Je ne comprend pas totalement ce que je fais pour être honnête. La commande sudo cat /var/log/fail2ban.log donne :
2023-04-09 00:00:02,131 fail2ban.server [575]: INFO rollover performed on /var/log/fail2ban.log
2023-04-12 21:17:21,793 fail2ban.server [582]: INFO --------------------------------------------- -----
2023-04-12 21:17:21,801 fail2ban.server [582]: INFO Starting Fail2ban v0.10.2
2023-04-12 21:17:21,840 fail2ban.database [582]: INFO Connected to fail2ban persistent database '/v ar/lib/fail2ban/fail2ban.sqlite3'
2023-04-12 21:17:21,874 fail2ban.jail [582]: INFO Creating new jail 'sshd'
2023-04-12 21:17:22,013 fail2ban.jail [582]: INFO Jail 'sshd' uses pyinotify {}
2023-04-12 21:17:22,027 fail2ban.jail [582]: INFO Initiated 'pyinotify' backend
2023-04-12 21:17:22,031 fail2ban.filter [582]: INFO maxLines: 1
2023-04-12 21:17:22,172 fail2ban.server [582]: INFO Jail sshd is not a JournalFilter instance
2023-04-12 21:17:22,179 fail2ban.filter [582]: INFO Added logfile: '/var/log/auth.log' (pos = 220 2612, hash = 3684a4608ed5468b11b15072a6f0f53bd391d152)
2023-04-12 21:17:22,196 fail2ban.filter [582]: INFO encoding: UTF-8
2023-04-12 21:17:22,197 fail2ban.filter [582]: INFO maxRetry: 5
2023-04-12 21:17:22,198 fail2ban.filter [582]: INFO findtime: 600
2023-04-12 21:17:22,201 fail2ban.actions [582]: INFO banTime: 600
2023-04-12 21:17:22,207 fail2ban.jail [582]: INFO Jail 'sshd' started
2023-04-13 01:09:32,296 fail2ban.filter [582]: INFO [sshd] Found 192.168.0.23 - 2023-04-13 01:09: 32
2023-04-13 01:09:34,009 fail2ban.filter [582]: INFO [sshd] Found 192.168.0.23 - 2023-04-13 01:09: 34
2023-04-13 19:18:38,298 fail2ban.server [582]: INFO Shutdown in progress...
2023-04-13 19:18:38,301 fail2ban.server [582]: INFO Stopping all jails
2023-04-13 19:18:38,303 fail2ban.filter [582]: INFO Removed logfile: '/var/log/auth.log'
2023-04-13 19:18:38,424 fail2ban.actions [582]: NOTICE [sshd] Flush ticket(s) with iptables-multipor t
2023-04-13 19:18:39,513 fail2ban.jail [582]: INFO Jail 'sshd' stopped
2023-04-13 19:18:39,516 fail2ban.database [582]: INFO Connection to database closed.
2023-04-13 19:18:39,517 fail2ban.server [582]: INFO Exiting Fail2ban
2023-04-13 19:19:02,405 fail2ban.server [589]: INFO --------------------------------------------- -----
2023-04-13 19:19:02,413 fail2ban.server [589]: INFO Starting Fail2ban v0.10.2
2023-04-13 19:19:02,466 fail2ban.database [589]: INFO Connected to fail2ban persistent database '/v ar/lib/fail2ban/fail2ban.sqlite3'
2023-04-13 19:19:02,490 fail2ban.jail [589]: INFO Creating new jail 'sshd'
2023-04-13 19:19:02,657 fail2ban.jail [589]: INFO Jail 'sshd' uses pyinotify {}
2023-04-13 19:19:02,680 fail2ban.jail [589]: INFO Initiated 'pyinotify' backend
2023-04-13 19:19:02,684 fail2ban.filter [589]: INFO maxLines: 1
2023-04-13 19:19:02,857 fail2ban.server [589]: INFO Jail sshd is not a JournalFilter instance
2023-04-13 19:19:02,872 fail2ban.filter [589]: INFO Added logfile: '/var/log/auth.log' (pos = 309 7252, hash = 3684a4608ed5468b11b15072a6f0f53bd391d152)
2023-04-13 19:19:02,888 fail2ban.filter [589]: INFO encoding: UTF-8
2023-04-13 19:19:02,889 fail2ban.filter [589]: INFO maxRetry: 5
2023-04-13 19:19:02,891 fail2ban.filter [589]: INFO findtime: 600
2023-04-13 19:19:02,892 fail2ban.actions [589]: INFO banTime: 600
2023-04-13 19:19:02,899 fail2ban.jail [589]: INFO Jail 'sshd' started
2023-04-13 19:21:16,286 fail2ban.transmitter [589]: WARNING Command ['status', 'apach-multiport'] has fai led. Received UnknownJailException('apach-multiport')
2023-04-13 22:50:17,842 fail2ban.server [589]: INFO Shutdown in progress...
2023-04-13 22:50:17,843 fail2ban.server [589]: INFO Stopping all jails
2023-04-13 22:50:17,844 fail2ban.filter [589]: INFO Removed logfile: '/var/log/auth.log'
2023-04-13 22:50:17,943 fail2ban.actions [589]: NOTICE [sshd] Flush ticket(s) with iptables-multipor t
2023-04-13 22:50:17,944 fail2ban.jail [589]: INFO Jail 'sshd' stopped
2023-04-13 22:50:17,945 fail2ban.database [589]: INFO Connection to database closed.
