Bug 17159

Summary: fail2ban fail when launched after shorewall
Product: Mageia Reporter: Stéphane Pontier <stephane.pontier>
Component: RPM PackagesAssignee: Remco Rijnders <remco>
Status: RESOLVED OLD QA Contact:
Severity: normal    
Priority: Normal CC: r+mageia
Version: Cauldron   
Target Milestone: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Source RPM: fail2ban-0.9.3-1.mga6.src.rpm CVE:
Status comment:

Description Stéphane Pontier 2015-11-16 11:34:00 CET
Description of problem:

After booting my computer, I got lot of error in fail2ban log:

iptables -w -X f2b-sshd -- stderr: b"iptables v1.4.21: Couldn't load target `f2b-sshd':No such file or directory\n\nTry `iptables -h' or 'iptables --help' for more information.\niptables: No chain/
target/match by that name.\niptables: No chain/target/match by that name.\n"

and receiving lot of mail of blacklisting an IP, even if this one should already been blacklisted thus not appearing again in application log.
when looking with "fail2ban-client status" I could see that the IP was currently in blacklisted list but "iptables -nL |grep f2" return nothing.

If I restart fail2ban, I can see that specific rules are created and fail2ban works correctly again.
iptables -nL |grep f2
f2b-sshd   tcp  --  0.0.0.0/0            0.0.0.0/0            multiport dports 22
Chain f2b-sshd (1 references)

I edited /usr/lib/systemd/system/fail2ban.service to change
- After=syslog.target network.target 
to 
+ After=syslog.target network.target shorewall.service
and after that, fail2ban worked correctly even after rebooting.


Version-Release number of selected component (if applicable):
fail2ban-0.9.3-1.mga6
shorewall-4.6.13.1-1.mga6

How reproducible:
Always

Steps to Reproduce:
1.
2.
3.


Reproducible: 

Steps to Reproduce:
Comment 1 Samuel Verschelde 2015-11-16 12:17:06 CET
Assigning to you Remmy, if it happens to be a problem with shorewall, you'll have to re-triage it :)

CC: (none) => r+mageia
Assignee: bugsquad => remco

Comment 2 sturmvogel 2022-08-07 17:28:22 CEST
This bug was filed against MGA6 which is EOL since Sep 2019. Please open a new bug i it is still valid with supported Mageia releases.

Closing OLD.

Status: NEW => RESOLVED
Resolution: (none) => OLD