<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[iRedMail — fail2ban banning cell phone clients]]></title>
	<link rel="self" href="http://www.iredmail.org/forum/feed-atom-topic3963.xml" />
	<updated>2012-10-09T04:15:20Z</updated>
	<generator>PunBB</generator>
	<id>http://www.iredmail.org/forum/topic3963-fail2ban-banning-cell-phone-clients.html</id>
		<entry>
			<title type="html"><![CDATA[Re: fail2ban banning cell phone clients]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post18510.html#p18510" />
			<content type="html"><![CDATA[<div class="quotebox"><blockquote><p>On 10/7/2012<br />The IP 184.78.62.159 has just been banned by Fail2Ban after 5 attempts against Postfix.</p></blockquote></div><p>Works as expected.</p><p>Did you try resetting this user&#039;s password?</p>]]></content>
			<author>
				<name><![CDATA[ZhangHuangbin]]></name>
				<uri>http://www.iredmail.org/forum/user2.html</uri>
			</author>
			<updated>2012-10-09T04:15:20Z</updated>
			<id>http://www.iredmail.org/forum/post18510.html#p18510</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: fail2ban banning cell phone clients]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post18504.html#p18504" />
			<content type="html"><![CDATA[<p>How can I search the log files to see why it is happening?</p><p>in /var/log/, does Fail2ban look in all logs?</p><p>On 10/7/2012<br />The IP 184.78.62.159 has just been banned by Fail2Ban after 5 attempts against Postfix.</p><p>nm2:/var/log# grep &quot;184.78.62.159&quot; * | grep &quot;failed&quot;</p><p>I have results from mail.info, mail.warn, mail.log and syslog1.</p><br /><p>mail.info:Oct&nbsp; 7 10:34:00 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />mail.info:Oct&nbsp; 7 10:34:06 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.info:Oct&nbsp; 7 10:34:16 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.info:Oct&nbsp; 7 10:34:18 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.info:Oct&nbsp; 7 10:34:21 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.info:Oct&nbsp; 7 10:34:23 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.info:Oct&nbsp; 7 10:34:34 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.info:Oct&nbsp; 7 10:34:40 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.info:Oct&nbsp; 7 10:36:44 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />mail.info:Oct&nbsp; 7 10:36:50 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.info:Oct&nbsp; 7 10:37:01 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.info:Oct&nbsp; 7 10:37:07 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.info:Oct&nbsp; 7 10:39:08 nm2 postfix/smtpd[1379]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />mail.info:Oct&nbsp; 7 10:39:14 nm2 postfix/smtpd[1379]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:34:00 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />mail.log:Oct&nbsp; 7 10:34:06 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:34:16 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:34:18 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:34:21 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:34:23 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:34:34 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:34:40 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:36:44 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />mail.log:Oct&nbsp; 7 10:36:50 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:37:01 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:37:07 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:39:08 nm2 postfix/smtpd[1379]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />mail.log:Oct&nbsp; 7 10:39:14 nm2 postfix/smtpd[1379]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:34:00 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />mail.warn:Oct&nbsp; 7 10:34:06 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:34:16 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:34:18 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:34:21 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:34:23 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:34:34 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:34:40 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:36:44 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />mail.warn:Oct&nbsp; 7 10:36:50 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:37:01 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:37:07 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:39:08 nm2 postfix/smtpd[1379]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />mail.warn:Oct&nbsp; 7 10:39:14 nm2 postfix/smtpd[1379]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:34:00 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />syslog.1:Oct&nbsp; 7 10:34:06 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:34:16 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:34:18 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:34:21 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:34:23 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:34:34 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:34:40 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:36:44 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />syslog.1:Oct&nbsp; 7 10:36:50 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:37:01 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:37:07 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:39:08 nm2 postfix/smtpd[1379]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />syslog.1:Oct&nbsp; 7 10:39:14 nm2 postfix/smtpd[1379]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6</p>]]></content>
			<author>
