<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[iRedMail — fail2ban banning cell phone clients]]></title>
		<link>http://www.iredmail.org/forum/topic3963-fail2ban-banning-cell-phone-clients.html</link>
		<atom:link href="http://www.iredmail.org/forum/feed-rss-topic3963.xml" rel="self" type="application/rss+xml" />
		<description><![CDATA[The most recent posts in fail2ban banning cell phone clients.]]></description>
		<lastBuildDate>Tue, 09 Oct 2012 04:15:20 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Re: fail2ban banning cell phone clients]]></title>
			<link>http://www.iredmail.org/forum/post18510.html#p18510</link>
			<description><![CDATA[<div class="quotebox"><blockquote><p>On 10/7/2012<br />The IP 184.78.62.159 has just been banned by Fail2Ban after 5 attempts against Postfix.</p></blockquote></div><p>Works as expected.</p><p>Did you try resetting this user&#039;s password?</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Tue, 09 Oct 2012 04:15:20 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post18510.html#p18510</guid>
		</item>
		<item>
			<title><![CDATA[Re: fail2ban banning cell phone clients]]></title>
			<link>http://www.iredmail.org/forum/post18504.html#p18504</link>
			<description><![CDATA[<p>How can I search the log files to see why it is happening?</p><p>in /var/log/, does Fail2ban look in all logs?</p><p>On 10/7/2012<br />The IP 184.78.62.159 has just been banned by Fail2Ban after 5 attempts against Postfix.</p><p>nm2:/var/log# grep &quot;184.78.62.159&quot; * | grep &quot;failed&quot;</p><p>I have results from mail.info, mail.warn, mail.log and syslog1.</p><br /><p>mail.info:Oct&nbsp; 7 10:34:00 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />mail.info:Oct&nbsp; 7 10:34:06 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.info:Oct&nbsp; 7 10:34:16 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.info:Oct&nbsp; 7 10:34:18 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.info:Oct&nbsp; 7 10:34:21 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.info:Oct&nbsp; 7 10:34:23 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.info:Oct&nbsp; 7 10:34:34 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.info:Oct&nbsp; 7 10:34:40 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.info:Oct&nbsp; 7 10:36:44 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />mail.info:Oct&nbsp; 7 10:36:50 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.info:Oct&nbsp; 7 10:37:01 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.info:Oct&nbsp; 7 10:37:07 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.info:Oct&nbsp; 7 10:39:08 nm2 postfix/smtpd[1379]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />mail.info:Oct&nbsp; 7 10:39:14 nm2 postfix/smtpd[1379]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:34:00 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />mail.log:Oct&nbsp; 7 10:34:06 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:34:16 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:34:18 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:34:21 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:34:23 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:34:34 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:34:40 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:36:44 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />mail.log:Oct&nbsp; 7 10:36:50 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:37:01 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:37:07 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.log:Oct&nbsp; 7 10:39:08 nm2 postfix/smtpd[1379]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />mail.log:Oct&nbsp; 7 10:39:14 nm2 postfix/smtpd[1379]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:34:00 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />mail.warn:Oct&nbsp; 7 10:34:06 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:34:16 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:34:18 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:34:21 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:34:23 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:34:34 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:34:40 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:36:44 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />mail.warn:Oct&nbsp; 7 10:36:50 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:37:01 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:37:07 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />mail.warn:Oct&nbsp; 7 10:39:08 nm2 postfix/smtpd[1379]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />mail.warn:Oct&nbsp; 7 10:39:14 nm2 postfix/smtpd[1379]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:34:00 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />syslog.1:Oct&nbsp; 7 10:34:06 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:34:16 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:34:18 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:34:21 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:34:23 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:34:34 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:34:40 nm2 postfix/smtpd[1160]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:36:44 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />syslog.1:Oct&nbsp; 7 10:36:50 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:37:01 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:37:07 nm2 postfix/smtpd[1300]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6<br />syslog.1:Oct&nbsp; 7 10:39:08 nm2 postfix/smtpd[1379]: warning: unknown[184.78.62.159]: SASL PLAIN authentication failed:<br />syslog.1:Oct&nbsp; 7 10:39:14 nm2 postfix/smtpd[1379]: warning: unknown[184.78.62.159]: SASL LOGIN authentication failed: UGFzc3dvcmQ6</p>]]></description>
