Topic: Sasl authentication failures to fail2ban
==== REQUIRED BASIC INFO OF YOUR IREDMAIL SERVER ====
- iRedMail version (check /etc/iredmail-release): 1.6.1
- Deployed with iRedMail Easy or the downloadable installer? installer
- Linux/BSD distribution name and version: Debian 11.6
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MySQL
- Web server (Apache or Nginx): Nginx
- Manage mail accounts with iRedAdmin-Pro? No
- [IMPORTANT] Related original log or error message is required if you're experiencing an issue.
====
I have plenty of sasl auth failures from many ips;
Feb 10 12:47:37 mail postfix/submission/smtpd[2922253]: warning: unknown[192.72.5.192]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Feb 10 12:50:46 mail postfix/submission/smtpd[2922375]: warning: unknown[5.101.129.104]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Feb 10 12:51:34 mail postfix/submission/smtpd[2922375]: warning: unknown[45.119.30.213]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Feb 10 12:52:46 mail postfix/submission/smtpd[2922375]: warning: unknown[122.165.141.16]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Feb 10 12:53:13 mail postfix/submission/smtpd[2922375]: warning: unknown[177.135.223.185]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Feb 10 13:01:36 mail postfix/submission/smtpd[2922648]: warning: unknown[185.41.110.40]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Feb 10 13:01:57 mail postfix/submission/smtpd[2922648]: warning: unknown[122.170.5.197]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Feb 10 13:02:17 mail postfix/submission/smtpd[2922648]: warning: unknown[45.14.165.137]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Feb 10 13:03:37 mail postfix/submission/smtpd[2922648]: warning: unknown[141.98.11.144]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Feb 10 13:05:46 mail postfix/submission/smtpd[2922648]: warning: unknown[58.216.101.162]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
I have no user like that and I would like to block that ips. Is this possilbe with fail2ban?
fail2ban works for postfix:
Status for the jail: postfix
|- Filter
| |- Currently failed: 51
| |- Total failed: 441132
| `- File list: /var/log/mail.log
`- Actions
|- Currently banned: 1
|- Total banned: 1382
`- Banned IP list: 46.41.134.164
Do I have to do anything else or it's just immpossible to block such of actions?
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.