Bug 1321476 - shouldn't require fail2ban-firewalld
Summary: shouldn't require fail2ban-firewalld
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: fail2ban
Version: epel7
Hardware: All
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Orion Poplawski
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-03-27 19:00 UTC by Brian J. Murrell
Modified: 2016-03-28 11:09 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-03-27 21:35:12 UTC
Type: Bug


Attachments (Terms of Use)

Description Brian J. Murrell 2016-03-27 19:00:12 UTC
Description of problem:
fail2ban requires fail2ban-firewalld, but I implement my bans at the network edge, not the fail2ban server.

Version-Release number of selected component (if applicable):
fail2ban-0.9.3-1.el7.noarch

How reproducible:
100%

In my fail2ban installation, I am running the server on a central logging server which receives the logs from many other machines but in particular from the firewall for the network, which is not the fail2ban server.

As such I have customized actions to implement the bans on the network firewall, not the fail2ban server.  Having fail2ban-firewalld on the fail2ban server is useless for me and I should not be forced to have it.

I'd be happy to supply an alternative to fail2ban-firewalld for remote routers (mine is an OpenWrt) but I'm not convinced it would be useful to anyone but my customized installation.  That said, I should still be allowed to choose not to have fail2ban-firewalld.

Comment 1 Orion Poplawski 2016-03-27 21:35:12 UTC
If you don't want firewalld, just install fail2ban-server which is the core fail2ban server component.  The fail2ban package is just a meta package that brings in the default components.

Comment 2 Brian J. Murrell 2016-03-28 11:09:42 UTC
Ahh.  Yes, that does the trick.  Thanks!


Note You need to log in before you can comment on or make changes to this bug.