Anonymous | Login | 2024-12-21 23:41 MST |
Main | My View | View Issues | Change Log | Roadmap | Repositories |
View Issue Details [ Jump to Notes ] | [ Issue History ] [ Print ] | ||||||||
ID | Project | Category | View Status | Date Submitted | Last Update | ||||
0015701 | ClearOS | app-attack-detector - Attack Detector | public | 2017-07-12 08:39 | 2021-11-09 05:39 | ||||
Reporter | user2 | ||||||||
Assigned To | |||||||||
Priority | normal | Severity | minor | Reproducibility | have not tried | ||||
Status | closed | Resolution | won't fix | ||||||
Platform | OS | OS Version | |||||||
Product Version | 7.3.1 | ||||||||
Target Version | Fixed in Version | ||||||||
Summary | 0015701: Tidy up if fail2ban is stopped | ||||||||
Description | If fail2ban is stopped, it should tidy up any existing rules or at least remove the firewall hook. As it stands, the rules will stay in place until the firewall is restarted. Note: fail2ban takes a looong time to regenerate rules, so it would be good to differentiate between a "stop" and a "restart" (which is often coded as a "stop / start"). | ||||||||
Tags | No tags attached. | ||||||||
Attached Files | firewall.txt [^] (11,612 bytes) 2017-07-13 13:02 [Show Content] [Hide Content]Chain INPUT (policy DROP 2606 packets, 235K bytes) pkts bytes target prot opt in out source destination 81099 8092K f2b-apache-404 tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 80,443 55509 65M f2b-postfix-disc tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 25,465,587 52975 64M f2b-postfix-relay tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 25,465,587 404K 103M f2b-cyrus-imap tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 143,993 237K 80M f2b-postfix-sasl tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 25,465,587,220,993,110,995 52883 64M f2b-postfix tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 25,465,587 80930 8083K f2b-apache-nohome tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 80,443 0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:1195 6812 555K DROP all -- * * 0.0.0.0/0 0.0.0.0/0 match-set custom-block src state NEW 2799 686K DROP udp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 match-set country-list src udp dpt:!51413 state NEW 30978 1658K DROP tcp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 match-set country-list src multiport dports !25,80,443,1875 state NEW 2985K 463M IPSET_BLK udp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW multiport dports !1194,51413 293K 18M IPSET_BLK tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:!25 34811 2646K ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:123 state RELATED,ESTABLISHED 4565 556K ACCEPT udp -- enp2s0 * 92.16.0.0/12 0.0.0.0/0 udp dpt:500 0 0 ACCEPT udp -- enp2s0 * 89.240.0.0/14 0.0.0.0/0 udp dpt:500 0 0 ACCEPT udp -- enp2s0 * 88.104.0.0/13 0.0.0.0/0 udp dpt:500 0 0 ACCEPT udp -- enp2s0 * 84.13.0.0/16 0.0.0.0/0 udp dpt:500 36885 4490K ACCEPT udp -- enp2s0 * 79.64.0.0/12 0.0.0.0/0 udp dpt:500 22133 2694K ACCEPT udp -- enp2s0 * 78.144.0.0/13 0.0.0.0/0 udp dpt:500 92 38192 DROP udp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 udp dpt:500 48312 2428K DROP