|
Cutting down on the iptables output is not too helpful as you lose
the names of the chains that the rules belong to, but in this case
you are missing something with a "-p tcp -m multiport --dports
80,443 -j dynamic" Mine would go in the INPUT chain but yours may be
different. I'm also not convinced about using the "dynamic" chain. Normally it would be an "f2b-apache-noscript" chain as you should use a separate chain for each jail. Can you restart f2b and look for errors setting up the -j rules and the f2b chains? On my system (ClearOS) a firewall restart wipes all the f2b rules so I have to do some extra manipulation to re-add them on each restart. On 28/11/2018 08:39, Koenraad Lelong
wrote:
|
_______________________________________________ Fail2ban-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/fail2ban-users
