[Dovecot] fail2ban

Oscar del Rio delrio at mie.utoronto.ca
Sat Oct 5 16:55:41 EEST 2013


On 04/10/2013 1:47 AM, Nick Edwards wrote:
> filter.d/dovecot.conf
> [Definition]
> failregex = (?: pop3-login|imap-login): (?:Authentication
> failure|Aborted login \(auth failed|Aborted login \(tried to use
> disabled|Disconnected \(auth failed).*rip=(?P<host>\S*),.*
> ignoreregex =

The following is included with fail2ban 0.8.10

filters.d/dovecot.conf

# Fail2Ban configuration file for dovcot
#
# Author: Martin Waschbuesch
#
#

[Definition]

# Option:  failregex
# Notes.:  regex to match the password failures messages in the logfile. The
#          host must be matched by a group named "host". The tag 
"<HOST>" can
#          be used for standard IP/hostname matching and is only an 
alias for
#          (?:::f{4,6}:)?(?P<host>[\w\-.^_]+)
# Values:  TEXT
#
failregex = .*(?:pop3-login|imap-login):.*(?:Authentication 
failure|Aborted login \(auth failed|Aborted login \(tried to use 
disabled|Disconnected \(auth failed).*\s+rip=(?P<host>\S*),.*
             pam.*dovecot.*(?:authentication 
failure).*\s+rhost=<HOST>(?:\s+user=.*)?\s*$

# Option:  ignoreregex
# Notes.:  regex to ignore. If this regex matches, the line is ignored.
# Values:  TEXT
#
ignoreregex =



More information about the dovecot mailing list