all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID 0 0 REJECT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x12/0x12 state NEW reject-with tcp-reset 6528 507K DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:!0x17/0x02 state NEW 0 0 DROP all -- enp2s0 * 127.0.0.0/8 0.0.0.0/0 2 180 DROP all -- enp2s0 * 169.254.0.0/16 0.0.0.0/0 5105K 1292M ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0 0 0 ACCEPT all -- pptp+ * 0.0.0.0/0 0.0.0.0/0 2984K 171M ACCEPT all -- tun+ * 0.0.0.0/0 0.0.0.0/0 12M 16G ACCEPT all -- enp5s0 * 0.0.0.0/0 0.0.0.0/0 15755 460K ACCEPT icmp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 icmptype 0 152K 12M ACCEPT icmp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 icmptype 3 50485 1837K ACCEPT icmp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 icmptype 8 145 13506 ACCEPT icmp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 icmptype 11 3 1041 ACCEPT udp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 udp spt:67 dpt:68 0 0 ACCEPT tcp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 tcp spt:67 dpt:68 2483 4526K ACCEPT tcp -- * * 0.0.0.0/0 82.19.158.192 tcp dpt:1875 27905 3237K ACCEPT tcp -- * * 0.0.0.0/0 82.19.158.192 tcp dpt:80 30605 3456K ACCEPT tcp -- * * 0.0.0.0/0 82.19.158.192 tcp dpt:443 50283 4602K ACCEPT tcp -- * * 0.0.0.0/0 82.19.158.192 tcp dpt:993 3232K 471M ACCEPT udp -- * * 0.0.0.0/0 82.19.158.192 udp dpt:1194 44467 46M ACCEPT tcp -- * * 0.0.0.0/0 82.19.158.192 tcp dpt:25 80 10979 ACCEPT tcp -- * * 0.0.0.0/0 82.19.158.192 tcp dpt:587 0 0 ACCEPT tcp -- * * 0.0.0.0/0 82.19.158.192 tcp dpt:51413 7695K 991M ACCEPT udp -- * * 0.0.0.0/0 82.19.158.192 udp dpt:51413 0 0 ACCEPT udp -- * * 0.0.0.0/0 82.19.158.192 udp spt:500 dpt:500 3942 559K ACCEPT esp -- * * 0.0.0.0/0 82.19.158.192 0 0 ACCEPT ah -- * * 0.0.0.0/0 82.19.158.192 0 0 ACCEPT all -- * * 0.0.0.0/0 82.19.158.192 mark match 0x64 0 0 ACCEPT all -- * * 0.0.0.0/0 172.17.2.1 mark match 0x64 890K 319M ACCEPT udp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 udp dpts:1024:65535 state RELATED,ESTABLISHED 610K 1102M ACCEPT tcp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 tcp dpts:1024:65535 state RELATED,ESTABLISHED Chain FORWARD (policy DROP 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 321K 28M IPSET_BLK all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0x64 69M 116G MINIUPNPD all -- enp2s0 !enp2s0 0.0.0.0/0 0.0.0.0/0 115M 122G ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED 0 0 ACCEPT all -- pptp+ * 0.0.0.0/0 0.0.0.0/0 17 1020 ACCEPT all -- tun+ * 0.0.0.0/0 0.0.0.0/0 388K 32M ACCEPT all -- enp5s0 * 0.0.0.0/0 0.0.0.0/0 Chain OUTPUT (policy DROP 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 2735K 433M IPSET_BLK udp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:!53 167K 10M IPSET_BLK tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW multiport dports !25,53 5125K 1293M ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0 0 0 ACCEPT all -- * pptp+ 0.0.0.0/0 0.0.0.0/0 2961K 7328M ACCEPT all -- * tun+ 0.0.0.0/0 0.0.0.0/0 9225K 12G ACCEPT all -- * enp5s0 0.0.0.0/0 0.0.0.0/0 127K 11M ACCEPT icmp -- * enp2s0 0.0.0.0/0 0.0.0.0/0 3 984 ACCEPT udp -- * enp2s0 0.0.0.0/0 