Merci pour vos interventions
donc voici le retour de journalctl -u fail2ban.service
juin 14 09:26:45 intranet systemd[1]: Starting Fail2Ban Service...
juin 14 09:26:46 intranet fail2ban-client[424]: ERROR Failed during configuration: While reading from '/etc/fail2ban/jail.conf' [line 156]: option 'port' in section 'pam-generic' already exists
juin 14 09:26:46 intranet systemd[1]: fail2ban.service: Control process exited, code=exited status=255
juin 14 09:26:46 intranet systemd[1]: Failed to start Fail2Ban Service.
juin 14 09:26:46 intranet systemd[1]: fail2ban.service: Unit entered failed state.
juin 14 09:26:46 intranet systemd[1]: fail2ban.service: Failed with result 'exit-code'.
juin 14 09:26:47 intranet systemd[1]: fail2ban.service: Service hold-off time over, scheduling restart.
juin 14 09:26:47 intranet systemd[1]: Stopped Fail2Ban Service.
juin 14 09:26:47 intranet systemd[1]: Starting Fail2Ban Service...
juin 14 09:26:47 intranet fail2ban-client[720]: ERROR Failed during configuration: While reading from '/etc/fail2ban/jail.conf' [line 156]: option 'port' in section 'pam-generic' already exists
juin 14 09:26:47 intranet systemd[1]: fail2ban.service: Control process exited, code=exited status=255
juin 14 09:26:47 intranet systemd[1]: Failed to start Fail2Ban Service.
juin 14 09:26:47 intranet systemd[1]: fail2ban.service: Unit entered failed state.
juin 14 09:26:47 intranet systemd[1]: fail2ban.service: Failed with result 'exit-code'.
juin 14 09:26:47 intranet systemd[1]: fail2ban.service: Service hold-off time over, scheduling restart.
juin 14 09:26:47 intranet systemd[1]: Stopped Fail2Ban Service.
juin 14 09:26:47 intranet systemd[1]: Starting Fail2Ban Service...
juin 14 09:26:47 intranet fail2ban-client[732]: ERROR Failed during configuration: While reading from '/etc/fail2ban/jail.conf' [line 156]: option 'port' in section 'pam-generic' already exists
juin 14 09:26:47 intranet systemd[1]: fail2ban.service: Control process exited, code=exited status=255
juin 14 09:26:47 intranet systemd[1]: Failed to start Fail2Ban Service.
juin 14 09:26:47 intranet systemd[1]: fail2ban.service: Unit entered failed state.
juin 14 09:26:47 intranet systemd[1]: fail2ban.service: Failed with result 'exit-code'.
juin 14 09:26:47 intranet systemd[1]: fail2ban.service: Service hold-off time over, scheduling restart.
juin 14 09:26:47 intranet systemd[1]: Stopped Fail2Ban Service.
juin 14 09:26:47 intranet systemd[1]: Starting Fail2Ban Service...
juin 14 09:26:47 intranet fail2ban-client[745]: ERROR Failed during configuration: While reading from '/etc/fail2ban/jail.conf' [line 156]: option 'port' in section 'pam-generic' already exists
juin 14 09:26:47 intranet systemd[1]: fail2ban.service: Control process exited, code=exited status=255
juin 14 09:26:47 intranet systemd[1]: Failed to start Fail2Ban Service.
juin 14 09:26:47 intranet systemd[1]: fail2ban.service: Unit entered failed state.
juin 14 09:26:47 intranet systemd[1]: fail2ban.service: Failed with result 'exit-code'.
juin 14 09:26:48 intranet systemd[1]: fail2ban.service: Service hold-off time over, scheduling restart.
juin 14 09:26:48 intranet systemd[1]: Stopped Fail2Ban Service.
juin 14 09:26:48 intranet systemd[1]: Starting Fail2Ban Service...
juin 14 09:26:48 intranet fail2ban-client[764]: ERROR Failed during configuration: While reading from '/etc/fail2ban/jail.conf' [line 156]: option 'port' in section 'pam-generic' already exists
juin 14 09:26:48 intranet systemd[1]: fail2ban.service: Control process exited, code=exited status=255
juin 14 09:26:48 intranet systemd[1]: Failed to start Fail2Ban Service.
juin 14 09:26:48 intranet systemd[1]: fail2ban.service: Unit entered failed state.
juin 14 09:26:48 intranet systemd[1]: fail2ban.service: Failed with result 'exit-code'.
juin 14 09:26:48 intranet systemd[1]: fail2ban.service: Service hold-off time over, scheduling restart.
