salut, de mon coté je n'ai plus le meme résultat depuis plusieurs jours. soit la mise a jour du DSM 7.2.1-69057 Update 5 ( DS920+ ) iptables v1.8.10
soit la maj de crazymax/fail2ban. crazymax/fail2ban:1.1.0
j'ai tout retourné dans tout les sens ... impossible de regler le probleme pour le moment, cela fonctionnais bien avant
2024/05/04 22:19:23 stdout 2024-05-04 20:19:23,678 fail2ban.actions [1]: ERROR Failed to execute ban jail 'vaultwarden' action 'iptables-allports' info 'ActionInfo({'ip': 'XX.XX.XX.XX', 'family': 'inet4', 'fid': <function Actions.ActionInfo.<lambda> at 0x7fd7e3965d00>, 'raw-ticket': <function Actions.ActionInfo.<lambda> at 0x7fd7e3966480>})': Error starting action Jail('vaultwarden')/iptables-allports: 'Script error'
2024/05/04 22:19:23 stdout 2024-05-04 20:19:23,677 fail2ban.utils [1]: ERROR 7fd7e39cd6b0 -- returned 4
2024/05/04 22:19:23 stdout 2024-05-04 20:19:23,677 fail2ban.utils [1]: ERROR 7fd7e39cd6b0 -- stderr: 'iptables v1.8.10 (nf_tables): Could not fetch rule set generation id: Invalid argument'
2024/05/04 22:19:23 stdout 2024-05-04 20:19:23,677 fail2ban.utils [1]: ERROR 7fd7e39cd6b0 -- stderr: 'iptables v1.8.10 (nf_tables): Could not fetch rule set generation id: Invalid argument'
2024/05/04 22:19:23 stdout 2024-05-04 20:19:23,677 fail2ban.utils [1]: ERROR 7fd7e39cd6b0 -- stderr: 'iptables v1.8.10 (nf_tables): Could not fetch rule set generation id: Invalid argument'
2024/05/04 22:19:23 stdout done
2024/05/04 22:19:23 stdout { iptables -w -C INPUT -p $proto -j f2b-vaultwarden >/dev/null 2>&1; } || { iptables -w -I INPUT -p $proto -j f2b-vaultwarden; }
2024/05/04 22:19:23 stdout for proto in $(echo 'tcp' | sed 's/,/ /g'); do
2024/05/04 22:19:23 stdout 2024-05-04 20:19:23,677 fail2ban.utils [1]: ERROR 7fd7e39cd6b0 -- exec: { iptables -w -C f2b-vaultwarden -j RETURN >/dev/null 2>&1; } || { iptables -w -N f2b-vaultwarden || true; iptables -w -A f2b-vaultwarden -j RETURN; }
2024/05/04 22:19:23 stdout 2024-05-04 20:19:23,662 fail2ban.actions [1]: NOTICE [vaultwarden] Restore Ban XX.XX.XX.XX
2024/05/04 22:19:23 stdout 2024-05-04 20:19:23,579 fail2ban.actions [1]: ERROR Failed to execute ban jail 'vaultwarden-admin' action 'iptables-allports' info 'ActionInfo({'ip': 'XX.XX.XX.XX', 'family': 'inet4', 'fid': <function Actions.ActionInfo.<lambda> at 0x7fd7e3965d00>, 'raw-ticket': <function Actions.ActionInfo.<lambda> at 0x7fd7e3966480>})': Error starting action Jail('vaultwarden-admin')/iptables-allports: 'Script error'
2024/05/04 22:19:23 stdout 2024-05-04 20:19:23,579 fail2ban.utils [1]: ERROR 7fd7e3224370 -- returned 4
2024/05/04 22:19:23 stdout 2024-05-04 20:19:23,579 fail2ban.utils [1]: ERROR 7fd7e3224370 -- stderr: 'iptables v1.8.10 (nf_tables): Could not fetch rule set generation id: Invalid argument'
2024/05/04 22:19:23 stdout 2024-05-04 20:19:23,579 fail2ban.utils [1]: ERROR 7fd7e3224370 -- stderr: 'iptables v1.8.10 (nf_tables): Could not fetch rule set generation id: Invalid argument'
2024/05/04 22:19:23 stdout 2024-05-04 20:19:23,579 fail2ban.utils [1]: ERROR 7fd7e3224370 -- stderr: 'iptables v1.8.10 (nf_tables): Could not fetch rule set generation id: Invalid argument'
2024/05/04 22:19:23 stdout done
2024/05/04 22:19:23 stdout { iptables -w -C INPUT -p $proto -j f2b-vaultwarden-admin >/dev/null 2>&1; } || { iptables -w -I INPUT -p $proto -j f2b-vaultwarden-admin; }
2024/05/04 22:19:23 stdout for proto in $(echo 'tcp' | sed 's/,/ /g'); do
2024/05/04 22:19:23 stdout 2024-05-04 20:19:23,579 fail2ban.utils [1]: ERROR 7fd7e3224370 -- exec: { iptables -w -C f2b-vaultwarden-admin -j RETURN >/dev/null 2>&1; } || { iptables -w -N f2b-vaultwarden-admin || true; iptables -w -A f2b-vaultwarden-admin -j RETURN; }
2024/05/04 22:19:23 stdout 2024-05-04 20:19:23,564 fail2ban.actions [1]: ERROR Failed to execute ban jail 'vaultwarden-admin' action 'iptables-allports' info 'ActionInfo({'ip': 'XX.XX.XX.XX', 'family': 'inet4', 'fid': <function Actions.ActionInfo.<lambda> at 0x7fd7e3965d00>, 'raw-ticket': <function Actions.ActionInfo.<lambda> at 0x7fd7e3966480>})': Error starting action Jail('vaultwarden-admin')/iptables-allports: 'Script error'
2024/05/04 22:19:23 stdout 2024-05-04 20:19:23,563 fail2ban.utils [1]: ERROR 7fd7e3224370 -- returned 4
2024/05/04 22:19:23 stdout 2024-05-04 20:19:23,563 fail2ban.utils [1]: ERROR 7fd7e3224370 -- stderr: 'iptables v1.8.10 (nf_tables): Could not fetch rule set generation id: Invalid argument'
2024/05/04 22:19:23 stdout 2024-05-04 20:19:23,563 fail2ban.utils [1]: ERROR 7fd7e3224370 -- stderr: 'iptables v1.8.10 (nf_tables): Could not fetch rule set generation id: Invalid argument'
2024/05/04 22:19:23 stdout 2024-05-04 20:19:23,563 fail2ban.utils [1]: ERROR 7fd7e3224370 -- stderr: 'iptables v1.8.10 (nf_tables): Could not fetch rule set generation id: Invalid argument'
vaultwarden.conf de jail.d
[DEFAULT]
ignoreip = 172.0.0.1/8 192.168.10.0/24 10.6.0.0/24
#Ban for 1 day
bantime = 86400
destemail = xxxxxxxxx@gmail.com
sender = fail2ban@host.com(hostname -f)
#findtime for 4h
findtime = 14400
maxretry = 3
backend = auto
banaction = iptables-allports
action = iptables-allports[name=vaultwarden]
[vaultwarden]
enabled = true
port = 80,6603,443,
filter = vaultwarden
logpath = /logs/vaultwarden.log
vaultwarden.conf de filter.d
[INCLUDES]
before = common.conf
[Definition]
failregex = ^.*Username or password is incorrect\. Try again\. IP: <ADDR>\. Username:.*$
ignoreregex =