 93.157.62.102
Also seeing similar for PostFix.
Do I need to make some Config Adjustments in NetData to make it see these entries?
I caught it, because I see the Logwatch report email, and saw many failed SSHD attempts.
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.