0.0.0.0/0 udp spt:68 dpt:67 0 0 ACCEPT tcp -- * enp2s0 0.0.0.0/0 0.0.0.0/0 tcp spt:68 dpt:67 1567 492K ACCEPT tcp -- * enp2s0 82.19.158.192 0.0.0.0/0 tcp spt:1875 26685 47M ACCEPT tcp -- * enp2s0 82.19.158.192 0.0.0.0/0 tcp spt:80 29336 53M ACCEPT tcp -- * enp2s0 82.19.158.192 0.0.0.0/0 tcp spt:443 48983 12M ACCEPT tcp -- * enp2s0 82.19.158.192 0.0.0.0/0 tcp spt:993 5641K 7901M ACCEPT udp -- * enp2s0 82.19.158.192 0.0.0.0/0 udp spt:1194 40806 4232K ACCEPT tcp -- * enp2s0 82.19.158.192 0.0.0.0/0 tcp spt:25 91 20441 ACCEPT tcp -- * enp2s0 82.19.158.192 0.0.0.0/0 tcp spt:587 0 0 ACCEPT tcp -- * enp2s0 82.19.158.192 0.0.0.0/0 tcp spt:51413 7716K 2105M ACCEPT udp -- * enp2s0 82.19.158.192 0.0.0.0/0 udp spt:51413 63592 7750K ACCEPT udp -- * enp2s0 82.19.158.192 0.0.0.0/0 udp spt:500 dpt:500 0 0 ACCEPT esp -- * enp2s0 82.19.158.192 0.0.0.0/0 0 0 ACCEPT ah -- * enp2s0 82.19.158.192 0.0.0.0/0 1871K 161M ACCEPT all -- * enp2s0 0.0.0.0/0 0.0.0.0/0 Chain DROP-lan (0 references) pkts bytes target prot opt in out source destination 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 Chain IPSET_BLK (5 references) pkts bytes target prot opt in out source destination 61 4688 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 match-set blacklist dst 769 58912 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 match-set blacklist src Chain MINIUPNPD (1 references) pkts bytes target prot opt in out source destination Chain f2b-apache-404 (1 references) pkts bytes target prot opt in out source destination Chain f2b-apache-nohome (1 references) pkts bytes target prot opt in out source destination 0 0 DROP all -- * * 36.248.96.186 0.0.0.0/0 4 240 DROP all -- * * 212.237.60.47 0.0.0.0/0 8 416 DROP all -- * * 75.138.88.200 0.0.0.0/0 3 152 DROP all -- * * 142.54.177.2 0.0.0.0/0 17 1576 DROP all -- * * 177.141.159.120 0.0.0.0/0 18 752 DROP all -- * * 103.237.3.172 0.0.0.0/0 1 48 DROP all -- * * 190.248.153.234 0.0.0.0/0 12 720 DROP all -- * * 46.45.181.120 0.0.0.0/0 Chain f2b-cyrus-imap (1 references) pkts bytes target prot opt in out source destination 21 1491 DROP all -- * * 91.187.93.52 0.0.0.0/0 Chain f2b-postfix (1 references) pkts bytes target prot opt in out source destination Chain f2b-postfix-disc (1 references) pkts bytes target prot opt in out source destination 33 1608 DROP all -- * * 89.147.210.206 0.0.0.0/0 Chain f2b-postfix-relay (1 references) pkts bytes target prot opt in out source destination 0 0 DROP all -- * * 1.160.53.50 0.0.0.0/0 Chain f2b-postfix-sasl (1 references) pkts bytes target prot opt in out source destination firewall1.txt [^] (8,835 bytes) 2017-07-13 13:03 [Show Content] [Hide Content] Chain INPUT (policy DROP 5 packets, 318 bytes) pkts bytes target prot opt in out source destination 0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:1195 6812 555K DROP all -- * * 0.0.0.0/0 0.0.0.0/0 match-set custom-block src state NEW 2799 686K DROP udp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 match-set country-list src udp dpt:!51413 state NEW 30978 1658K DROP tcp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 match-set country-list src multiport dports !25,80,443,1875 state NEW 2985K 463M IPSET_BLK