Open Andsup opened 6 months ago
Hi @Andsup ,
Are you facing this issue on the newly installed system (using the latest installation script )? if not build the new system using the latest installation script and check.
On the Newly installation system, fail2ban is working and is not able to reproduce the issue.
root@uc-42126347:~# fail2ban-client version 1.0.2 root@uc-42126347:~# iptables -V iptables v1.8.9 (nf_tables) root@uc-42126347:~# iptables -L INPUT Chain INPUT (policy ACCEPT) target prot opt source destination fail2ban-SIP all -- anywhere anywhere fail2ban-FTP tcp -- anywhere anywhere multiport dports ftp fail2ban-BadBots tcp -- anywhere anywhere multiport dports http,https fail2ban-api tcp -- anywhere anywhere multiport dports http,https fail2ban-openvpn udp -- anywhere anywhere multiport dports openvpn fail2ban-recidive all -- anywhere anywhere fail2ban-PBX-GUI all -- anywhere anywhere fail2ban-SSH tcp -- anywhere anywhere multiport dports ssh fail2ban-apache-auth all -- anywhere anywhere fail2ban-sng-deskapp tcp -- anywhere anywhere fpbxfirewall all -- anywhere anywhere root@uc-42126347:~# fwconsole ma list | grep firewall | firewall | 17.0.1.17 | Enabled | AGPLv3+ | Sangoma |
yes full new installation with the latest script.
iptables -V ==> iptables v1.8.9 (nf_tables)
fwconsole ma list | grep firewall | firewall | 17.0.1.18 | Enabled | AGPLv3+ | Sangoma |
NB: direct iptables commands on ssh session are working fine.
iptables -L INPUT
Chain INPUT (policy ACCEPT)
target prot opt source destination
fail2ban-apache-auth all -- anywhere anywhere
fail2ban-recidive all -- anywhere anywhere
fail2ban-openvpn udp -- anywhere anywhere multiport dports openvpn
fail2ban-api tcp -- anywhere anywhere multiport dports http,https
fail2ban-BadBots tcp -- anywhere anywhere multiport dports http,https
fail2ban-FTP tcp -- anywhere anywhere multiport dports ftp
fail2ban-SSH tcp -- anywhere anywhere multiport dports ssh
fail2ban-PBX-GUI all -- anywhere anywhere
fail2ban-SIP all -- anywhere anywhere
fail2ban-sshd tcp -- anywhere anywhere multiport dports ssh
How can I help you ?
I forced a fail2ban reinstallation. To be confirmed but since then no erreur any more.
I had also to modify logrotate config to avoid the compress option for fail2ban log.
Could be close.
Thanks for your support on this topic.
Hi,
Again errors :
Command ['get', 'ignoreip'] has failed. Received IndexError('list index out...: 279 Time(s) Command ['set', 'addignoreip', '127.0.0.1'] has failed. Received Exception(...: 279 Time(s) Command ['set', 'addignoreip', '127.0.1.1'] has failed. Received Exception(...: 279 Time(s) Command ['set', 'addignoreip', '192.168.5.55'] has failed. Received Excepti...: 279 Time(s)
... 2024-05-26 15:50:10,501 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', 'xxxxxxxx'] has failed. Received Exception("Invalid command '57.129.5.195' (no set action or not yet implemented)") 2024-05-26 15:50:10,558 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', '127.0.1.1'] has failed. Received Exception("Invalid command '127.0.1.1' (no set action or not yet implemented)") 2024-05-26 15:50:10,622 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', '192.168.6.4'] has failed. Received Exception("Invalid command '192.168.6.4' (no set action or not yet implemented)") 2024-05-26 15:50:10,681 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', '127.0.0.1'] has failed. Received Exception("Invalid command '127.0.0.1' (no set action or not yet implemented)") 2024-05-26 15:55:12,641 fail2ban.transmitter [847779]: ERROR Command ['get', 'ignoreip'] has failed. Received IndexError('list index out of range') 2024-05-26 15:55:12,697 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', '192.168.5.55'] has failed. Received Exception("Invalid command '192.168.5.55' (no set action or not yet implemented)") 2024-05-26 15:55:12,751 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', 'xxxxx'] has failed. Received Exception("Invalid command '81.247.187.175' (no set action or not yet implemented)") 2024-05-26 15:55:12,808 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', '57.129.5.195'] has failed. Received Exception("Invalid command '57.129.5.195' (no set action or not yet implemented)") 2024-05-26 15:55:12,869 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', '127.0.1.1'] has failed. Received Exception("Invalid command '127.0.1.1' (no set action or not yet implemented)") 2024-05-26 15:55:12,932 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', '192.168.6.4'] has failed. Received Exception("Invalid command '192.168.6.4' (no set action or not yet implemented)") 2024-05-26 15:55:12,987 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', '127.0.0.1'] has failed. Received Exception("Invalid command '127.0.0.1' (no set action or not yet implemented)") 2024-05-26 16:00:33,629 fail2ban.transmitter [847779]: ERROR Command ['get', 'ignoreip'] has failed. Received