Hi It seems that Debian shipped vsftp comes with pam support which gets enabled if you enable local_enable option
then I start getting auth.log entries like Dec 21 23:37:06 belka vsftpd: (pam_unix) authentication failure; logname= uid=0 euid=0 tty=ftp ruser=yoh rhost=165.230.95.67 user=yoh which would match failregex as it was shipped in 0.7 and corresponding vsftpd.log line Thu Dec 21 23:37:08 2006 [pid 22501] [yoh] FAIL LOGIN: Client "165.230.95.67" so you must be using some non-standard setup to don't trigger log entries in auth.log. ok - I would join both failregexes into 1, so depending on the file used and setup one or another would be used ;-) Tentative version is here http://itanix.rutgers.edu/rumba/dists/sid/perspect/binary-all/net/fail2ban_0.7.5-3~pre2_all.deb Please give it a try so I am sure that failregex works before I upload it to debian -- .-. =------------------------------ /v\ ----------------------------= Keep in touch // \\ (yoh@|www.)onerussian.com Yaroslav Halchenko /( )\ ICQ#: 60653192 Linux User ^^-^^ [175555] -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]