From top I can see that fail2ban uses 85% to 98% of cpu. It doesn't drop below 85%. I've closed all ports in iptables except for ICMP responses, DNS responses, if state of connection is related, and if state of connection is established and one UDP port I use for remote management with hamachi. The box is directly on the Internet with no NAT which really isn't an issue because all ports I don't need are blocked including rtp ports and sip. These are established connections by trixbox and so come under the heading of "if state of connection is established".
fail2ban was running and causing no issues until recently when I restarted it after making a change in iptables when I shut down port 80. What would cause fail2ban to use so many cpu cycles?
Member Since:
2007-07-09