Bonjour,
Suite à différents sujets, je regarde les logs ce matin 
Voila ce que je trouve sur auth.log :
Mar 17 07:52:30 mx sshd[18181]: Did not receive identification string from 95.81.203.81
Mar 17 07:52:31 mx sshd[18182]: reverse mapping checking getaddrinfo for 081.203.81.95.chtts.ru [95.81.203.81] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 17 07:52:31 mx sshd[18182]: Failed password for root from 95.81.203.81 port 3997 ssh2
Mar 17 07:52:32 mx sshd[18186]: reverse mapping checking getaddrinfo for 081.203.81.95.chtts.ru [95.81.203.81] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 17 07:52:32 mx sshd[18186]: Failed password for root from 95.81.203.81 port 4023 ssh2
Mar 17 07:52:33 mx sshd[18190]: reverse mapping checking getaddrinfo for 081.203.81.95.chtts.ru [95.81.203.81] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 17 07:52:33 mx sshd[18190]: Failed password for root from 95.81.203.81 port 4041 ssh2
Mar 17 07:52:34 mx sshd[18194]: reverse mapping checking getaddrinfo for 081.203.81.95.chtts.ru [95.81.203.81] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 17 07:52:34 mx sshd[18194]: Failed password for root from 95.81.203.81 port 4064 ssh2
Mar 17 07:52:35 mx sshd[18198]: reverse mapping checking getaddrinfo for 081.203.81.95.chtts.ru [95.81.203.81] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 17 07:52:35 mx sshd[18198]: Failed password for root from 95.81.203.81 port 4086 ssh2
Mar 17 07:52:36 mx sshd[18202]: reverse mapping checking getaddrinfo for 081.203.81.95.chtts.ru [95.81.203.81] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 17 07:52:36 mx sshd[18202]: Failed password for root from 95.81.203.81 port 4115 ssh2
Mar 17 07:52:37 mx sshd[18206]: reverse mapping checking getaddrinfo for 081.203.81.95.chtts.ru [95.81.203.81] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 17 07:52:37 mx sshd[18206]: Failed password for root from 95.81.203.81 port 4138 ssh2
Clairement, il y a un test de connexion en ssh à mon serveur depuis un ordinateur russe, je vais voir dans fail2ban.log, et là :
2010-03-17 07:52:37,342 fail2ban.actions: WARNING [ssh] Ban 95.81.203.81
2010-03-17 08:02:37,358 fail2ban.actions: WARNING [ssh] Unban 95.81.203.81
Dois-je en conclure que fail2ban s’est rendu compte que le serveur russe était un peut trop insistant, donc l’a banni une première fois, puis dix minutes après la dernière tentative, l’a de nouveau autorisé ? Si c’est le cas ne pourrait-on pas changer cette valeur à 24 Heures ?