2023-04-13 22:50:17,946 fail2ban.server [589]: INFO Exiting Fail2ban
2023-04-13 22:50:18,865 fail2ban.server [29941]: INFO ------------------------------------------- -------
2023-04-13 22:50:18,866 fail2ban.server [29941]: INFO Starting Fail2ban v0.10.2
2023-04-13 22:50:18,883 fail2ban.database [29941]: INFO Connected to fail2ban persistent database ' /var/lib/fail2ban/fail2ban.sqlite3'
2023-04-13 22:50:18,890 fail2ban.jail [29941]: INFO Creating new jail 'sshd'
2023-04-13 22:50:18,977 fail2ban.jail [29941]: INFO Jail 'sshd' uses pyinotify {}
2023-04-13 22:50:18,997 fail2ban.jail [29941]: INFO Initiated 'pyinotify' backend
2023-04-13 22:50:19,004 fail2ban.filter [29941]: INFO maxLines: 1
2023-04-13 22:50:19,177 fail2ban.server [29941]: INFO Jail sshd is not a JournalFilter instance
2023-04-13 22:50:19,181 fail2ban.filter [29941]: INFO Added logfile: '/var/log/auth.log' (pos = 3 282116, hash = 3684a4608ed5468b11b15072a6f0f53bd391d152)
2023-04-13 22:50:19,201 fail2ban.filter [29941]: INFO encoding: UTF-8
2023-04-13 22:50:19,203 fail2ban.filter [29941]: INFO maxRetry: 3
2023-04-13 22:50:19,205 fail2ban.filter [29941]: INFO findtime: 7200
2023-04-13 22:50:19,207 fail2ban.actions [29941]: INFO banTime: 28800
2023-04-13 22:50:19,217 fail2ban.jail [29941]: INFO Creating new jail 'apache-noscript'
2023-04-13 22:50:19,217 fail2ban.jail [29941]: INFO Jail 'apache-noscript' uses pyinotify {}
2023-04-13 22:50:19,235 fail2ban.jail [29941]: INFO Initiated 'pyinotify' backend
2023-04-13 22:50:19,264 fail2ban.filter [29941]: INFO Added logfile: '/var/www/html/log/http.erro r' (pos = 0, hash = 64a9107915a6344caafa4fe68c5ac73023243353)
2023-04-13 22:50:19,366 fail2ban.filter [29941]: INFO encoding: UTF-8
2023-04-13 22:50:19,368 fail2ban.filter [29941]: INFO maxRetry: 1
2023-04-13 22:50:19,369 fail2ban.filter [29941]: INFO findtime: 7200
2023-04-13 22:50:19,370 fail2ban.actions [29941]: INFO banTime: 28800
2023-04-13 22:50:19,377 fail2ban.jail [29941]: INFO Creating new jail 'apache-overflows'
2023-04-13 22:50:19,378 fail2ban.jail [29941]: INFO Jail 'apache-overflows' uses pyinotify {}
2023-04-13 22:50:19,394 fail2ban.jail [29941]: INFO Initiated 'pyinotify' backend
2023-04-13 22:50:19,411 fail2ban.filter [29941]: INFO Added logfile: '/var/www/html/log/http.erro r' (pos = 0, hash = 64a9107915a6344caafa4fe68c5ac73023243353)
2023-04-13 22:50:19,424 fail2ban.filter [29941]: INFO encoding: UTF-8
2023-04-13 22:50:19,425 fail2ban.filter [29941]: INFO maxRetry: 2
2023-04-13 22:50:19,427 fail2ban.filter [29941]: INFO findtime: 7200
2023-04-13 22:50:19,429 fail2ban.actions [29941]: INFO banTime: 28800
2023-04-13 22:50:19,439 fail2ban.jail [29941]: INFO Creating new jail 'apache-botsearch'
2023-04-13 22:50:19,439 fail2ban.jail [29941]: INFO Jail 'apache-botsearch' uses pyinotify {}
2023-04-13 22:50:19,457 fail2ban.jail [29941]: INFO Initiated 'pyinotify' backend
2023-04-13 22:50:19,493 fail2ban.filter [29941]: INFO Added logfile: '/var/www/html/log/http.erro r' (pos = 0, hash = 64a9107915a6344caafa4fe68c5ac73023243353)
2023-04-13 22:50:19,504 fail2ban.filter [29941]: INFO encoding: UTF-8
2023-04-13 22:50:19,505 fail2ban.filter [29941]: INFO maxRetry: 6
2023-04-13 22:50:19,507 fail2ban.filter [29941]: INFO findtime: 7200
2023-04-13 22:50:19,508 fail2ban.actions [29941]: INFO banTime: 28800
2023-04-13 22:50:19,521 fail2ban.jail [29941]: INFO Jail 'sshd' started
2023-04-13 22:50:19,524 fail2ban.jail [29941]: INFO Jail 'apache-noscript' started
2023-04-13 22:50:19,528 fail2ban.jail [29941]: INFO Jail 'apache-overflows' started
2023-04-13 22:50:19,531 fail2ban.jail [29941]: INFO Jail 'apache-botsearch' started
Et la commande avec /var/log/fail2ban.log.2 donne :
2023-03-26 00:00:02,669 fail2ban.server [575]: INFO rollover performed on /var/log/fail2ban.log
Dans la premiere je vois une IP proche de celle mon Jeedom apparaitre :
2023-04-13 01:09:32,296 fail2ban.filter [582]: INFO [sshd] Found 192.168.0.23 - 2023-04-13 01:09: 32
2023-04-13 01:09:34,009 fail2ban.filter [582]: INFO [sshd] Found 192.168.0.23 - 2023-04-13 01:09: