Crie um novo arquivo /etc/fail2ban/filter.d/postfix-sasl.conf e insira o conteúdo abaixo:Mar 15 23:31:57 mailserver fail2ban-server[108692]: Found no accessible config files for 'filter.d/postfix-sasl' under /etc/fail2ban
Mar 15 23:31:57 mailserver fail2ban-server[108692]: Unable to read the filter 'postfix-sasl'
Mar 15 23:31:58 mailserver fail2ban-server[108692]: Errors in jail 'postfix-sasl'. Skipping...
Código: Selecionar todos
# Fail2Ban filter for postfix authentication failures
#
[INCLUDES]
before = common.conf
[Definition]
_daemon = postfix/(submission/)?smtp(d|s)
failregex = ^%(__prefix_line)swarning: [-._\w]+\[<HOST>\]: SASL ((?i)LOGIN|PLAIN|(?:CRAM|DIGEST)-MD5) authentication failed(: [ A-Za-z0-9+/:]*={0,2})?\s*$
ignoreregex = authentication failed: Connection lost to authentication server$
[Init]
journalmatch = _SYSTEMD_UNIT=postfix.service
# Author: Yaroslav Halchenko
ignoreregex =