juin 14 09:26:48 intranet systemd[1]: Stopped Fail2Ban Service.
juin 14 09:26:48 intranet systemd[1]: fail2ban.service: Start request repeated too quickly.
juin 14 09:26:48 intranet systemd[1]: Failed to start Fail2Ban Service.
juin 14 09:26:48 intranet systemd[1]: fail2ban.service: Unit entered failed state.
juin 14 09:26:48 intranet systemd[1]: fail2ban.service: Failed with result 'exit-code'.
juin 14 09:28:08 intranet systemd[1]: Starting Fail2Ban Service...
juin 14 09:28:08 intranet fail2ban-client[863]: ERROR Failed during configuration: While reading from '/etc/fail2ban/jail.conf' [line 156]: option 'port' in section 'pam-generic' already exists
juin 14 09:28:08 intranet systemd[1]: fail2ban.service: Control process exited, code=exited status=255
juin 14 09:28:08 intranet systemd[1]: Failed to start Fail2Ban Service.
juin 14 09:28:08 intranet systemd[1]: fail2ban.service: Unit entered failed state.
juin 14 09:28:08 intranet systemd[1]: fail2ban.service: Failed with result 'exit-code'.
juin 14 09:28:08 intranet systemd[1]: fail2ban.service: Service hold-off time over, scheduling restart.
juin 14 09:28:08 intranet systemd[1]: Stopped Fail2Ban Service.
juin 14 09:28:08 intranet systemd[1]: Starting Fail2Ban Service...
juin 14 09:28:08 intranet fail2ban-client[883]: ERROR Failed during configuration: While reading from '/etc/fail2ban/jail.conf' [line 156]: option 'port' in section 'pam-generic' already exists
juin 14 09:28:08 intranet systemd[1]: fail2ban.service: Control process exited, code=exited status=255
juin 14 09:28:08 intranet systemd[1]: Failed to start Fail2Ban Service.
juin 14 09:28:08 intranet systemd[1]: fail2ban.service: Unit entered failed state.
juin 14 09:28:08 intranet systemd[1]: fail2ban.service: Failed with result 'exit-code'.
juin 14 09:28:08 intranet systemd[1]: fail2ban.service: Service hold-off time over, scheduling restart.
juin 14 09:28:08 intranet systemd[1]: Stopped Fail2Ban Service.
juin 14 09:28:08 intranet systemd[1]: Starting Fail2Ban Service...
juin 14 09:28:08 intranet fail2ban-client[885]: ERROR Failed during configuration: While reading from '/etc/fail2ban/jail.conf' [line 156]: option 'port' in section 'pam-generic' already exists
juin 14 09:28:08 intranet systemd[1]: fail2ban.service: Control process exited, code=exited status=255
juin 14 09:28:08 intranet systemd[1]: Failed to start Fail2Ban Service.
juin 14 09:28:08 intranet systemd[1]: fail2ban.service: Unit entered failed state.
juin 14 09:28:08 intranet systemd[1]: fail2ban.service: Failed with result 'exit-code'.
juin 14 09:28:09 intranet systemd[1]: fail2ban.service: Service hold-off time over, scheduling restart.
juin 14 09:28:09 intranet systemd[1]: Stopped Fail2Ban Service.
juin 14 09:28:09 intranet systemd[1]: Starting Fail2Ban Service...
juin 14 09:28:09 intranet fail2ban-client[887]: ERROR Failed during configuration: While reading from '/etc/fail2ban/jail.conf' [line 156]: option 'port' in section 'pam-generic' already exists
juin 14 09:28:09 intranet systemd[1]: fail2ban.service: Control process exited, code=exited status=255
juin 14 09:28:09 intranet systemd[1]: Failed to start Fail2Ban Service.
juin 14 09:28:09 intranet systemd[1]: fail2ban.service: Unit entered failed state.
juin 14 09:28:09 intranet systemd[1]: fail2ban.service: Failed with result 'exit-code'.
juin 14 09:28:09 intranet systemd[1]: fail2ban.service: Service hold-off time over, scheduling restart.
juin 14 09:28:09 intranet systemd[1]: Stopped Fail2Ban Service.
juin 14 09:28:09 intranet systemd[1]: Starting Fail2Ban Service...
juin 14 09:28:09 intranet fail2ban-client[889]: ERROR Failed during configuration: While reading from '/etc/fail2ban/jail.conf' [line 156]: option 'port' in section 'pam-generic' already exists
juin 14 09:28:09 intranet systemd[1]: fail2ban.service: Control process exited, code=exited status=255
juin 14 09:28:09 intranet systemd[1]: Failed to start Fail2Ban Service.