				<name><![CDATA[darth_wells]]></name>
				<uri>http://www.iredmail.org/forum/user23240.html</uri>
			</author>
			<updated>2012-10-08T20:31:33Z</updated>
			<id>http://www.iredmail.org/forum/post18504.html#p18504</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: fail2ban banning cell phone clients]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post18481.html#p18481" />
			<content type="html"><![CDATA[<p>Your log is not related to banned IP 69.246.221.84.</p><p>Fail2ban scan log files, if there&#039;re multiple password failures, it will ban client IP with iptables. This is how it works.</p>]]></content>
			<author>
				<name><![CDATA[ZhangHuangbin]]></name>
				<uri>http://www.iredmail.org/forum/user2.html</uri>
			</author>
			<updated>2012-10-07T12:30:45Z</updated>
			<id>http://www.iredmail.org/forum/post18481.html#p18481</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: fail2ban banning cell phone clients]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post18458.html#p18458" />
			<content type="html"><![CDATA[<p>Could this be causing the problem?</p><p>In the /var/log/mail.info or /var/log/syslog</p><p>mail.info:Sep 30 11:10:00 nm2 postfix/smtpd[18221]: warning: hostname mobile-166-137-081-095.mycingular.net does not resolve to address 166.137.81.95: Name or service not known</p><p>mail.info:Sep 30 12:28:45 nm2 postfix/smtpd[20873]: warning: hostname static.kpn.net does not resolve to address 46.144.243.70: Name or service not known</p><p>mail.info:Sep 30 16:36:58 nm2 postfix/smtpd[30102]: warning: hostname 173-170-174-97.res.bhn.net does not resolve to address 173.170.174.97: Name or service not known</p><p>mail.info:Oct&nbsp; 1 03:39:15 nm2 postfix/smtpd[20559]: warning: hostname mobile-166-137-080-007.mycingular.net does not resolve to address 166.137.80.7: Name or service not known</p>]]></content>
			<author>
				<name><![CDATA[darth_wells]]></name>
				<uri>http://www.iredmail.org/forum/user23240.html</uri>
			</author>
			<updated>2012-10-04T19:32:07Z</updated>
			<id>http://www.iredmail.org/forum/post18458.html#p18458</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: fail2ban banning cell phone clients]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post18442.html#p18442" />
			<content type="html"><![CDATA[<p>What log file should I be looking in?</p><p>Is it the dovecot-info.log file?</p>]]></content>
			<author>
				<name><![CDATA[darth_wells]]></name>
				<uri>http://www.iredmail.org/forum/user23240.html</uri>
			</author>
			<updated>2012-10-03T14:16:57Z</updated>
			<id>http://www.iredmail.org/forum/post18442.html#p18442</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: fail2ban banning cell phone clients]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post18430.html#p18430" />
			<content type="html"><![CDATA[<p>Does this client get many password failure while performing SMTP auth/login?</p>]]></content>
			<author>
				<name><![CDATA[ZhangHuangbin]]></name>
				<uri>http://www.iredmail.org/forum/user2.html</uri>
			</author>
			<updated>2012-10-03T08:39:13Z</updated>
			<id>http://www.iredmail.org/forum/post18430.html#p18430</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[fail2ban banning cell phone clients]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post18421.html#p18421" />
			<content type="html"><![CDATA[<p>==== Required information ====<br />- iRedMail version: 0.8.1<br />- Store mail accounts in which backend (LDAP/MySQL/PGSQL): mysql<br />- Linux/BSD distribution name and version: debian<br />- Related log if you&#039;re reporting an issue: <br />==== </p><p>fail2ban is banning cell phone clients,</p><p>/var/log/fail2ban.log<br />2012-10-01 18:31:05,338 fail2ban.actions: WARNING [postfix-iredmail] Ban 69.246.221.84<br />2012-10-01 18:36:05,688 fail2ban.actions: WARNING [postfix-iredmail] Unban 69.246.221.84<br />2012-10-01 18:45:55,354 fail2ban.actions: WARNING [postfix-iredmail] Ban 69.246.221.84<br />2012-10-01 18:49:36,602 fail2ban.actions: WARNING [postfix-iredmail] 69.246.221.84 already banned<br />2012-10-01 18:50:55,691 fail2ban.actions: WARNING [postfix-iredmail] Unban 69.246.221.84<br />2012-10-01 19:00:50,367 fail2ban.actions: WARNING [postfix-iredmail] Ban 69.246.221.84<br />2012-10-01 19:05:50,701 fail2ban.actions: WARNING [postfix-iredmail] Unban 69.246.221.84<br />2012-10-01 19:15:32,354 fail2ban.actions: WARNING [postfix-iredmail] Ban 69.246.221.84<br />2012-10-01 19:16:32,433 fail2ban.actions: WARNING [postfix-iredmail] 69.246.221.84 already banned<br />2012-10-01 19:20:32,706 fail2ban.actions: WARNING [postfix-iredmail] Unban 69.246.221.84<br />2012-10-01 19:30:31,401 fail2ban.actions: WARNING [postfix-iredmail] Ban 69.246.221.84<br />2012-10-01 19:35:31,777 fail2ban.actions: WARNING [postfix-iredmail] Unban 69.246.221.84<br />2012-10-01 19:44:10,373 fail2ban.actions: WARNING [postfix-iredmail] Ban 69.246.221.84<br />2012-10-01 19:49:10,717 fail2ban.actions: WARNING [postfix-iredmail] Unban 69.246.221.84<br />2012-10-01 19:58:49,386 fail2ban.actions: WARNING [postfix-iredmail] Ban 69.246.221.84<br />2012-10-01 19:59:49,455 fail2ban.actions: WARNING [postfix-iredmail] 69.246.221.84 already banned<br />2012-10-01 20:03:49,726 fail2ban.actions: WARNING [postfix-iredmail] Unban 69.246.221.84</p><p>Where can I look to see why this is getting banned?<br />the /var/log/fail2ban.log doesn&#039;t really give me any information<br />how to troubleshoot postfix-iredmail bans?</p>]]></content>
			<author>
				<name><![CDATA[darth_wells]]></name>
				<uri>http://www.iredmail.org/forum/user23240.html</uri>
			</author>
			<updated>2012-10-02T15:53:44Z</updated>
			<id>http://www.iredmail.org/forum/post18421.html#p18421</id>
		</entry>
</feed>