udp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW multiport dports !1194,51413 293K 18M IPSET_BLK tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:!25 34813 2646K ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:123 state RELATED,ESTABLISHED 4565 556K ACCEPT udp -- enp2s0 * 92.16.0.0/12 0.0.0.0/0 udp dpt:500 0 0 ACCEPT udp -- enp2s0 * 89.240.0.0/14 0.0.0.0/0 udp dpt:500 0 0 ACCEPT udp -- enp2s0 * 88.104.0.0/13 0.0.0.0/0 udp dpt:500 0 0 ACCEPT udp -- enp2s0 * 84.13.0.0/16 0.0.0.0/0 udp dpt:500 36887 4490K ACCEPT udp -- enp2s0 * 79.64.0.0/12 0.0.0.0/0 udp dpt:500 22133 2694K ACCEPT udp -- enp2s0 * 78.144.0.0/13 0.0.0.0/0 udp dpt:500 92 38192 DROP udp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 udp dpt:500 48312 2428K DROP all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID 0 0 REJECT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x12/0x12 state NEW reject-with tcp-reset 6528 507K DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:!0x17/0x02 state NEW 0 0 DROP all -- enp2s0 * 127.0.0.0/8 0.0.0.0/0 2 180 DROP all -- enp2s0 * 169.254.0.0/16 0.0.0.0/0 5105K 1292M ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0 0 0 ACCEPT all -- pptp+ * 0.0.0.0/0 0.0.0.0/0 2984K 171M ACCEPT all -- tun+ * 0.0.0.0/0 0.0.0.0/0 12M 16G ACCEPT all -- enp5s0 * 0.0.0.0/0 0.0.0.0/0 15755 460K ACCEPT icmp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 icmptype 0 152K 12M ACCEPT icmp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 icmptype 3 50485 1837K ACCEPT icmp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 icmptype 8 145 13506 ACCEPT icmp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 icmptype 11 3 1041 ACCEPT udp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 udp spt:67 dpt:68 0 0 ACCEPT tcp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 tcp spt:67 dpt:68 2483 4526K ACCEPT tcp -- * * 0.0.0.0/0 82.19.158.192 tcp dpt:1875 27905 3237K ACCEPT tcp -- * * 0.0.0.0/0 82.19.158.192 tcp dpt:80 30605 3456K ACCEPT tcp -- * * 0.0.0.0/0 82.19.158.192 tcp dpt:443 50283 4602K ACCEPT tcp -- * * 0.0.0.0/0 82.19.158.192 tcp dpt:993 3232K 471M ACCEPT udp -- * * 0.0.0.0/0 82.19.158.192 udp dpt:1194 44467 46M ACCEPT tcp -- * * 0.0.0.0/0 82.19.158.192 tcp dpt:25 80 10979 ACCEPT tcp -- * * 0.0.0.0/0 82.19.158.192 tcp dpt:587 0 0 ACCEPT tcp -- * * 0.0.0.0/0 82.19.158.192 tcp dpt:51413 7695K 991M ACCEPT udp -- * * 0.0.0.0/0 82.19.158.192 udp dpt:51413 0 0 ACCEPT udp -- * * 0.0.0.0/0 82.19.158.192 udp spt:500 dpt:500 3942 559K ACCEPT esp -- * * 0.0.0.0/0 82.19.158.192 0 0 ACCEPT ah -- * * 0.0.0.0/0 82.19.158.192 0 0 ACCEPT all -- * * 0.0.0.0/0 82.19.158.192 mark match 0x64 0 0 ACCEPT all -- * * 0.0.0.0/0 172.17.2.1 mark match 0x64 890K 319M ACCEPT udp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 udp dpts:1024:65535 state RELATED,ESTABLISHED 610K 1102M ACCEPT tcp -- enp2s0 * 0.0.0.0/0 0.0.0.0/0 tcp dpts:1024:65535 state RELATED,ESTABLISHED Chain FORWARD (policy DROP 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 321K 28M IPSET_BLK all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0x64 69M 116G MINIUPNPD all -- enp2s0 !enp2s0 0.0.0.0/0 0.0.0.0/0 115M 122G ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED 