5 Oct
2013
5 Oct
'13
4:55 p.m.
On 04/10/2013 1:47 AM, Nick Edwards wrote:
filter.d/dovecot.conf [Definition] failregex = (?: pop3-login|imap-login): (?:Authentication failure|Aborted login \(auth failed|Aborted login \(tried to use disabled|Disconnected \(auth failed).*rip=(?P<host>\S*),.* ignoreregex =
The following is included with fail2ban 0.8.10
filters.d/dovecot.conf
Fail2Ban configuration file for dovcot
Author: Martin Waschbuesch
[Definition]
Option: failregex
Notes.: regex to match the password failures messages in the logfile. The
host must be matched by a group named "host". The tag
"<HOST>" can
be used for standard IP/hostname matching and is only an
alias for
(?:::f{4,6}:)?(?P<host>[\w\-.^_]+)
Values: TEXT
failregex = .*(?:pop3-login|imap-login):.*(?:Authentication failure|Aborted login \(auth failed|Aborted login \(tried to use disabled|Disconnected \(auth failed).*\s+rip=(?P<host>\S*),.* pam.*dovecot.*(?:authentication failure).*\s+rhost=<HOST>(?:\s+user=.*)?\s*$
Option: ignoreregex
Notes.: regex to ignore. If this regex matches, the line is ignored.
Values: TEXT
ignoreregex =