juin 14 09:28:09 intranet systemd[1]: fail2ban.service: Unit entered failed state.
juin 14 09:28:09 intranet systemd[1]: fail2ban.service: Failed with result 'exit-code'.
juin 14 09:28:09 intranet systemd[1]: fail2ban.service: Service hold-off time over, scheduling restart.
juin 14 09:28:09 intranet systemd[1]: Stopped Fail2Ban Service.
juin 14 09:28:09 intranet systemd[1]: fail2ban.service: Start request repeated too quickly.
juin 14 09:28:09 intranet systemd[1]: Failed to start Fail2Ban Service.
juin 14 09:28:09 intranet systemd[1]: fail2ban.service: Unit entered failed state.
juin 14 09:28:09 intranet systemd[1]: fail2ban.service: Failed with result 'exit-code'.
juin 14 09:32:15 intranet systemd[1]: Starting Fail2Ban Service...
juin 14 09:32:15 intranet fail2ban-client[944]: WARNING 'filter' not defined in 'sshd'. Using default one: ''
juin 14 09:32:15 intranet fail2ban-client[944]: WARNING No filter set for jail sshd
juin 14 09:32:15 intranet fail2ban-client[944]: WARNING 'filter' not defined in 'sshd'. Using default one: ''
juin 14 09:32:15 intranet fail2ban-client[944]: ERROR Failed during configuration: Bad value substitution: option 'action' in section 'sshd' contains an interpolation key 'port' which is not a valid option name. Raw value: '%(action_mwl)s'
juin 14 09:32:15 intranet systemd[1]: fail2ban.service: Control process exited, code=exited status=255
juin 14 09:32:15 intranet systemd[1]: Failed to start Fail2Ban Service.
juin 14 09:32:15 intranet systemd[1]: fail2ban.service: Unit entered failed state.
juin 14 09:32:15 intranet systemd[1]: fail2ban.service: Failed with result 'exit-code'.
juin 14 09:32:15 intranet systemd[1]: fail2ban.service: Service hold-off time over, scheduling restart.
juin 14 09:32:15 intranet systemd[1]: Stopped Fail2Ban Service.
juin 14 09:32:15 intranet systemd[1]: Starting Fail2Ban Service...
juin 14 09:32:15 intranet fail2ban-client[964]: WARNING 'filter' not defined in 'sshd'. Using default one: ''
juin 14 09:32:15 intranet fail2ban-client[964]: WARNING No filter set for jail sshd
juin 14 09:32:15 intranet fail2ban-client[964]: WARNING 'filter' not defined in 'sshd'. Using default one: ''
juin 14 09:32:15 intranet fail2ban-client[964]: ERROR Failed during configuration: Bad value substitution: option 'action' in section 'sshd' contains an interpolation key 'port' which is not a valid option name. Raw value: '%(action_mwl)s'
juin 14 09:32:15 intranet systemd[1]: fail2ban.service: Control process exited, code=exited status=255
juin 14 09:32:15 intranet systemd[1]: Failed to start Fail2Ban Service.
juin 14 09:32:15 intranet systemd[1]: fail2ban.service: Unit entered failed state.
juin 14 09:32:15 intranet systemd[1]: fail2ban.service: Failed with result 'exit-code'.
juin 14 09:32:16 intranet systemd[1]: fail2ban.service: Service hold-off time over, scheduling restart.
juin 14 09:32:16 intranet systemd[1]: Stopped Fail2Ban Service.
juin 14 09:32:16 intranet systemd[1]: Starting Fail2Ban Service...
juin 14 09:32:16 intranet fail2ban-client[967]: WARNING 'filter' not defined in 'sshd'. Using default one: ''
juin 14 09:32:16 intranet fail2ban-client[967]: WARNING No filter set for jail sshd
juin 14 09:32:16 intranet fail2ban-client[967]: WARNING 'filter' not defined in 'sshd'. Using default one: ''
juin 14 09:32:16 intranet fail2ban-client[967]: ERROR Failed during configuration: Bad value substitution: option 'action' in section 'sshd' contains an interpolation key 'port' which is not a valid option name. Raw value: '%(action_mwl)s'
juin 14 09:32:16 intranet systemd[1]: fail2ban.service: Control process exited, code=exited status=255
juin 14 09:32:16 intranet systemd[1]: Failed to start Fail2Ban Service.
juin 14 09:32:16 intranet systemd[1]: fail2ban.service: Unit entered failed state.
juin 14 09:32:16 intranet systemd[1]: fail2ban.service: Failed with result 'exit-code'.