IndexError('list index out of range') 2024-05-26 16:00:33,687 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', '192.168.5.55'] has failed. Received Exception("Invalid command '192.168.5.55' (no set action or not yet implemented)") 2024-05-26 16:00:33,742 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', 'xxxxx'] has failed. Received Exception("Invalid command '81.247.187.175' (no set action or not yet implemented)") 2024-05-26 16:00:33,800 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', '57.129.5.195'] has failed. Received Exception("Invalid command '57.129.5.195' (no set action or not yet implemented)") 2024-05-26 16:00:33,861 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', '127.0.1.1'] has failed. Received Exception("Invalid command '127.0.1.1' (no set action or not yet implemented)") 2024-05-26 16:00:33,916 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', '192.168.6.4'] has failed. Received Exception("Invalid command '192.168.6.4' (no set action or not yet implemented)") 2024-05-26 16:00:33,970 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', '127.0.0.1'] has failed. Received Exception("Invalid command '127.0.0.1' (no set action or not yet implemented)") 2024-05-26 16:05:31,007 fail2ban.transmitter [847779]: ERROR Command ['get', 'ignoreip'] has failed. Received IndexError('list index out of range') 2024-05-26 16:05:31,062 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', '192.168.5.55'] has failed. Received Exception("Invalid command '192.168.5.55' (no set action or not yet implemented)") 2024-05-26 16:05:31,117 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', 'xxxxx'] has failed. Received Exception("Invalid command '81.247.187.175' (no set action or not yet implemented)") 2024-05-26 16:05:31,171 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', '57.129.5.195'] has failed. Received Exception("Invalid command '57.129.5.195' (no set action or not yet implemented)") 2024-05-26 16:05:31,247 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', '127.0.1.1'] has failed. Received Exception("Invalid command '127.0.1.1' (no set action or not yet implemented)") 2024-05-26 16:05:31,302 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', '192.168.6.4'] has failed. Received Exception("Invalid command '192.168.6.4' (no set action or not yet implemented)") 2024-05-26 16:05:31,359 fail2ban.transmitter [847779]: ERROR Command ['set', 'addignoreip', '127.0.0.1'] has failed. Received Exception("Invalid command '127.0.0.1' (no set action or not yet implemented)") 2024-05-26 16:10:51,880 fail2ban.server [847779]: INFO Shutdown in progress...
NB:
target prot opt source destination
zone-trusted all -- 192.168.5.55 anywhere
zone-internal all -- 192.168.6.0/24 anywhere
zone-internal all -- 192.168.5.0/24 anywhere
....
FreePBX Version
FreePBX 17
Issue Description
Freepbx 17 is generating lot of iptables errors.
NOTE: iptables was replaced by nftables starting in Debian 10
Examples : (more below)
2024-05-09 21:16:32,734 fail2ban.actions [440]: ERROR Failed to stop jail 'vsftpd-iptables' action 'iptables-multiport-FTP': Error stopping action Jail('vsftpd-iptables')/iptables-multiport-FTP: 'Script error' 2024-05-09 21:16:32,740 fail2ban.utils [440]: ERROR 7f991a3af7b0 -- exec: iptables -D INPUT -p tcp -m multiport --dports http,https -j fail2ban-BadBots 2024-05-09 21:16:32,740 fail2ban.utils [440]: ERROR 7f991a3af7b0 -- stderr: "iptables v1.8.9 (nf_tables): Chain 'fail2ban-BadBots' does not exist" 2024-05-09 21:16:32,740 fail2ban.utils [440]: ERROR 7f991a3af7b0 -- stderr: "Try `iptables -h' or 'iptables --help' for more information." 2024-05-09 21:16:32,740 fail2ban.utils [440]: ERROR 7f991a3af7b0 -- stderr: 'iptables: No chain/target/match by that name.' 2024-05-09 21:16:32,740 fail2ban.utils [440]: ERROR 7f991a3af7b0 -- stderr: 'iptables: No chain/target/match by that name.' 2024-05-09 21:16:32,740 fail2ban.utils [440]: ERROR 7f991a3af7b0 -- returned 1 2024-05-09 21:16:32,740 fail2ban.actions [440]: ERROR Failed to stop jail 'apache-badbots' action 'iptables-multiport-BadBots': Error stopping action Jail('apache-badbots')/iptables-multiport-BadBots: 'Script error' 2024-05-09 21:24:27,345 fail2ban.utils [441]: ERROR 7fdd06e9a080 -- exec: iptables -D INPUT -p tcp -m multiport --dports ssh -j fail2ban-sshd 2024-05-09 21:24:27,345 fail2ban.utils [441]: ERROR 7fdd06e9a080 -- stderr: 'iptables v1.8.9 (nf_tables): CHAIN_DEL failed (Device or resource busy): chain fail2ban-sshd' 2024-05-09 21:24:27,345 fail2ban.utils [441]: ERROR 7fdd06e9a080 -- returned 4 2024-05-09 21:24:27,345 fail2ban.actions [441]: ERROR Failed to stop jail 'sshd' action 'iptables-multiport': Error stopping action Jail('sshd')/iptables-multiport: 'Scr2024-05-09 21:24:41,228 fail2ban.server [442]: INFO --------------------------------------------------
Operating Environment
debian 12.5 iptables v1.8.9 (nf_tables) Fail2Ban v1.0.2
Relevant log output