			<author><![CDATA[null@example.com (darth_wells)]]></author>
			<pubDate>Mon, 08 Oct 2012 20:31:33 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post18504.html#p18504</guid>
		</item>
		<item>
			<title><![CDATA[Re: fail2ban banning cell phone clients]]></title>
			<link>http://www.iredmail.org/forum/post18481.html#p18481</link>
			<description><![CDATA[<p>Your log is not related to banned IP 69.246.221.84.</p><p>Fail2ban scan log files, if there&#039;re multiple password failures, it will ban client IP with iptables. This is how it works.</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Sun, 07 Oct 2012 12:30:45 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post18481.html#p18481</guid>
		</item>
		<item>
			<title><![CDATA[Re: fail2ban banning cell phone clients]]></title>
			<link>http://www.iredmail.org/forum/post18458.html#p18458</link>
			<description><![CDATA[<p>Could this be causing the problem?</p><p>In the /var/log/mail.info or /var/log/syslog</p><p>mail.info:Sep 30 11:10:00 nm2 postfix/smtpd[18221]: warning: hostname mobile-166-137-081-095.mycingular.net does not resolve to address 166.137.81.95: Name or service not known</p><p>mail.info:Sep 30 12:28:45 nm2 postfix/smtpd[20873]: warning: hostname static.kpn.net does not resolve to address 46.144.243.70: Name or service not known</p><p>mail.info:Sep 30 16:36:58 nm2 postfix/smtpd[30102]: warning: hostname 173-170-174-97.res.bhn.net does not resolve to address 173.170.174.97: Name or service not known</p><p>mail.info:Oct&nbsp; 1 03:39:15 nm2 postfix/smtpd[20559]: warning: hostname mobile-166-137-080-007.mycingular.net does not resolve to address 166.137.80.7: Name or service not known</p>]]></description>
			<author><![CDATA[null@example.com (darth_wells)]]></author>
			<pubDate>Thu, 04 Oct 2012 19:32:07 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post18458.html#p18458</guid>
		</item>
		<item>
			<title><![CDATA[Re: fail2ban banning cell phone clients]]></title>
			<link>http://www.iredmail.org/forum/post18442.html#p18442</link>
			<description><![CDATA[<p>What log file should I be looking in?</p><p>Is it the dovecot-info.log file?</p>]]></description>
			<author><![CDATA[null@example.com (darth_wells)]]></author>
			<pubDate>Wed, 03 Oct 2012 14:16:57 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post18442.html#p18442</guid>
		</item>
		<item>
			<title><![CDATA[Re: fail2ban banning cell phone clients]]></title>
			<link>http://www.iredmail.org/forum/post18430.html#p18430</link>
			<description><![CDATA[<p>Does this client get many password failure while performing SMTP auth/login?</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Wed, 03 Oct 2012 08:39:13 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post18430.html#p18430</guid>
		</item>
		<item>
			<title><![CDATA[fail2ban banning cell phone clients]]></title>
			<link>http://www.iredmail.org/forum/post18421.html#p18421</link>
			<description><![CDATA[<p>==== Required information ====<br />- iRedMail version: 0.8.1<br />- Store mail accounts in which backend (LDAP/MySQL/PGSQL): mysql<br />- Linux/BSD distribution name and version: debian<br />- Related log if you&#039;re reporting an issue: <br />==== </p><p>fail2ban is banning cell phone clients,</p><p>/var/log/fail2ban.log<br />2012-10-01 18:31:05,338 fail2ban.actions: WARNING [postfix-iredmail] Ban 69.246.221.84<br />2012-10-01 18:36:05,688 fail2ban.actions: WARNING [postfix-iredmail] Unban 69.246.221.84<br />2012-10-01 18:45:55,354 fail2ban.actions: WARNING [postfix-iredmail] Ban 69.246.221.84<br />2012-10-01 18:49:36,602 fail2ban.actions: WARNING [postfix-iredmail] 69.246.221.84 already banned<br />2012-10-01 18:50:55,691 fail2ban.actions: WARNING [postfix-iredmail] Unban 69.246.221.84<br />2012-10-01 19:00:50,367 fail2ban.actions: WARNING [postfix-iredmail] Ban 69.246.221.84<br />2012-10-01 19:05:50,701 fail2ban.actions: WARNING [postfix-iredmail] Unban 69.246.221.84<br />2012-10-01 19:15:32,354 fail2ban.actions: WARNING [postfix-iredmail] Ban 69.246.221.84<br />2012-10-01 19:16:32,433 fail2ban.actions: WARNING [postfix-iredmail] 69.246.221.84 already banned<br />2012-10-01 19:20:32,706 fail2ban.actions: WARNING [postfix-iredmail] Unban 69.246.221.84<br />2012-10-01 19:30:31,401 fail2ban.actions: WARNING [postfix-iredmail] Ban 69.246.221.84<br />2012-10-01 19:35:31,777 fail2ban.actions: WARNING [postfix-iredmail] Unban 69.246.221.84<br />2012-10-01 19:44:10,373 fail2ban.actions: WARNING [postfix-iredmail] Ban 69.246.221.84<br />2012-10-01 19:49:10,717 fail2ban.actions: WARNING [postfix-iredmail] Unban 69.246.221.84<br />2012-10-01 19:58:49,386 fail2ban.actions: WARNING [postfix-iredmail] Ban 69.246.221.84<br />2012-10-01 19:59:49,455 fail2ban.actions: WARNING [postfix-iredmail] 69.246.221.84 already banned<br />2012-10-01 20:03:49,726 fail2ban.actions: WARNING [postfix-iredmail] Unban 69.246.221.84</p><p>Where can I look to see why this is getting banned?<br />the /var/log/fail2ban.log doesn&#039;t really give me any information<br />how to troubleshoot postfix-iredmail bans?</p>]]></description>
			<author><![CDATA[null@example.com (darth_wells)]]></author>
			<pubDate>Tue, 02 Oct 2012 15:53:44 +0000</pubDate>
			<guid>http://www.iredmail.org/forum/post18421.html#p18421</guid>
		</item>
	</channel>
</rss>
