On Sat, Apr 25, 2009 at 5:16 PM, William Maddler <[email protected]> wrote: > > Hello all, looks like I've got a problem with the following log: > > > ----------- BEGIN > Received From: fennel->/var/log/syslog > Rule: 40111 fired (level 10) -> "Multiple authentication failures." > Portion of the log(s): > > Apr 25 18:57:56 fennel couriertcpd: LOGIN FAILED, user=user, > ip=[::ffff:204.111.80.65] > Apr 25 18:57:48 fennel couriertcpd: LOGIN FAILED, user=user, > ip=[::ffff:204.111.80.65] > Apr 25 18:57:47 fennel couriertcpd: LOGIN FAILED, user=testing, > ip=[::ffff:204.111.80.65] > Apr 25 18:57:48 fennel couriertcpd: LOGIN FAILED, user=user, > ip=[::ffff:204.111.80.65] > Apr 25 18:57:47 fennel couriertcpd: LOGIN FAILED, user=testing, > ip=[::ffff:204.111.80.65] > Apr 25 18:57:41 fennel couriertcpd: LOGIN FAILED, user=testing, > ip=[::ffff:204.111.80.65] > ----------- END > > Despite the alert is generated, I have no active response action. > Active respose is working fine for other alerts. > > I'd say the cause for this behaviour is that "::ffff:". Is someone else > having same problem? Any clue? > > Thanx > Maddler > >
I don't use active response, but I've seen issues using similar IPs in rules. dan
