可參考我的作法, 新增一個jail
/etc/fail2ban/filter.d/x5-dns.conf
[Definition]
failregex = <HOST>#.*denied
ignoreregex =
/etc/fail2ban/jail.local
[x5-dns]
enabled = true
filter = x5-dns
action = iptables-allports[name=named]
logpath = /var/log/security.log
maxretry = 5
findtime = 180
bantime = 3d
fail2ban.log