juin 14 09:32:16 intranet systemd[1]: fail2ban.service: Service hold-off time over, scheduling restart.
juin 14 09:32:16 intranet systemd[1]: Stopped Fail2Ban Service.
juin 14 09:32:16 intranet systemd[1]: Starting Fail2Ban Service...
juin 14 09:32:16 intranet fail2ban-client[969]: WARNING 'filter' not defined in 'sshd'. Using default one: ''
juin 14 09:32:16 intranet fail2ban-client[969]: WARNING No filter set for jail sshd
juin 14 09:32:16 intranet fail2ban-client[969]: WARNING 'filter' not defined in 'sshd'. Using default one: ''
juin 14 09:32:16 intranet fail2ban-client[969]: ERROR Failed during configuration: Bad value substitution: option 'action' in section 'sshd' contains an interpolation key 'port' which is not a valid option name. Raw value: '%(action_mwl)s'
juin 14 09:32:16 intranet systemd[1]: fail2ban.service: Control process exited, code=exited status=255
juin 14 09:32:16 intranet systemd[1]: Failed to start Fail2Ban Service.
juin 14 09:32:16 intranet systemd[1]: fail2ban.service: Unit entered failed state.
juin 14 09:32:16 intranet systemd[1]: fail2ban.service: Failed with result 'exit-code'.
juin 14 09:32:16 intranet systemd[1]: fail2ban.service: Service hold-off time over, scheduling restart.
juin 14 09:32:16 intranet systemd[1]: Stopped Fail2Ban Service.
juin 14 09:32:16 intranet systemd[1]: Starting Fail2Ban Service...
juin 14 09:32:16 intranet fail2ban-client[971]: WARNING 'filter' not defined in 'sshd'. Using default one: ''
juin 14 09:32:16 intranet fail2ban-client[971]: WARNING No filter set for jail sshd
juin 14 09:32:16 intranet fail2ban-client[971]: WARNING 'filter' not defined in 'sshd'. Using default one: ''
juin 14 09:32:16 intranet fail2ban-client[971]: ERROR Failed during configuration: Bad value substitution: option 'action' in section 'sshd' contains an interpolation key 'port' which is not a valid option name. Raw value: '%(action_mwl)s'
juin 14 09:32:16 intranet systemd[1]: fail2ban.service: Control process exited, code=exited status=255
juin 14 09:32:16 intranet systemd[1]: Failed to start Fail2Ban Service.
juin 14 09:32:16 intranet systemd[1]: fail2ban.service: Unit entered failed state.
juin 14 09:32:16 intranet systemd[1]: fail2ban.service: Failed with result 'exit-code'.
juin 14 09:32:16 intranet systemd[1]: fail2ban.service: Service hold-off time over, scheduling restart.
juin 14 09:32:16 intranet systemd[1]: Stopped Fail2Ban Service.
juin 14 09:32:16 intranet systemd[1]: fail2ban.service: Start request repeated too quickly.
juin 14 09:32:16 intranet systemd[1]: Failed to start Fail2Ban Service.
juin 14 09:32:16 intranet systemd[1]: fail2ban.service: Unit entered failed state.
juin 14 09:32:16 intranet systemd[1]: fail2ban.service: Failed with result 'exit-code'.
J’ai donc édité /etc/fail2ban/jail.d/defaults-debian.conf et modifié comme suit:
[sshd]
port = port que j'utilise pour le ssh
maxentry = 3
puis suis allé au niveau de la ligne 156 de jail.conf (qui concerne un port) et l’ai aussi commenté.
j’ai egalement modifié mon fichier de conf comme indiqué dans ce post allemand:
https://translate.google.fr/translate?hl=fr&sl=de&u=https://www.taste-of-it.de/debian-upgrade-von-jessie-zu-stretch-fail2ban-error/&prev=search
Le redemarrage de fail2ban c’est alors bien passé et apache et ssh sont bien sous la protection de fail2ban.
voila le retour de iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destination
f2b-apache tcp -- anywhere anywhere multiport dports http,https
f2b-apache-overflows tcp -- anywhere anywhere multiport dports http,https
f2b-ssh tcp -- anywhere anywhere multiport dports ssh
Chain FORWARD (policy ACCEPT)
target prot opt source destination
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
Chain f2b-apache (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere
Chain f2b-apache-overflows (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere
Chain f2b-ssh (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere
Donc il y a vraiment pas mal de chose qui ont changé entre les deux versions de fail2ban
Par contre au niveau du port ssh, comme il n’est pas sur le 22, j’espere que fail2ban le protege bien quand même