Applicable to:
- Plesk for Linux
Symptoms
- An IP address listed in Tools & Settings > IP Address Banning (Fail2Ban) > Trusted IP Addresses (or in the output of
plesk bin ip_ban --trusted) is banned by Fail2Ban. - The IP is banned in the
plesk-one-week-banjail. -
/var/log/fail2ban.logshows aBanline, followed milliseconds later by a recidiveIgnoreline for the same IP:CONFIG_TEXT: fail2ban.actions [3386747]: NOTICE [plesk-one-week-ban] Ban 203.0.113.2
fail2ban.filter [3386747]: INFO [recidive] Ignore 203.0.113.2 by ip
Cause
The plesk-one-week-ban jail only holds IP addresses that were banned manually for one week. It has no filter of its own, so every ban in it comes from a manual ban command.
The trusted list (ignoreip) only applies to bans that a jail creates itself from log matches. If the IP is banned directly with fail2ban-client, for example:
# fail2ban-client set plesk-one-week-ban banip 203.0.113.2
Then the trusted list is not checked, and the IP is banned even though it is trusted. The recidive jail then logs Ignore ... by ip when it sees the Ban line, which shows that the IP is recognized as trusted.
plesk bin ip_ban --ban does check the trusted list. It refuses to ban a trusted IP and returns the error below, before sending anything to Fail2Ban:
# plesk bin ip_ban --ban 203.0.113.2,plesk-one-week-ban
IP addresses on the list must not be trusted IP addresses.
Resolution
Ban and unban IP addresses with the documented plesk bin ip_ban utility instead of fail2ban-client. Plesk utility checks the trusted list before banning and rejects trusted IPs.
- Connect to the server via SSH.
-
Ban an IP in the one-week jail:
# plesk bin ip_ban --ban 198.51.100.7,plesk-one-week-ban
-
Unban an IP:
# plesk bin ip_ban --unban 198.51.100.7,plesk-one-week-ban
-
Unban any trusted IP that was already banned with
fail2ban-client:# plesk bin ip_ban --unban 203.0.113.2,plesk-one-week-ban
- If a script calls
fail2ban-client set <jail> banip, change it to useplesk bin ip_ban --ban.
Comments
Please sign in to leave a comment.