I got fail2ban running according to the settings in the wiki. And everything seems to be working after a few tweaks.
But today I encountered a lot of entries in the "mail.warn" log file (see below - changed the IP by xxx). How do I effectively close for this?
Mar 26 20:06:59 host1 postfix/smtpd[5723]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:06:59 host1 postfix/smtpd[5723]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:06:59 host1 postfix/smtpd[5723]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:06:59 host1 postfix/smtpd[5723]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:00 host1 postfix/smtpd[5723]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:00 host1 postfix/smtpd[5723]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:00 host1 postfix/smtpd[5723]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:00 host1 postfix/smtpd[5723]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:01 host1 postfix/smtpd[5723]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:01 host1 postfix/smtpd[5723]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:01 host1 postfix/smtpd[5723]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:01 host1 postfix/smtpd[5724]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:01 host1 postfix/smtpd[5724]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:02 host1 postfix/smtpd[5724]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:02 host1 postfix/smtpd[5724]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:02 host1 postfix/smtpd[5724]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:02 host1 postfix/smtpd[5724]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:02 host1 postfix/smtpd[5724]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:03 host1 postfix/smtpd[5724]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:03 host1 postfix/smtpd[5724]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:03 host1 postfix/smtpd[5724]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:03 host1 postfix/smtpd[5724]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:03 host1 postfix/smtpd[5724]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:04 host1 postfix/smtpd[5724]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:04 host1 postfix/smtpd[5724]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:04 host1 postfix/smtpd[5724]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
Mar 26 20:07:04 host1 postfix/smtpd[5724]: warning: unknown[xxx.xxx.xxx.xxx]: SASL LOGIN authentication failed: authentication failure
It seem to take up a lot of resources (CPU) and (Disk I/O utilization), so it would be nice to get this banned.
Michael