On 04/29/2016 04:58 PM, Ted Cooper wrote:
It's not so much AI, or automatic. You have to turn on exactly which tests and actions happen - filters (regex) & actions. In the case of the firewall ban, it only lasts as long as configured. The actions can be anything so you can also/instead notify yourself when someone is banned.
Here is a nice set of filters that someone shared. It doesn't cover the AUTH case in question, but it does have several other nice things.
One thing to be careful about with fail2ban filters is making sure they match your actual log entries. If you mess around with exim's normal logging, then fail2ban you get from someone else might fail-to-ban.
-- ## List details at https://lists.exim.org/mailman/listinfo/exim-users ## Exim details at http://www.exim.org/ ## Please use the Wiki with this list - http://wiki.exim.org/
