Bonjour,
J'ai un serveur qui est actuellement attaqué par brut force.
J'ai donc installé fail2ban afin de limiter cette attaque mais je ne sais pas si j'ai la bonne configuration.
Dans fail2ban j'ai juste modifié la durée de bannissement.
Lorsque je tape la commande
fail2ban-client status ssh
J'obtiens bien une liste d'adresse ip de bloqué à savoir
Status for the jail: ssh
|- filter
| |- File list: /var/log/auth.log
| |- Currently failed: 13
| `- Total failed: 7107
`- action
|- Currently banned: 14
| `- IP list: 117.50.127.207 149.129.95.70 8.218.118.192 47.243.104.65 47.76.118.228 120.25.238.67 47.243.126.140 219.153.56.131 8.210.86.169 8.130.137.183 47.238.188.244 47.242.33.127 8.217.185.82 8.137.126.60
`- Total banned: 14
Or si je regarde en continu les log de auth.log je constate toujours les tentative de connexion de ces mêmes adresses ip
Jun 17 16:33:43 serveur sshd[5785]: Received disconnect from 219.153.56.131: 11: Bye Bye [preauth]
Jun 17 16:33:43 serveur sshd[5807]: Failed password for root from 149.129.95.70 port 38470 ssh2
Jun 17 16:33:43 serveur sshd[5807]: Received disconnect from 149.129.95.70: 11: Bye Bye [preauth]
Jun 17 16:33:44 serveur sshd[5803]: Failed password for root from 47.243.126.140 port 48228 ssh2
Jun 17 16:33:45 serveur sshd[5815]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=8.210.86.169 user=root
Jun 17 16:33:45 serveur sshd[5813]: Failed password for root from 8.130.137.183 port 48706 ssh2
Jun 17 16:33:45 serveur sshd[5803]: Received disconnect from 47.243.126.140: 11: Bye Bye [preauth]
Jun 17 16:33:45 serveur sshd[5813]: Received disconnect from 8.130.137.183: 11: Bye Bye [preauth]
Jun 17 16:33:46 serveur sshd[5819]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=8.217.185.82 user=root
Jun 17 16:33:46 serveur sshd[5809]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=120.25.238.67 user=root
Jun 17 16:33:47 serveur sshd[5817]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=47.76.118.228 user=root
Jun 17 16:33:47 serveur sshd[5815]: Failed password for root from 8.210.86.169 port 39140 ssh2
Jun 17 16:33:47 serveur sshd[5825]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=8.130.137.183 user=root
Jun 17 16:33:47 serveur sshd[5815]: Received disconnect from 8.210.86.169: 11: Bye Bye [preauth]
Jun 17 16:33:48 serveur sshd[5819]: Failed password for root from 8.217.185.82 port 55240 ssh2
Jun 17 16:33:48 serveur sshd[5819]: Received disconnect from 8.217.185.82: 11: Bye Bye [preauth]
Jun 17 16:33:48 serveur sshd[5809]: Failed password for root from 120.25.238.67 port 53006 ssh2
Jun 17 16:33:48 serveur sshd[5823]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=47.243.126.140 user=root
Jun 17 16:33:49 serveur sshd[5817]: Failed password for root from 47.76.118.228 port 38676 ssh2
Jun 17 16:33:49 serveur sshd[5825]: Failed password for root from 8.130.137.183 port 51110 ssh2
Jun 17 16:33:49 serveur sshd[5811]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=8.218.118.192 user=root
Jun 17 16:33:49 serveur sshd[5825]: Received disconnect from 8.130.137.183: 11: Bye Bye [preauth]
Jun 17 16:33:49 serveur sshd[5829]: Invalid user deploy from 219.153.56.131
Jun 17 16:33:49 serveur sshd[5829]: input_userauth_request: invalid user deploy [preauth]
Jun 17 16:33:49 serveur sshd[5829]: pam_unix(sshd:auth): check pass; user unknown
Jun 17 16:33:49 serveur sshd[5829]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=219.153.56.131
Jun 17 16:33:49 serveur sshd[5834]: Received disconnect from 8.210.86.169: 11: Bye Bye [preauth]
Jun 17 16:33:50 serveur sshd[5822]: Invalid user dncaf from 47.242.33.127
Jun 17 16:33:50 serveur sshd[5822]: input_userauth_request: invalid user dncaf [preauth]
Jun 17 16:33:50 serveur sshd[5823]: Failed password for root from 47.243.126.140 port 56858 ssh2
Jun 17 16:33:50 serveur sshd[5809]: Received disconnect from 120.25.238.67: 11: Bye Bye [preauth]
Jun 17 16:33:50 serveur sshd[5823]: Received disconnect from 47.243.126.140: 11: Bye Bye [preauth]
Jun 17 16:33:51 serveur sshd[5817]: Received disconnect from 47.76.118.228: 11: Bye Bye [preauth]
Jun 17 16:33:51 serveur sshd[5822]: Received disconnect from 47.242.33.127: 11: Bye Bye [preauth]
Jun 17 16:33:51 serveur sshd[5821]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=47.243.104.65 user=root
Jun 17 16:33:51 serveur sshd[5836]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=8.130.137.183 user=root
Jun 17 16:33:51 serveur sshd[5811]: Failed password for root from 8.218.118.192 port 49204 ssh2
Jun 17 16:33:51 serveur sshd[5829]: Failed password for invalid user deploy from 219.153.56.131 port 39011 ssh2
Jun 17 16:33:52 serveur sshd[5829]: Received disconnect from 219.153.56.131: 11: Bye Bye [preauth]
Jun 17 16:33:52 serveur sshd[5811]: Received disconnect from 8.218.118.192: 11: Bye Bye [preauth]
Jun 17 16:33:53 serveur sshd[5821]: Failed password for root from 47.243.104.65 port 48388 ssh2
Jun 17 16:33:53 serveur sshd[5836]: Failed password for root from 8.130.137.183 port 53368 ssh2
Jun 17 16:33:53 serveur sshd[5821]: Received disconnect from 47.243.104.65: 11: Bye Bye [preauth]
Jun 17 16:33:53 serveur sshd[5836]: Received disconnect from 8.130.137.183: 11: Bye Bye [preauth]
Jun 17 16:33:54 serveur sshd[5838]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=47.238.188.244 user=root
Jun 17 16:33:54 serveur sshd[5832]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=149.129.95.70 user=root
Jun 17 16:33:55 serveur sshd[5844]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=8.217.185.82 user=root
Jun 17 16:33:56 serveur sshd[5850]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=8.130.137.183 user=root
Jun 17 16:33:56 serveur sshd[5838]: Failed password for root from 47.238.188.244 port 45768 ssh2
Jun 17 16:33:56 serveur sshd[5838]: Received disconnect from 47.238.188.244: 11: Bye Bye [preauth]
Jun 17 16:33:56 serveur sshd[5832]: Failed password for root from 149.129.95.70 port 55006 ssh2
Jun 17 16:33:57 serveur sshd[5844]: Failed password for root from 8.217.185.82 port 44506 ssh2
Est-ce que cela vient du fait que dans les logs il s'agit de sshd ? A noter également que mon port d'écoute SSH n'est pas le port classique
Pouvez-vous m'aider à configurer fail2ban de la meilleur des façons ?
Merci