• Inviting everyone who uses WordPress management tools in Plesk
    The Plesk team is conducting a 60-minute research session that includes an interview and a moderated usability test.
    To participate, please use this link .
    Your experience will help shape product decisions and ensure the tools better support real-world use cases.

Issue LogBrowser, Fail2ban and SASL filter

OverWolf

Regular Pleskian
Server operating system version
Almalinux 9.7
Plesk version and microupdate number
18.0.74 Update #3
Good morning,
I've read a lot about 'problems' with Fail2ban sals filter, and the "solution" was to use postfix[mode=auth], but in my case it doesn't work.
After a little troubleshooting, I have found this inconsistency beetween what is showed on LoBbrowser and what I found on maillog:

LogBrowser
warning: cm-72-241-202-104.buckeyecom.net[72.241.202.104]: SASL CRAM-MD5 authentication failed: authentication failure, sasl_username=xxxx

maillog
postfix/smtpd[53528]: warning: SASL authentication failure: incorrect digest response

As you can see, on maillog isn't present the same syntax and even less the IP (HOST), so the sasl filter (old or new with postfix mode) cannot catch the entry.

Now, I ask to you, is there the possibility to catch this IP and block it ?Where I can find the LogBrowser entry so I can configure Fail2ban filter to look at that log ? Should I must set a different journalmatch ?

Thank you for your support.
 
Back
Top