After the recent fail2ban update… I notice the IP is already in recidive ban isn’t taking priority to reject re-occuring IP, it seems the other jail filters ie in dovecot not recognizing that it already banned.
Pls see the log file below… I thought when an IP already banned in recidive, it would reject or drop that IP over other Jail filters…
2017-11-22 00:44:28,409 fail2ban.filter [2194]: INFO [recidive] Found 5.188.11.11
2017-11-22 00:44:28,409 fail2ban.filter [2194]: INFO [recidive] Found 5.188.11.11
2017-11-22 00:44:29,062 fail2ban.actions [2194]: NOTICE [recidive] 5.188.11.11 already banned
2017-11-22 01:44:28,141 fail2ban.actions [2194]: NOTICE [dovecot-nethserver] Unban 5.188.11.11
2017-11-22 01:44:28,436 fail2ban.actions [2194]: NOTICE [dovecot] Unban 5.188.11.11
2017-11-22 01:48:34,820 fail2ban.filter [2194]: INFO [dovecot] Found 5.188.11.11
2017-11-22 01:48:35,164 fail2ban.filter [2194]: INFO [dovecot-nethserver] Found 5.188.11.11
2017-11-22 02:30:45,785 fail2ban.filter [2194]: INFO [dovecot] Found 5.188.11.11
2017-11-22 02:30:46,702 fail2ban.filter [2194]: INFO [dovecot-nethserver] Found 5.188.11.11 2017-11-22 02:51:50,484 fail2ban.filter [2194]: INFO [dovecot] Found 5.188.11.11
2017-11-22 02:51:50,938 fail2ban.filter [2194]: INFO [dovecot-nethserver] Found 5.188.11.11
2017-11-22 03:12:56,791 fail2ban.filter [2194]: INFO [dovecot] Found 5.188.11.11 2017-11-22 03:12:57,135 fail2ban.filter [2194]: INFO [dovecot-nethserver] Found 5.188.11.11
2017-11-22 03:12:57,522 fail2ban.actions [2194]: NOTICE [dovecot-nethserver] Ban 5.188.11.11 2017-11-22 03:12:57,634 fail2ban.actions [2194]: NOTICE [dovecot] Ban 5.188.11.11
2017-11-22 03:12:58,023 fail2ban.filter [2194]: INFO [recidive] Found 5.188.11.11
2017-11-22 03:12:58,024 fail2ban.filter [2194]: INFO [recidive] Found 5.188.11.11
2017-11-22 03:12:58,067 fail2ban.actions [2194]: NOTICE [recidive] 5.188.11.11 already banned