Articles in this section

Trusted IP address is banned in Fail2Ban

Applicable to:

  • Plesk for Linux

Symptoms

  • An IP address listed in Tools & Settings > IP Address Banning (Fail2Ban) > Trusted IP Addresses (or in the output of plesk bin ip_ban --trusted) is banned by Fail2Ban.
  • The IP is banned in the plesk-one-week-ban jail.
  • /var/log/fail2ban.log shows a Ban line, followed milliseconds later by a recidive Ignore line for the same IP:

    CONFIG_TEXT: fail2ban.actions [3386747]: NOTICE [plesk-one-week-ban] Ban 203.0.113.2
    fail2ban.filter [3386747]: INFO [recidive] Ignore 203.0.113.2 by ip

Cause

The plesk-one-week-ban jail only holds IP addresses that were banned manually for one week. It has no filter of its own, so every ban in it comes from a manual ban command.

The trusted list (ignoreip) only applies to bans that a jail creates itself from log matches. If the IP is banned directly with fail2ban-client, for example:

# fail2ban-client set plesk-one-week-ban banip 203.0.113.2

Then the trusted list is not checked, and the IP is banned even though it is trusted. The recidive jail then logs Ignore ... by ip when it sees the Ban line, which shows that the IP is recognized as trusted.

plesk bin ip_ban --ban does check the trusted list. It refuses to ban a trusted IP and returns the error below, before sending anything to Fail2Ban:

# plesk bin ip_ban --ban 203.0.113.2,plesk-one-week-ban
IP addresses on the list must not be trusted IP addresses.

Resolution

Ban and unban IP addresses with the documented plesk bin ip_ban utility instead of fail2ban-client. Plesk utility checks the trusted list before banning and rejects trusted IPs.

  1. Connect to the server via SSH.
  2. Ban an IP in the one-week jail:

    # plesk bin ip_ban --ban 198.51.100.7,plesk-one-week-ban

  3. Unban an IP:

    # plesk bin ip_ban --unban 198.51.100.7,plesk-one-week-ban

  4. Unban any trusted IP that was already banned with fail2ban-client:

    # plesk bin ip_ban --unban 203.0.113.2,plesk-one-week-ban

  5. If a script calls fail2ban-client set <jail> banip, change it to use plesk bin ip_ban --ban.
Was this article helpful?

Comments

0 comments

Please sign in to leave a comment.