[CentOS] fail2ban problem new installation

Sun Dec 20 16:41:44 UTC 2015
Paul Heinlein <heinlein at madboa.com>

On Sat, 19 Dec 2015, Günther J. Niederwimmer wrote:

> Hello,
>
> I have a big problem with fail2ban and firewalld on my new system.
>
> I have a server running (CentOS 7.1) and run a Update to 7.2 on this system
> all is working ?
>
> BUT I install a new system with CentOS 7 1511 on this systems fail2ban don't
> work anymore. I have this error  or more, in the firewalld
>
> 2015-12-19 08:39:55 ERROR: COMMAND_FAILED: '/sbin/iptables -w2 -t filter -I
> INPUT_direct 1 -p tcp -m multiport --dports ssh -m set --match-set fail2ban-
> sshd src -j REJECT --reject-with icmp-port-unreachable' failed: iptables
> v1.4.21: Set fail2ban-sshd doesn't exist.

Things to check:

* the output of "ipset -l -n" to see if you have any ip sets
   defined

* that the fail2ban-firewalld rpm is installed

* that firewalld.service and fail2ban.service are both enabled
   and running

-- 
Paul Heinlein
heinlein at madboa.com
45°38' N, 122°6' W