0 0 ACCEPT all -- pptp+ * 0.0.0.0/0 0.0.0.0/0 17 1020 ACCEPT all -- tun+ * 0.0.0.0/0 0.0.0.0/0 388K 32M ACCEPT all -- enp5s0 * 0.0.0.0/0 0.0.0.0/0 Chain OUTPUT (policy DROP 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 2735K 433M IPSET_BLK udp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:!53 167K 10M IPSET_BLK tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW multiport dports !25,53 5126K 1293M ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0 0 0 ACCEPT all -- * pptp+ 0.0.0.0/0 0.0.0.0/0 2961K 7328M ACCEPT all -- * tun+ 0.0.0.0/0 0.0.0.0/0 9227K 12G ACCEPT all -- * enp5s0 0.0.0.0/0 0.0.0.0/0 127K 11M ACCEPT icmp -- * enp2s0 0.0.0.0/0 0.0.0.0/0 3 984 ACCEPT udp -- * enp2s0 0.0.0.0/0 0.0.0.0/0 udp spt:68 dpt:67 0 0 ACCEPT tcp -- * enp2s0 0.0.0.0/0 0.0.0.0/0 tcp spt:68 dpt:67 1567 492K ACCEPT tcp -- * enp2s0 82.19.158.192 0.0.0.0/0 tcp spt:1875 26685 47M ACCEPT tcp -- * enp2s0 82.19.158.192 0.0.0.0/0 tcp spt:80 29336 53M ACCEPT tcp -- * enp2s0 82.19.158.192 0.0.0.0/0 tcp spt:443 48983 12M ACCEPT tcp -- * enp2s0 82.19.158.192 0.0.0.0/0 tcp spt:993 5641K 7901M ACCEPT udp -- * enp2s0 82.19.158.192 0.0.0.0/0 udp spt:1194 40806 4232K ACCEPT tcp -- * enp2s0 82.19.158.192 0.0.0.0/0 tcp spt:25 91 20441 ACCEPT tcp -- * enp2s0 82.19.158.192 0.0.0.0/0 tcp spt:587 0 0 ACCEPT tcp -- * enp2s0 82.19.158.192 0.0.0.0/0 tcp spt:51413 7716K 2105M ACCEPT udp -- * enp2s0 82.19.158.192 0.0.0.0/0 udp spt:51413 63594 7750K ACCEPT udp -- * enp2s0 82.19.158.192 0.0.0.0/0 udp spt:500 dpt:500 0 0 ACCEPT esp -- * enp2s0 82.19.158.192 0.0.0.0/0 0 0 ACCEPT ah -- * enp2s0 82.19.158.192 0.0.0.0/0 1871K 161M ACCEPT all -- * enp2s0 0.0.0.0/0 0.0.0.0/0 Chain DROP-lan (0 references) pkts bytes target prot opt in out source destination 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 Chain IPSET_BLK (5 references) pkts bytes target prot opt in out source destination 61 4688 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 match-set blacklist dst 769 58912 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 match-set blacklist src Chain MINIUPNPD (1 references) pkts bytes target prot opt in out source destination | ||||||||
Notes | |
(0005851) NickH (developer) 2017-07-13 13:06 |
This is a WFM on 7.3 with f2b 0.9.5-3. See the file firewall.txt with f2b running and firewall1.txt after stopping it. The only "f2b native" way round this is to go towards ipset rules and use the ipset timeout feature. This improves the start up times and allows you to just destroy the set on stopping rather than delete the rules one by one. |
(0015981) NickH (developer) 2021-11-09 05:39 |
Ipset lists are now used and work in the backgrouns in an unobtrusive way |
Issue History | |||
Date Modified | Username | Field | Change |
2017-07-12 08:39 | user2 | New Issue | |
2017-07-12 08:40 | user2 | Status | new => confirmed |
2017-07-13 13:02 | NickH | File Added: firewall.txt | |
2017-07-13 13:03 | NickH | File Added: firewall1.txt | |
2017-07-13 13:06 | NickH | Note Added: 0005851 | |
2021-11-09 05:39 | NickH | Note Added: 0015981 | |
2021-11-09 05:39 | NickH | Status | confirmed => closed |
2021-11-09 05:39 | NickH | Resolution | open => won't fix |