#!/usr/bin/env bash # # JbTecWiz Support Centre -- generated fix script # # Fault : fail2ban is not banning, or has banned you # Fix : Unban an address and keep it out of range # Source: https://jbtecwiz.com/support/lnx-sec-fail2ban # # Run as : Root shell, via console if locked out # Expect : 15 minutes # Risk : low # Reversible : yes # # WHEN THIS IS THE RIGHT FIX # A legitimate address has been banned. # # HOW TO UNDO IT # Remove the ignoreip line and restart to return to the previous # behaviour. # # Walks the fix one step at a time and asks before each. Steps with no # command are yours to do -- it prints those and waits. DRYRUN=1 prints # without executing; UNATTENDED=1 does not ask. # # -------------------------------------------------------------------- # NO WARRANTY - USE AT YOUR OWN RISK # # This script is provided by JbTecWiz as-is and with no warranty of any # kind, express or implied. You run it entirely at your own risk. # # JbTecWiz accepts no liability for any loss or damage arising from its # use, including but not limited to data loss, downtime, or configuration # changes that turn out to be wrong for your system. # # You are responsible for reading this script before running it, for # satisfying yourself that it suits the machine in front of you, and for # having a working backup first. Some steps cannot be undone. # -------------------------------------------------------------------- set -uo pipefail DRYRUN="${DRYRUN:-0}" UNATTENDED="${UNATTENDED:-0}" failed=0 if [ "$(id -u)" -ne 0 ]; then echo " This fix is documented as needing root. Re-run with sudo." >&2 exit 3 fi rule() { printf "\n%s\n" "$(printf '-%.0s' $(seq 1 70))"; if [ $# -gt 0 ]; then echo "$1"; fi; } prose() { echo "$1" | fold -s -w 74 | sed "s/^/ /"; } # Returns 0 when the caller should run the command, 1 when it should not. # A manual step always returns 1 -- there is nothing for the caller to run. step() { # step [command lines...] local n="$1" dotext="$2" why="$3" mode="$4"; shift 4 rule " Step $n of 4" prose "$dotext" if [ -n "$why" ]; then echo; prose "$why"; fi if [ "$mode" = "manual" ]; then echo; echo " -> Do this yourself, then press Enter to carry on." if [ "$UNATTENDED" = "0" ] && [ "$DRYRUN" = "0" ]; then read -r _; fi return 1 fi echo; printf " %s\n" "$@"; echo if [ "$DRYRUN" = "1" ]; then echo " (dry run -- not executed)"; return 1; fi if [ "$UNATTENDED" = "0" ]; then read -r -p " Run this step? [Y]es / [S]kip / [Q]uit " a case "$a" in [Qq]*) echo " Stopped at your request."; exit 0 ;; [Ss]*) echo " Skipped."; return 1 ;; esac fi return 0 } rule echo " fail2ban is not banning, or has banned you" echo " Unban an address and keep it out of range" echo echo " Risk: low Reversible 15 minutes" echo prose 'No warranty. Use at your own risk - JbTecWiz accepts no liability. Read it before you run it, and have a backup.' rule echo if [ "$UNATTENDED" = "0" ] && [ "$DRYRUN" = "0" ]; then read -r -p " Ready? [y/N] " go case "$go" in [Yy]*) ;; *) echo " Nothing was changed."; exit 0;; esac fi if step 1 'See the jails and their current bans.' '' cmd 'sudo fail2ban-client status' 'sudo fail2ban-client status sshd'; then sudo fail2ban-client status sudo fail2ban-client status sshd if [ $? -ne 0 ]; then failed=$((failed+1)) echo " Step 1 failed. The rest of the fix may depend on it." >&2 fi fi if step 2 'Unban the address.' '' cmd 'sudo fail2ban-client set sshd unbanip 203.0.113.5'; then sudo fail2ban-client set sshd unbanip 203.0.113.5 if [ $? -ne 0 ]; then failed=$((failed+1)) echo " Step 2 failed. The rest of the fix may depend on it." >&2 fi fi if step 3 'Add the office or management range to the ignore list so it cannot recur.' 'An ignore list containing the addresses you administer from is the difference between fail2ban protecting the machine and fail2ban locking you out of it at the worst moment.' cmd 'sudo tee -a /etc/fail2ban/jail.local >/dev/null <<'\''EOF'\''' '[DEFAULT]' 'ignoreip = 127.0.0.1/8 ::1 203.0.113.0/24 10.0.0.0/8' 'EOF' 'sudo systemctl restart fail2ban'; then sudo tee -a /etc/fail2ban/jail.local >/dev/null <<'EOF' [DEFAULT] ignoreip = 127.0.0.1/8 ::1 203.0.113.0/24 10.0.0.0/8 EOF sudo systemctl restart fail2ban if [ $? -ne 0 ]; then failed=$((failed+1)) echo " Step 3 failed. The rest of the fix may depend on it." >&2 fi fi step 4 'Keep an out-of-band route -- a hypervisor console or a second port that fail2ban does not watch.' '' manual || true rule " Confirm it worked" prose 'The address connects and is listed in ignoreip.' if [ "$DRYRUN" = "0" ]; then sudo fail2ban-client get sshd ignoreip fi rule if [ "$failed" -gt 0 ]; then echo " Finished with $failed failed step(s)." echo " Read the full write-up at https://jbtecwiz.com/support/lnx-sec-fail2ban" else echo " Finished." fi echo prose 'To undo: Remove the ignoreip line and restart to return to the previous behaviour.' rule